The Power of Community

RSA Conference 2024 · West Stage Keynote

Overview

Hugh Thompson, Executive Chairman of RSA Conference, delivered a powerful keynote address at RSAC 2024, emphasizing the critical role of community in navigating the complex and ever-evolving landscape of cybersecurity. Titled "The Power of Community," his talk served as both an opening welcome and a strategic call to action for the more than 40,000 cybersecurity professionals gathered from over 130 countries. Thompson framed the conference's theme, "The Art of Possible," as a dual message: inspiring hope in what can be achieved through collective effort, while also serving as a stark warning against underestimating the capabilities of adversaries.

Watch on YouTube

Visual summary for The Power of Community
Visual summary for The Power of Community

Key moments

  1. 0:00 Welcome to RSAC 2024; global scale
  2. 2:00 Conference theme: Art of Possible; community's power
  3. 4:30 Personal story: Family of Bahamian lighthouse keepers
  4. 6:00 Lighthouse keeper's mission: shining light, readiness to respond
  5. 8:00 Challenge of prevention: often unacknowledged, difficult work
  6. 8:45 Major trend: Cybersecurity professional burnout spiking again
  7. 9:30 New burnout causes: liability, reporting, incident documentation

The Power of Community

Speakers: Hugh Thompson, Executive Chairman, RSA Conference

Conference: RSAC 2024

YouTube: https://www.youtube.com/watch?v=FBhCLU6WW5c

Overview

Hugh Thompson, Executive Chairman of RSA Conference, delivered a powerful keynote address at RSAC 2024, emphasizing the critical role of community in navigating the complex and ever-evolving landscape of cybersecurity. Titled "The Power of Community," his talk served as both an opening welcome and a strategic call to action for the more than 40,000 cybersecurity professionals gathered from over 130 countries. Thompson framed the conference's theme, "The Art of Possible," as a dual message: inspiring hope in what can be achieved through collective effort, while also serving as a stark warning against underestimating the capabilities of adversaries.

The core message of the keynote revolved around the idea that while individuals possess intelligence and strength, it is through community that wisdom, endurance, and formidable collective power are truly unlocked. Thompson illustrated this with a deeply personal anecdote about his family's multi-generational legacy as lighthouse keepers in the Bahamas, drawing parallels between their mission to "shine a light in the dark places" and the daily imperative of cybersecurity professionals to prevent bad things from happening and respond when necessary. This talk is highly relevant for anyone in the cybersecurity field, offering a foundational perspective on the human element, strategic challenges, and collaborative solutions essential for future resilience.

Background

▶ Watch: Welcome to RSAC 2024; global scale (0:00)

The cybersecurity landscape is characterized by relentless threats, rapidly advancing technologies, and a persistent skills gap, leading to significant stress and burnout among professionals. Thompson highlighted that the challenges faced daily often seem insurmountable when tackled in isolation. Historically, individual brilliance has driven many security innovations, but the scale and sophistication of modern threats, from nation-state actors to organized cybercrime, demand a more integrated and collaborative approach.

Thompson's personal narrative provided a poignant backdrop for this emphasis on community. His family's history as lighthouse keepers in the treacherous, shallow waters surrounding the 700-plus islands of the Bahamas underscored a deep-seated mission to protect. Since the 1850s, his ancestors understood that their role was a calling: to keep the light lit, preventing ships from running aground and saving lives. This historical context illustrates a fundamental human drive to defend and respond, a drive that Thompson argues is inherent in many cybersecurity professionals. This mission-driven ethos, however, often goes unacknowledged, as successful prevention—the absence of a negative event—rarely garners public praise or recognition, contributing to the silent burden carried by defenders.

Against this backdrop, the RSA Conference itself acts as a crucial community hub. For 16 years, Thompson has observed that the "impossible" problems in cybersecurity become "possible" through the collective intelligence and shared experiences fostered at such gatherings. The conference's call for speakers, which received a record number of submissions this year, reflects the community's engagement across diverse areas, from risk management and policy setting to vulnerability research and the pervasive influence of Large Language Models (LLMs). This annual convergence provides a vital platform for sharing insights, developing frameworks, and reinforcing the communal bonds necessary to tackle current and emerging threats effectively.

