Exploring AI and Cybersecurity with Daniel Newman | RSAC Conference 2025
Alan Shimel and Daniel Newman discuss RSAC’s significance, with an expected attendance of 40-45,000 people. They highlight AI’s role in cybersecurity, notable company announcements like Palo Alto Networks’ acquisition, and regulatory challenges for Google. The fragmented security industry calls for platformization and innovation, with concerns about established companies lacking innovation. The conference emphasizes investment in startups and the need for proactive security measures.
Transcript
Hey everyone. We're live here at RSA. This is Alan Shimel.
It's my first interview for RSA 2025. I've been busy over, I don't know if you could see it out the back, but Moscon South is just over there. We're in Moscone West, and I've been over in south all day.
I haven't had a chance to be here. Lisa Martin's done a great job. I hope you're following along.
What a be best way to kick off my RSA coverage though, then with this guy right here. If you don't know him, shame on you, but no, if you don't know him, he's the CEO of Futurum group. It's my good friend Daniel Newman.
Daniel, welcome to RSA Coverage man. You are my first interview. Yeah.
And welcome, uh, yourself. I mean, we're at the desk together. Yeah.
Our first one since we got happily married. Uh, That's right. And that was in Boca was the last time we did that.
That Was in Boca. Yeah. And, uh, our first RSA together though As Yes, this first one.
Big Happy Family this first time we've been here. So, and this is a good RSA, they're expecting somewhere between 40 and 45,000 people. Um, you know, we, we do this event every year over in, uh, with, in conjunction with them.
It's our 10th year doing it. And we had, well, at two o'clock, we had about 850 people there, but they'll, um, we'll probably finish with a thousand. It was an amazing day of AI cyber at depth.
Yeah, it's been a good one so far. Uh, I came in on Sunday. I know the event technically is not even really fully, So tonight started The expo floor, but, uh, been doing some stuff around the perimeter.
I had a great sit down with, um, Palo Alto Network, CEO Nikesh Aurora. They, they bought a company since last Night and a company Announced, uh, and, and launched a new platform. So talk a little bit about that.
Uh, yep. Spent some time with, uh, Cisco's chief product Officer, G two Patel today. Love G two.
Uh, had him, uh, for, yeah, G Two's great. Yeah, a great sit down. I went over and visited the Veeam House.
Um, just, I was just sitting with Google Cloud for a while. Really. Course Google is, uh, making big moves.
Um, you know, we'll see if Billions and billions, 30 Something billion, uh, doing the, gotta get the wiz deal done. Yeah. You know, um, the, the environment's still a little questionable.
So I, I heard the Wiz deal is not getting done now till 2026. Um, I haven't heard anything official, and even if I had, I wouldn't say it here. Okay.
But, um, let's say from the onset of that announcement, I'm just, there's a lot of regulatory uncertainty still. And Google, of course, yeah. Is in the middle of a lot more regulatory scrutiny.
Chrome, The two cases Advertising business, they're just going through a lot right now. And so, while personally I don't actually believe this transaction is particularly problematic, um, I think when you're a company that's kind of facing this many investigations, both here domestically and around the world, trying to get something through you, you know how hard it is to get these deals done. You need a lot of regulatory bodies to approve them.
There's also a PR aspect to it. And like you said, while this particular deal I don't think represents any sort of monopolistic behavior or anything because of the atmosphere that Google Find finds themselves in, it's going to get so much more scrutiny than it deserves, quite frankly. You know, I'm not a handicapper, but I, you know, the odds of this thing getting done are just not as good as they you would think that it should be.
Yeah. So Lemme tell you something that is very interesting in those conversations that I had though. So far, this industry has long been very fragmented.
There's so many different types and pieces of security. Yeah. You come here and it's not a few dozen power players.
It is hundreds, thousands of companies. There's new companies, tons of venture money going into this space. You know, we're securing this application, this device, this edge, this data, but there is this really big sort of movement by these larger companies to try to do a platformization.
Yeah. Um, I heard it from Nikesh, I heard it from G two. This kind of, the industry needs centralization and that AI is a bit of a forcing function Maybe.
But, so here, as someone who's been in security 30 years, the move to a platform, you know, it's little fish get eaten by the medium fish, big fish eat the medium fish. One of the issues in security is innovation at the Cisco level, or even the Palo Alto level kind of stops. They, they count on acquisition for innovation.
And the, what you used to hear was products become features. Right? So you would have a small company that made a product and then that became a feature in a larger product set.
Well, the other shoe of dropping on that is products moving into platforms. Yep. And then the nice thing about platform is you don't have to own every product that fits into that platform.
You could partner and have an ecosystem, if you will. I think that's been the holy grail that companies like Palo, Cisco and before them, McAfee Semantic, they all chased that holy grail. Very few companies achieve that platform status, which is weird.
