The RSA Conference (RSAC) 2026, held in San Francisco on March 28, marked a pivotal moment in the cybersecurity realm, with ‘agentic AI’ and ‘agentic SOC’ emerging as dominant themes. As the world becomes increasingly interconnected, the necessity for robust cybersecurity measures has never been more critical. This year, the focus shifted to how artificial intelligence (AI) is reshaping security practices and the roles of security professionals.
Understanding Agentic AI and SOC
‘Agentic AI’ refers to systems that can operate autonomously, making decisions based on data analysis without human intervention. This trend is particularly significant within Security Operations Centers (SOCs), where AI-driven tools are being deployed to enhance threat detection and response capabilities. The integration of agentic AI into security frameworks is poised to streamline operations, allowing organizations to respond to threats more efficiently.
Implications for Cybersecurity Firms
During the conference, industry experts discussed the potential ramifications of AI on the valuation of cybersecurity firms. As companies increasingly adopt AI technologies, there is a growing concern that valuations will come under pressure. This shift could lead to a wave of consolidation within the industry as smaller firms struggle to compete with larger, AI-driven entities. Furthermore, the costs associated with implementing advanced AI solutions may rise, impacting organizations that rely on these technologies to protect their assets. (AI-driven phishing insights)
- Increased demand for agentic AI: As organizations seek to automate and enhance their cybersecurity measures, the demand for agentic AI solutions is expected to surge.
- Potential industry consolidation: Smaller cybersecurity firms may face challenges in keeping up with the evolving landscape, leading to mergers and acquisitions.
- Rising implementation costs: The integration of advanced AI technologies could lead to higher costs for organizations, necessitating budget adjustments.
The Evolving Role of the CISO
Bill O’Connell, Chief Information Security Officer (CISO) at Commvault, addressed the changing dynamics of cybersecurity leadership in his keynote speech. He emphasized the need for CISOs to adapt to new challenges, particularly in the context of cyber resilience and risk communication. As organizations face increasingly sophisticated threats, the role of the CISO is evolving from a focus on compliance and risk management to a more strategic position that encompasses overall business resilience.
Cyber Resilience and Risk Communication
CISO O’Connell highlighted the importance of developing a robust cyber resilience framework. This framework should not only focus on prevention but also emphasize the organization’s ability to recover from incidents. Key components of cyber resilience include:
- Proactive threat detection: Utilizing AI to identify vulnerabilities before they can be exploited.
- Incident response planning: Preparing for potential breaches and having a clear strategy for response and recovery.
- Continuous risk assessment: Regularly evaluating potential threats and adjusting security measures accordingly.
O’Connell also addressed the necessity for clear risk communication within organizations. As cybersecurity threats become more complex, it is crucial for CISOs to articulate the potential risks to stakeholders clearly. This involves translating technical jargon into understandable terms that resonate with non-technical executives, ensuring that cybersecurity is recognized as a vital component of overall business strategy.
The Dual-Edged Sword of AI in Cybersecurity
While the emergence of agentic AI presents numerous opportunities for enhancing cybersecurity, it also introduces new challenges. Cybercriminals are increasingly leveraging AI to develop more sophisticated phishing attacks and other malicious tactics. This evolution exacerbates the existing gap between defenders and attackers, making it imperative for organizations to stay one step ahead.
Challenges Posed by AI-Enhanced Cyber Threats
The dual-edged nature of AI means that as defenders bolster their capabilities, attackers are equally empowered. Some of the challenges posed by AI-enhanced cyber threats include:
- Advanced phishing techniques: Cybercriminals are using AI to craft personalized and convincing phishing messages that can easily deceive users.
- Automated attacks: AI allows attackers to automate processes, increasing the scale and speed of cyberattacks.
- Data manipulation: AI can be used to manipulate data within organizations, leading to misinformation and loss of trust.
Looking Ahead: The Future of Cybersecurity
The themes emerging from RSAC 2026 underscore a critical juncture in the cybersecurity landscape. As organizations embrace agentic AI, the need for strategic adaptation is paramount. The convergence of advanced technologies and evolving cyber threats necessitates a collaborative approach to security, one that prioritizes resilience, adaptability, and clear communication. Related reading: CISO's guide on AI risks.
As the cybersecurity industry continues to evolve, the insights gained from this year’s conference will undoubtedly shape the strategies of organizations worldwide. By acknowledging both the opportunities and challenges presented by agentic AI, companies can better prepare themselves for the future of cybersecurity.