Key Findings

▶ Watch: Personal story: Family of Bahamian lighthouse keepers (4:30)

Thompson identified three overarching trends emerging from the thousands of speaker submissions for RSAC 2024, which collectively paint a picture of the industry's current state and future trajectory:

  1. Spiking Burnout Rates: The most concerning trend is the resurgence of burnout among cybersecurity professionals. While burnout spiked in 2021 due to the rapid shift to remote work during the COVID-19 pandemic and the associated challenges of implementing Zero Trust architectures, it had seen a decrease in 2022 and 2023. However, 2024 data indicates another significant spike, driven by different factors. The submissions this year highlight words like ransomware, liability, and reporting. This suggests a shift in focus, where professionals are increasingly compelled to prioritize documentation and legal considerations over their natural instinct to immediately respond to an incident. This administrative burden, coupled with the relentless pressure of evolving threats, is contributing to a renewed sense of stress and exhaustion.
  1. Pervasive Influence of AI/LLMs: Unsurprisingly, Artificial Intelligence (AI) and specifically Large Language Models (LLMs) have become ubiquitous across all subdisciplines of cybersecurity. While AI has been a part of the RSA program for years, previously focusing on specific machine learning applications, it is now integrated into almost every aspect of the agenda. The submissions fall into two main categories:
  • Defensive Augmentation: How can cybersecurity professionals leverage LLMs and AI to enhance their defensive capabilities, making their work more efficient and effective?
  • Risk Surface Expansion: How do organizations manage the rapid adoption of AI technologies across the business, ensuring appropriate compensating controls are in place for this new, rapidly evolving risk surface? The speed of AI adoption is unprecedented, posing significant challenges for security teams trying to keep pace.
  1. Nuanced Evolution of Risk Management: While risk management is a long-standing discipline, Thompson observed a distinct pattern in how the industry addresses new threats. Initially, a new threat (e.g., software supply chain security in the wake of SolarWinds) generates intense discussion. This is typically followed by the introduction of frameworks (e.g., S-bombs for software supply chain security), which can sometimes create a false sense of security. As years pass, terms like "management" are appended to these frameworks (e.g., "software supply chain security management"), and the volume of submissions on the topic decreases. This reduction in discussion, Thompson argues, does not signify that the problem is solved (citing the ongoing challenges with libraries like X-U-tils), but rather that the industry may have become complacent or overwhelmed, leading to an illusion of control rather than actual resolution. This pattern highlights a critical vulnerability in how the industry perceives and addresses persistent threats.

These findings collectively underscore the immense pressure on cybersecurity professionals and the strategic shifts required to maintain effective defenses in a rapidly changing technological and threat landscape.

Technical Deep Dive

▶ Watch: Lighthouse keeper's mission: shining light, readiness to respond (6:00)

While Hugh Thompson's keynote did not delve into specific technical exploits, code, or intricate protocol analyses, it critically highlighted the broader technical challenges and implications arising from the identified industry trends. The pervasive influence of AI, the complexities of modern risk management, and the impact of burnout on technical execution are fundamentally technical issues that shape the daily work of cybersecurity professionals.

The discussion around AI and LLMs is perhaps the most direct technical implication. The rapid integration of these technologies into enterprise operations presents a dual technical challenge. On one hand, security teams are exploring how to harness AI for automated threat detection, malware analysis, vulnerability scanning, and incident response orchestration. This involves developing and deploying AI models that can process vast amounts of security telemetry, identify anomalous behavior, and even generate defensive actions. Technical work here includes:

  • Model Training and Validation: Ensuring AI models are trained on representative and unbiased security data to prevent false positives or false negatives.
  • Explainable AI (XAI) for Security: Developing methods to understand why an AI made a particular decision, crucial for auditing and trust in automated systems.
  • Integration with Existing Security Stacks: Seamlessly embedding AI capabilities into SIEMs, SOAR platforms, and endpoint detection and response (EDR) solutions.