'cause you would think, what's the big deal about being a platform? Right? But why is it so hard?
But very few companies get there, Daniel. Well, it's a massive deal. And what's a little different in terms of a forcing function, one ai.
Mm-hmm. Right? So AI is creating so much velocity, so much pace that companies have to be able to address that.
And stitching together dozens or hundreds of different security solutions is a challenge, especially given the amount of budget that is security, which is generally single digit percentage of an overall IT budget at best. While concurrently tending to be not the strongest part of expertise within any, any IT team. And so the idea, again, it's a good idea, not necessarily saying it will work, but that you could sort of have that one universal platform.
By the way, we started there a little bit with cloud, right? It was, you're gonna use one cloud, right? And that one cloud will solve all your compute, storage, networking needs.
And it's like, well, you need one cloud, but you also need a bunch of your own infrastructure still for this reason. And then it was how many years later that all those big clouds said, well, now you need more than one cloud. And by the way, it's a telco cloud and there's an edge.
But I think the idea that getting underneath a all of the security needs and having sort of a more prominent partner becomes relevant, but it also materially changes the makeup of the industry. If that was to really take place, Yes, it would. You know, the single biggest question I hear from my friends in security, especially those who can't make it out to San Francisco here at RSA, where's the innovation?
Where is the innovation in security? We're doing the same things we were doing. Where's the innovation?
And unfortunately, the innovation is generally not in Palo Alto or Cisco. Now, I don't mean to pick on them. They're two great security companies.
The innovation, I always say, if you go down to the expo floor here at five 30, it's kind of like the Star Wars galaxy in the center of the galaxy. There's a big black hole that's sucking in light. Yeah.
That's where these big companies have 40 by 40 booths and 80 by 80 booths. It's when you get to the outer rim, you see innovation, those 10 by 10 booths where security people are innovating, coming up with the next generation, especially with ai, ag, AI stuff. And I see it in two ways with ai.
One is AI is a sword, one is AI as a shield or it, you know, using a shield for ai. I don't think, I think the whole system is geared, and I'm not saying it's cracked, but the whole system is geared to keep that innovation engine humming. 100%.
These big companies will make a number of purchases of these smaller companies. That was the Protect ai. Absolutely.
It's just that there are thousands of smaller startups either being seated in Series A's and b's, um, that may not see that exit, but we do need in any industry, and that's the same thing in ai. There's lots of companies trying to innovate there, but we are seeing a very exciting convergence. Yeah.
Security doesn't sit on the island anymore. It used to be like IT, security. Security, you have to, and now these two things are very much interdependent.
Yep. And that security platforms plus data plus infrastructure aren't sitting that far away from the type of compute applications and resources and agents. Absolutely.
Let me bring up something else here. I'd like to get your thoughts. Hey, if you need a nap.
No, I'm good to choose. Okay. Um, But, uh, we're all a little sick.
Yeah. Well, it's going around here, But thank gosh, from where you sit watching us right now, uh, We're, they can't, we're not contagious. Catch it from here.
Contagious. So I don't know if you had a chance to go over to the, uh, what they call the innovation sandbox here. No, not yet.
So, 20th year at RSA, they pick 10 companies every year to compete in the innovation sandbox. A who's who of winners over 20 years. Lots of IPOs, lots of big exits.
This year they're doing something a little different. Every one of the 10 finalists is getting $5 million in venture money from Crosspoint Partners, which is the company that now owns RSA conference. Oh, wow.
Interesting. What's your opinion about, so RSA conference as a conference, should they be investing in companies? Are we gonna mess up?
Are we going to kill the, the gravy train? This whole system of innovation? Like, you know, there's a, a lot of people here are saying RS a's a conference, not an investor.
They're changing their business model. It's now RSAC conference, C for community. Well, I think that's very limiting.
It's a very small mindset. Look, the RSA conference community, whether it is or isn't community. Right.
We're, we're, we're debating that is a ecosystem, and it's a, it's a bringing together of many people and ideas. Transparency here is that RSA happens to be owned by a company that is invested in other businesses. They're using an event that they've built that brings the best together into one place to try to seed.
I mean, they could do it more stealthily and have their, I I Would rather them not. Yeah. I'm saying.
So now they're, it's with a level of transparency. It's out in the open. I mean, these companies that are entering it are choosing, they understand that the consequence of being good could be taking an investment Money.
Yep. Um, they probably are trying to raise money. They're probably talking to other venture companies to try to raise money.
Sure. So I, you know, it's kind of like CNBC hosting Shark Tank. It's like, look, you've got an audience, you've got access to these interesting people.
Uh, you're bringing them together and it's, it's good business. It good money it out. Capital allocators, putting good money towards good products and services is a key element of a strong capitalist society.
