I just returned from an exciting RSA 2024 Conference, and wow, what an experience! Here are some of the insights I had from conversations with hundreds of CISOs:
- The Power of Community: While the RSA floor had its quiet moments (with some of the booths looking empty), the real magic was in the after-hour dinners and off-site meetups. The CISO community is more vibrant and connected than ever, showing strength in numbers and insight.
- AI Revolution: It's official—AI is the new gold. Most companies are now incorporating AI language prompts on top of their data, and just like being a “SaaS company is a given” so will “AI”.
- Commoditizing Attack Surface: It’s now table stakes to have external threat visibility. The coolest part? It's often baked right into many products at no extra charge. Talk about value!
- Top of Mind Trends: CISOs are zeroing in on (1) Identity Access Management, (2) Cloud Security, and (3) Third-Party Risk. These are the battlegrounds where cyber wars are fought and won. Over 60% of the data breaches are now due to negligence of Third Parties - so that positions the important work that SecurityScorecard does very well.
- Startup Tsunami: As the CEO of a thriving $100M+ ARR company, I'm swamped with pitches from Alliance and M&A partners. Tip for startups: Scale matters, quality products matter, and gimmicks don't cut it. ? Too many startups are burning capital, building point solutions, getting stuck at under $20M ARR and hoping someone will buy them. ? As the scrutiny for budgets gets tougher, some startups are even resorting to gimmicks (like 50% off on the price - remember 50% off nothing in value is still nothing!)?
- Metrics that Matter: If we can't measure it, we can't master it. KPIs are our roadmap to industry excellence. We need objective, trusted ways to measure and quantify risk.
- Platformization—Just a Buzzword? While 'one-stop-shop' sounds great, savvy CISOs know better than to put all their eggs in one vendor's basket. This is good news for startups - because CISOs want the best solutions out there.
- Public Sector :? I was very impressed by collaboration between public and private sectors. The public sector cyber heads that I met, were innovative, forward-looking thinkers who wanted to make a difference. Big opportunity ahead to make life for adversaries harder!
- Top CISOs are in demand: The job market for CISOs is thriving, and some Fortune 500 CISOs are making $1-$3M a year in compensation. This is now a legitimate executive position with a seat at the Board room.
- ?Investor Frenzy: There’s a gold rush in cybersecurity investment. Capital is eager and ready, but the capital is concentrated in best-of-breed companies (for example WIZ who has an amazing product announced a $1B investment at $12B valuation). ? Picking the right investor makes a big difference - funds like Evolution Equity, BoldStart Ventures, Sequoia Capital, CyberStarts, and so on - are the right partners who will help not just with capital but also with advice and CISO introductions.
I’m feeling supercharged and ready to take on the future with all these insights and connections. The next wave of cyber innovation can't come soon enough! Let's do this!
Are there any insights that you had from RSA that I missed?
#RSAC #Cybersecurity #Innovation #FutureReady #RSA2024
Product Builder | Networks, Cybersecurity, SaaS, GenAI | Ex-Cisco
7 个月Thank you for a great summary. I agree 3. is a fantastic trend. Coming from the days when threat intel for BOT/APT was limited to Talos and a few others, is now accessible to most Cyber developers/users.
Sr. Manager @ Google Cloud AI Protection
10 个月Thank you for sharing Aleksandr Yampolskiy !
Love the summary. Question - where are the 1-3MM security roles? That market has been stagnate for quite some time. There are so many strong #infosec leaders who cannot afford to leave their #CISO roles becuase commensurate compensation packages are not available or accessible.
Observe & Discover, Invent & Innovate, Create & Solve CYBERSECURITY | RISK MANAGEMENT
10 个月I would add to the #4 another, the 4th point - the organization’s AI protection. AI’s revolution as a technology vehicle will bring AI unique challenges beyond the traditional cyber security. The complexity and (still) the unknown territory for cyber teams will increase the risk for all kind of AI, whereever in the organization utilized. https://www.security-assurance.com/post/ai-s-potential-while-guarding-against-emerging-cyber-threats-a-call-to-action-for-cisos