On the other hand, the business's rapid adoption of AI creates a vast new attack surface. Technical professionals must grapple with:

  • Securing AI/ML Pipelines: Protecting the entire machine learning lifecycle, from data ingestion and model training to deployment and inference, against data poisoning, model evasion, and model inversion attacks.
  • Prompt Injection and Data Leakage: Addressing vulnerabilities specific to LLMs, where malicious prompts can lead to unintended actions or the exfiltration of sensitive training data.
  • AI Governance and Compliance: Implementing technical controls and architectural patterns that ensure AI systems comply with privacy regulations (e.g., GDPR, CCPA) and ethical guidelines. This includes robust access controls, data anonymization techniques, and secure development lifecycle (SDL) practices tailored for AI.

The nuance around risk management, particularly concerning software supply chain security, also has profound technical dimensions. The introduction of S-bombs (Software Bill of Materials) was a technical response to the lack of visibility into third-party components. Technically, S-bombs aim to:

  • Inventory Dependencies: Provide a comprehensive list of all open-source and proprietary components, their versions, and licenses within an application.
  • Vulnerability Mapping: Enable automated tools to map known vulnerabilities (e.g., from CVE databases) to the components listed in an S-bomb, allowing for proactive patching.
  • License Compliance: Help organizations manage software licenses to avoid legal issues.

However, Thompson's observation that the problem isn't solved, despite the proliferation of "management" frameworks, points to inherent technical challenges. Generating accurate and complete S-bombs, especially for complex, multi-layered applications with transitive dependencies, remains difficult. Furthermore, merely having an S-bomb does not automatically secure the supply chain; it requires continuous monitoring, integration with DevSecOps pipelines, and robust processes for vulnerability remediation. The ongoing issues exemplified by libraries like X-U-tils underscore that even well-intentioned technical solutions require sustained effort and integration into a broader security culture and operational framework to be truly effective.

Finally, the spike in burnout has direct technical implications. An exhausted and overwhelmed workforce is less effective at identifying subtle threats, maintaining complex systems, or innovating defensive strategies. Alert fatigue, a common issue where security analysts are overwhelmed by a high volume of alerts, often leads to missed critical incidents. Burnout can also contribute to:

  • Reduced Code Quality: Leading to more vulnerabilities in internally developed software.
  • Delayed Patching and Configuration Drift: As critical tasks are postponed.
  • Decreased Vigilance: Making security teams more susceptible to sophisticated social engineering attacks.
  • High Turnover: Leading to a loss of institutional knowledge and expertise, further exacerbating the skills gap.

Thus, while the keynote was not a technical deep dive in the traditional sense, it laid bare the critical technical battlegrounds where the cybersecurity community must focus its collective energy. The solutions to these challenges will invariably require innovative technical approaches, robust architectural designs, and a sustained commitment to collaborative problem-solving.

Demo / Proof of Concept

▶ Watch: Major trend: Cybersecurity professional burnout spiking again (8:45)

As an opening keynote address, Hugh Thompson's presentation at RSAC 2024 did not include a live demonstration or a proof of concept of any specific security tool, exploit, or defensive technology. His talk focused on high-level strategic themes, industry trends, and the foundational importance of community and human connection within the cybersecurity field.

Defensive Implications

▶ Watch: New burnout causes: liability, reporting, incident documentation (9:30)

The trends highlighted by Hugh Thompson carry significant implications for cybersecurity defenders, urging a strategic re-evaluation of current practices and a renewed focus on collective resilience.