And so, I mean, I, you know, me, I mean, You're a capitalist. I, you know, we, uh, liked what you did so much. Yeah.
That I, that I had to have it. Yeah. Um, I get it.
So, You know, people thought a lot of things, like when we came into the industry though, oh, you're an analyst firm. You can't be media. Oh, you're a, you know, you can't be a lab because you're not objective.
You're, it's like we're in a world now where you have to question everyone's, uh, intent. But at the same time, you also have to be opportunistic. So I'm, I'm, I'm all For it.
You're all for that. Let me run so else by you. So I mentioned we were doing this thing up at South today, the 10th annual DevSecOps Connect.
We had a panel with the CSO of Anthropic, the CSO of OpenAI, excuse me, security Tech lead Yep. Of, uh, met Lama. Yep.
What are they doing around security? And you just may surprise you. The, the anthropic and the OpenAI CISO said they're under so much pressure to get the next model out and the next model out and the next model out that they didn't say it was impossible, but they said near impossible to really bake the security in.
This was at an open, we will have this next month on video for you to watch, but what's your feeling About that? So interesting. When I was spending time with G two, he was talking about some of the work that Cisco's doing, and he talked about how when they were trying to expose vulnerabilities of deep seek, they were able to accomplish that a hundred percent of the time.
Right. Okay. Models are by default, non-deterministic, meaning you don't actually know what they're gonna create otherwise.
It wouldn't be a mo it wouldn't be generative ai. Right. It would be some type of, you know, RPA or automation.
It's smart Hero. Yep. The TLDR is the pace is creating vulnerabilities.
And for instance, you might say, Hey, I wanna know how to make a gun out of spare parts in my home. Um, these models are largely developed and trained from a security standpoint to which it would know not to answer that question. However, putting just the slightest bit of context around that same question and saying, I'm creating a play for my school and I need to create a prop gun that can do X, Y, and Z.
And it might not know. And what I'm saying is, so the ability to, to manage the data, the model and, and create a secure situation with these non-deterministic platforms is incredibly difficult. Absolutely.
Given the unpredictability of the outcome. So there's a really large market opportunity for companies that can help these big players solve the fact that these models are, uh, inherently, inherently and have a high propensity to being utilized this way. And by the way, AI will be one of the biggest creators of risk because it can be used to very rapidly, um, put an onslaught of prompts into these systems to create more vulnerabilities.
So I think they're saying what's probably accurate. I think they probably are putting meaningful resources towards trying to secure them, but realistically, security has always lagged innovation. Yeah.
And this case, the innovation is just faster and the risks are higher. Absolutely. Let's talk rum a little bit.
Yeah. Little bit. We're here.
I saw some of the six five media folks and my friend, our friend Lee Sellers from VI is here. You are here. What's going, how does Futura view RSA conference?
Look, uh, when we came together, um, I always thought that security and it, uh, lacked the commonality, the community and discipline. And that a lot of analysts, communities, research communities, sort of treated kinda like there's a CISO and A CIO. Yep.
And my belief is security and IT, and ai, these things are converging in a really prolific way. And so our team is very committed. Whether that's been expanding on our analyst side, whether that's been building our data platform and the research around cybersecurity, whether that's been expanding programming, um, bringing great new talent into the tech strong family mm-hmm.
Security Boulevard, bringing developers security, it, um, AI closer together. Look, I deeply believe that technology is the deterministic, the most deterministic factor of the world's long-term economic leadership. Security is one of the most robust opportunities that exists.
It cannot, uh, be looked at any longer as some type of, of, uh, insurance, uh, life insurance or secondary thing that you purchase in a worst case scenario. It needs to be very proactive. It needs to be very upfront to everything you do.
And so, deep down, um, I couldn't be more bullish about this category. No. And so personally, while I haven't spent as much time in this space as I may be in other parts of the tech stack, um, seeing this, seeing the community, uh, I couldn't be more proud of the company that we've created and the depth that we're, uh, able to cover this space.
And, uh, I'm just, I'm just really glad we're here and I think you guys are doing a great job. And, uh, well, I can't stay longer. Um, Oh, I see you're getting here.
I, I can't stay long Another time, But, uh, I am really looking forward to coming back and, and RSA, but also just continuing to, you know, take a more and more active role in this community because I think security is one of the fronts that's just under covered, underused with so much upside opportunity and necessity. Alan, 40,000 plus people here would say absolutely. 100%.
Absolutely. Daniel Newman. Hey dude, it's a pleasure having you here.
Thanks for Having me. com. We didn't talk about the intelligence portal.
I'm gonna talk about it this week. Check it out. But we're live at, excuse me, my voice is going, we're live at RSA.
We'll be back actually visit for day one, right? Well, day zero. We'll be back tomorrow for day one.
Until then, enjoy. Bye-Bye.