Presented by Microsoft
RSAC in focus: Key takeaways for CISOs
The RSAC Conference 2025 spotlighted pivotal advancements in agentic AI, identity security, and collaborative defense strategies, shaping the evolving mandate for CISOs.


The RSAC Conference 2025 last month left CISOs to process a whirlwind of discussions, innovations, and evolving strategic imperatives. Building on themes that gained significant traction in previous years, 2025's event solidified several critical areas demanding CISO attention, from the pervasive influence of AI to the increasing personal and professional pressures of the CISO role itself.
For security leaders navigating this complex terrain, the key takeaways from San Francisco were both challenging and clarifying. With a focus on agentic AI, identity security, collaborative defense, and human-centric strategies, the conference provided valuable insights for security leaders.
Agentic AI: transforming security operations
Agentic AI, defined by autonomous systems capable of independent decision-making, was a major topic at RSAC Conference 2025. Cisco unveiled an open-source 8-billion-parameter Foundation AI Security Model, which is intended to improve detection and response capabilities within security operations centers (SOCs). This model is designed to automate tasks such as identifying intrusion methodologies, assessing severity, and generating compliance reports.
Vasu Jakkal, corporate vice president of security at Microsoft, highlighted the transformative potential of agentic AI in cybersecurity, discussing how AI agents can work collaboratively to detect and prevent intrusions, thereby reducing the cost and complexity of sophisticated security operations.
Identity security: beyond human users
The rise of digital ecosystems has resulted in numerous non-human identities, like machine-to-machine communications and AI agents. Traditional identity management is now inadequate, prompting organizations to secure these digital identities against unauthorized access and system compromises.
Comprehensive identity governance solutions are required, covering both human and non-human entities, with strong authentication and authorization protocols throughout the enterprise.
Collaborative defense between public and private sectors
RSAC Conference 2025 underscored the vital importance of collaboration between private enterprises and government agencies in addressing evolving digital challenges. Sessions emphasized the importance of sharing intelligence and coordinating responses to close gaps in cybersecurity. Collective knowledge and resources can help organizations better manage modern digital issues, creating a stronger defense network.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Speakers and panellists deliberated on strategies for effective public-private partnerships, advocating for open communication channels and trust-building measures. These partnerships aim to streamline intelligence sharing on harmful activities, making it more actionable and timely, while also pooling technological resources to tackle sophisticated malicious campaigns. Despite political shifts and challenges that can sometimes hinder collaboration, the overarching consensus was that such alliances are indispensable for fortifying both national and organizational cybersecurity postures.
CISOs are advised to foster partnerships through intelligence-sharing forums and collaborative plans, enhancing preparedness against emerging risks.
Human element as the persistent core of cybersecurity
While technological advancements dominate the cybersecurity landscape, the human factor remains a critical component. Keynotes and sessions consistently highlighted that human behavior, decision-making, and collaboration are irreplaceable elements in building robust security frameworks. Despite the proliferation of automation and artificial intelligence, the ability of humans to adapt swiftly to unforeseen security challenges and coordinate responses across diverse teams remains unmatched. This human-centric approach reinforces the significance of fostering a culture of vigilance and resilience within organizations, where each member is empowered to contribute to the collective defense.
The emphasis on community and shared responsibility further underscores the importance of continuous education and awareness programs. These initiatives are designed not only to enhance technical knowledge but also to cultivate critical thinking and proactive attitudes needed to counter increasingly sophisticated digital intrusions. By integrating these programs alongside cutting-edge technological defenses, organizations can strike a powerful balance, ensuring that while systems evolve to meet new challenges, the human element remains the persistent and vital core of cybersecurity success.
Innovation and investment driving the future
A key takeaway for CISOs from RSAC Conference 2025 is the recognition of ProjectDiscovery's open-source platform for managing system weaknesses as a game-changer for under-resourced teams. Its advanced scanning capabilities highlight the growing importance of accessible security tools in democratizing cybersecurity efforts.
Rene Millman is a freelance writer and broadcaster who covers cybersecurity, AI, IoT, and the cloud. He also works as a contributing analyst at GigaOm and has previously worked as an analyst for Gartner covering the infrastructure market. He has made numerous television appearances to give his views and expertise on technology trends and companies that affect and shape our lives. You can follow Rene Millman on Twitter.
-
How CISOs can work with business leaders to harness the power of AI
Features Harnessing AI's transformative potential requires a strategic partnership between CISOs and business leaders to ensure secure and ethical innovation
-
RSAC in focus: Quantum computing and security
Experts at RSAC 2025 emphasize the need for urgent action to secure data against future cryptographic risks posed by quantum computing
-
RSAC in focus: Quantum computing and security
Experts at RSAC 2025 emphasize the need for urgent action to secure data against future cryptographic risks posed by quantum computing
-
RSAC in focus: How AI is improving cybersecurity
AI is revolutionizing cybersecurity by enhancing threat detection, automating defenses, and letting IT professionals tackle evolving digital challenges.
-
RSAC in focus: Collaboration in cybersecurity
Experts at RSA Conference 2025 emphasised that collaboration across sectors and shared intelligence are pivotal to addressing the evolving challenges of cybersecurity.
-
RSAC in focus: Considerations and possibilities for the remainder of 2025
As 2025 unfolds, RSAC explores the pivotal considerations and emerging possibilities shaping the cybersecurity landscape
-
RSAC Conference 2025: The front line of cyber innovation
ITPro Podcast Ransomware, quantum computing, and an unsurprising focus on AI were highlights of this year's event
-
How is the role of the CISO evolving?
Supported Content This role now stands as a pivotal figure in organizational strategy and security posture
-
CISOs bet big on AI tools to reduce mounting cost pressures
News AI automation is a top priority for CISOs, though data quality, privacy, and a lack of in-house expertise are common hurdles
-
RSAC Conference 2025: AI and quantum complicate security
Organizations are grappling with the complications of adopting AI for security