  1. Addressing Burnout as a Critical Threat: The resurgence of burnout is not just an HR issue; it's a direct threat to an organization's defensive posture. Defenders must recognize that an overwhelmed and demoralized team is less effective.
  • Prioritize Automation: Invest in automation tools, particularly those leveraging AI/ML, to reduce repetitive tasks and alert fatigue. This allows human analysts to focus on complex, high-value threats.
  • Streamline Reporting and Liability Processes: Work with legal and compliance teams to simplify documentation requirements where possible, ensuring that the need for rapid incident response is not hampered by bureaucratic burdens. Develop clear protocols that balance legal obligations with operational urgency.
  • Foster a Culture of Recognition: Implement mechanisms to acknowledge successful prevention, not just successful response. Leadership must actively communicate the value of proactive security measures to boost morale and reinforce the "lighthouse keeper" ethos.
  • Promote Work-Life Balance: Encourage breaks, provide mental health resources, and manage workloads realistically to ensure the sustainability of security teams.
  1. Strategic Integration and Securing of AI: The omnipresence of AI demands a two-pronged defensive strategy.
  • Leverage AI for Defense: Defenders should actively explore and implement AI-powered security solutions for threat intelligence analysis, behavioral analytics, anomaly detection, and automated vulnerability management. This requires internal expertise to evaluate, deploy, and fine-tune AI systems effectively.
  • Secure the AI Supply Chain and Deployment: As AI is adopted across the business, security teams must embed themselves in the AI development lifecycle. This includes:
  • Implementing secure-by-design principles for AI systems.
  • Establishing robust data governance and privacy controls for AI training data.
  • Developing strategies to detect and mitigate adversarial AI attacks (e.g., data poisoning, model evasion).
  • Ensuring transparent AI models where possible, to understand decision-making and avoid "black box" security risks.
  • Creating compensating controls for new AI-driven business processes, which might involve re-architecting security perimeters or identity and access management (IAM) strategies.
  1. Maturing Risk Management Beyond Frameworks: The observation about the "false sense of security" derived from frameworks like S-bombs and "management" terms requires defenders to adopt a more critical and continuous approach to risk.
  • Continuous Validation: Don't just implement a framework; continuously validate its effectiveness. For software supply chain security, this means not only generating S-bombs but also actively monitoring them for new vulnerabilities, performing regular penetration testing on third-party components, and ensuring a rapid patching and update cycle for all dependencies (e.g., addressing issues like X-U-tils proactively).
  • Focus on Outcomes, Not Just Compliance: Shift the mindset from merely checking boxes for compliance to actively reducing risk and improving security outcomes. This involves understanding the real attack surface and threat vectors, rather than just what frameworks dictate.
  • Integrate Risk Management into Operations: Embed risk considerations into daily DevSecOps practices, ensuring that security is a continuous process throughout the software development lifecycle, not an afterthought.
  • Share Threat Intelligence: Actively participate in community-driven threat intelligence sharing initiatives to gain real-time insights into emerging threats and attack methodologies, moving beyond static frameworks to dynamic defense.

In essence, Thompson's message empowers defenders to leverage the collective wisdom and strength of the cybersecurity community. By openly sharing knowledge, collaborating on solutions, and supporting one another, professionals can overcome individual limitations and build a more resilient collective defense against the "art of possible" by adversaries.

Key Takeaways

  • Community is the Ultimate Strength: Individual intelligence is valuable, but collective wisdom, endurance, and formidable power are unlocked through community. This is crucial for tackling seemingly impossible cybersecurity challenges.
  • Burnout is a Critical Operational Risk: The significant spike in burnout, driven by factors like ransomware, liability concerns, and reporting burdens, directly impacts defensive efficacy. Organizations must prioritize strategies to mitigate stress and support their security teams.
  • AI Presents Dual Challenges and Opportunities: AI and LLMs are revolutionizing cybersecurity, both as powerful defensive tools and as expansive new attack surfaces. Defenders must strategically leverage AI while rigorously securing its adoption across the enterprise.
  • Beware of False Security from Frameworks: The mere existence of security frameworks or "management" terminology does not equate to solved problems. Continuous vigilance, validation, and operational integration are essential to avoid a false sense of security, especially in areas like software supply chain security.
  • Embrace Curiosity and Openness: To maximize learning and collaboration, professionals should step outside their comfort zones, meet new people with genuine curiosity, and remain open to diverse ideas and approaches.
  • You Are Not Alone: The cybersecurity community provides a vital support network. Professionals are not isolated lighthouse keepers; they are part of a collective shining a light in the dark, with others ready to assist when challenges arise.

About the Speaker(s)

Hugh Thompson is the Executive Chairman of RSA Conference, a role he has held for a significant period, including 16 years as the program chair. His extensive experience at the helm of one of the world's most prominent cybersecurity conferences provides him with a unique vantage point on industry trends and challenges. Thompson is deeply mission-driven, a characteristic he attributes to his personal background. He hails from the Bahamas, where his family—including his grandfather, great-grandfather, and generations before—served as lighthouse keepers. This heritage instilled in him a profound understanding of the dedication required to "shine a light in the dark places" and protect others from unseen dangers, a philosophy he sees mirrored in the work of cybersecurity professionals. He is a passionate advocate for the power of community and collaboration in addressing the complex problems facing the digital world.

All talks from RSA Conference 2024