The RSA Conference, arguably the cybersecurity industry’s biggest annual gathering that kicks off on Monday, May 17, will for the first time be a virtual event.
Conference organizers should have called off the in-person event last year, well before some 32,000 people descended upon the San Francisco Bay Area, which turned out to be ground zero for COVID-19 on the West Coast, or at least by the time that San Francisco Mayor London Breed’s office declared a state of emergency on day 1 of the 2020 event. But that’s a whole different story — and one that I already wrote.
RSAC 2021 will be bittersweet this year. For many security professionals, last year’s event was the final time they saw their friends and counterparts in person, and many remained hopeful that this year’s conference would bookend the pandemic nightmare — sharing different kinds of war stories over cocktails in actual bars and reflecting on how the physical and cyber world has changed since March 2020.
However, more than a year into pandemic life, we’ve become accustomed to daily Zoom calls and virtual events. We suffer from screen fatigue, but we have also attended some exceptional virtual events. Hopefully the RSA Conference won’t disappoint. As with in-person RSA events, I expect a handful of top trends, technologies, and threats to dominate the discourse. And like just about everything else over the past 12 months, many of these have been shaped by the COVID-19 pandemic.
While the full impact of the SolarWinds supply chain attack continues to unfold, that hack remains top of mind as new details emerge, and it will likely be a key talking point for attendees and speakers alike. I’d suggest adding the Wednesday keynote by SolarWinds CEO Sudhakar Ramakrishna to your calendar right now.
And when it comes time to play buzzword bingo, I predict this year’s top buzzy acronyms will be application security (AppSec) XDR, ZT, SASE.
SASE, or secure access service edge, provides an edge-based architecture to deliver networking and security technologies. While SASE was already becoming popular before COVID-19, the pandemic — and related influx of remote workers — made SASE almost a necessity for businesses trying to secure their assets while their employees accessed corporate systems via their home networks. I suspect SASE will continue to be a hot topic at the RSA Conference, but with an increasing focus on the zero-trust piece.
Similar to SASE, zero trust (ZT) isn’t one technology, but rather a framework to ensure that only verified users and devices are allowed access to corporate resources and restrict data on a least-privilege basis. A handful of technologies support zero trust, including multi-factor authentication, endpoint device management, and network segmentation. Look for innovations in all of the above at RSA.
Additionally, extended detection and response (XDR), which provides centralized security data and incident response via cloud-based software, has been on fire over recent months. Several endpoint detection and response (EDR) vendors have pivoted to XDR along with every major cloud security vendor touting their own XDR platform — whether or not they can actually deliver on the promise of combined security information and event management (SIEM); security orchestration, automation, and response (SOAR); EDR; and network traffic analysis (NTA).
I expect to hear a lot of XDR news at RSA, from startup launches to partnerships and additional capabilities, not to mention companies with existing platforms talking (prematurely) about “next-gen” XDR.
And finally, as COVID-19 pushed everything to the cloud, securing all parts of cloud-native applications — from proprietary and open source code, to containers and Kubernetes, as well as APIs and data — has become a top priority. In just the first few months of 2021, we’ve seen a flurry of activity in this space with large vendors including Palo Alto Networks and VMware scooping up startups while application security providers scored hundreds of millions of dollars in funding rounds.
Don’t be surprised if DevOps and application security startups steal the show at RSA this year, as enterprises and small businesses alike look for easier ways to build security into their modern applications.
Comments