03/26/2026 | Press release | Archived content
RSAC 2026 felt exactly like you'd think such a major industry gathering would feel: busy, fast-moving, crowded, and worthwhile. It was the kind of week where the calendar fills up quickly, the hallways are packed, and the best conversations often happen between sessions rather than inside them. What stood out to me, though, was that this was not just a busy conference. It was a good conference to run into colleagues, customers, partners, and friends, and to spend real time with people who are all trying to make sense of the same market shift. That matters, especially at a conference whose official theme was "Power of Community," held March 23 through March 26 at the Moscone Center in San Francisco.
My biggest takeaway is that the center of gravity in cybersecurity continues to move from talking about AI as an interesting capability to dealing with AI as an operating reality. RSAC's own 2026 trend preview was explicit about the topics shaping the conference: Model Context Protocol (MCP), agentic AI, vibe coding, identity, governance, burnout in the community, and the power of partnerships. That list tells us something important. The industry is no longer asking whether AI will affect security. It is now asking how we secure autonomous behavior, how we govern what we cannot always see clearly, and how we keep human decision-making relevant while the technology stack becomes more dynamic and more distributed.
That shift was visible everywhere. The conversation is increasingly about observability, identity, and governance as prerequisites for safe AI adoption, not nice-to-haves that can be bolted on later. Microsoft's RSAC-related messaging, and reporting around their keynote, reinforced that point by centering observability, governance, and security as foundational to the agentic era. RSAC's own "Actionability" preview also made a related point that I think landed well: visibility by itself is no longer enough. If data is not trustworthy and usable, it does not create outcomes. It just creates more noise.
Another important signal was that the conference was not only about AI. Post-quantum readiness and cryptography modernization remained firmly on the agenda as well. Vendors highlighted post-quantum cryptography as one of the defining areas to watch at this year's event, and RSAC's keynote lineup again gave prominent space to the Cryptographers' Panel. That is a useful reminder that while AI dominates the headlines, the trust fabric of the industry is still being shaped by hard questions around cryptography, resilience, and long-term security architecture.
The startup and market narrative was just as telling as the formal agenda. The Innovation Sandbox finalists leaned heavily into AI agent security, AI governance, AI-native code security, and identity for the AI era. Geordie AI was positioned around security and governance for AI agents. vendors focused on governing AI agents and non-human identities. Emphasizing next-generation authentication built for the AI era. There was representation on the push toward AI-native application and code security. At the same time, vendors framed RSAC 2026 as a race to find the next major AI-security category leader, with growing pressure on incumbents to adapt through acquisition, platform change, or both. That is not random conference noise. That is market direction showing up in real time.
My personal view is that this tells us the industry is moving toward a much tighter convergence of identity, governance, observability, and automation. In other words, the next phase of cybersecurity will not be won by point features alone. It will be won by an ecosystem of functions and operating models that can answer very basic but very important questions, consistently and fast: what exists, who owns it, what can it access, how is it behaving, is that behavior/action legitimate, is the intent validated, and what do we do about it now? That is true for human identities, machine identities, cloud entitlements, AI agents, and the workflows that connect them. The winners will be the organizations that can turn this complexity into controls, evidence, and action without making operations harder than they need to be. That direction is strongly supported by RSAC's trend framing and by the market energy around AI-native security at this year's event.
That said, I also came away with a note of caution. Those of us in the field need to keep this practical. We need to keep it actionable. We need to keep it understandable. It is easy at a conference like RSAC for the market to get ahead of itself, especially when every booth, every session, and every conversation seems to include the words AI, agentic, autonomous, or platform. But if we push the language too far ahead of execution, or make the message too abstract for customers trying to solve real problems right now, we lose people. We also risk creating confusion where clarity is needed most. The organizations that will move fastest are not necessarily the ones with the boldest language. They are the ones that can connect big ideas to immediate control improvements, operating discipline, and measurable outcomes. RSAC's own emphasis on actionability, grounded in fundamentals, was a timely reminder of exactly that.
I also believe the market is responding the way markets always do when a real shift becomes impossible to ignore. Buyers are trying to figure out what is genuinely new, what is rebranding, what belongs in the existing stack, and what requires a new control plane altogether. Vendors are racing to prove relevance. Startups are rushing into open white space. Larger players are trying to show they can evolve fast enough to matter. That is why identity, governance, AI agent visibility, AI-native security operations, and practical automation are getting so much attention. The demand is real because the problem is real. The attack surface is changing, the operating model is changing, and the security industry knows it.
For me, that is what RSAC 2026 ultimately meant. Yes, it was crowded. Yes, it was busy. Yes, it was a good week to reconnect with people I respect across the industry. But beyond that, it was clarifying. It showed that cybersecurity is entering a phase where community still matters, perhaps more than ever, but community alone is not enough. We now need shared understanding, practical execution, and a more disciplined way to bring emerging security concepts down to earth. That is where the industry needs to go next, and that is where the most credible leaders in the field should stay focused.
David (DJ) Morimanno is the Field CTO at Xalient, where he helps organisations design and deliver identity-centric security strategies for complex, fast-evolving environments. With over 20 years of experience, he brings deep expertise across identity governance, privileged access, access management, and broader identity security programs. As a practitioner, advisor and strategist, he supports clients in translating identity into practical, scalable capabilities.
His work focuses on modern identity challenges, including non-human and machine identities, AI governance, cloud entitlements, identity threat detection and response, and Zero Trust. DJ advises senior leaders and Fortune 500 organisations across sectors such as energy, healthcare, manufacturing, and financial services, helping them turn emerging trends into clear operating models and measurable security outcomes.