Skip to Content

Tevora Ranks No. 12 on Fast Company's Annual List of the 100 Best Workplaces for Innovators Read Press Release

Dark teal and black gradient

Webinar

Innovation 2025: What to Look for at RSA Conference This Year

With over 41,000 attendees and 600+ exhibitors, RSA Conference continues to set the tone for where the cybersecurity industry is headed next. But with so much happening, how do you know what’s worth your time? In this pre-conference session, Tevora’s RSA veterans—Ben Dimick, Mark Broghammer, Josh Johnson, and Ayo Adeusi—share their insider picks on what to watch for at RSA Conference 2025. These industry leaders have combed through the agenda and exhibitor lineup to spotlight the trends, technologies, and breakout vendors that are set to make waves.

Key Takeaways:

  • Key trends we expect to define the conference
  • The product categories gaining momentum
  • Startups and innovators who are doing things differently
  • What we’re most excited about from the Innovation Lab

Whether you’re attending in person or tuning in from afar, this is your roadmap to RSA 2025.

Innovation 2025: What to Look for at RSA Conference This Year

Each year, the RSA Conference serves as a barometer for where the cybersecurity industry is headed. From emerging startups and Innovation Sandbox finalists to major platform vendors unveiling new capabilities, RSA often reveals the technologies and strategies that will dominate security conversations for years to come.

In this discussion, Mark Broghammer (Head of Security Pre-Sales Architecture at Tevora) was joined by Josh Johnson (Principal Architect) and Christian Navarro (Senior Pre-Sales Architect) to discuss what they expected to see at RSA Conference 2025, the trends worth paying attention to, and how security leaders can separate meaningful innovation from marketing hype.


What Makes RSA Valuable?

Before diving into the technology trends, the panel reflected on what keeps bringing them back to RSA year after year.

For Josh, RSA is as much about networking as technology.

“Everyone tends to be in the same places during RSA. It’s one of the best opportunities to reconnect with peers and have meaningful conversations outside the conference floor.”

Christian emphasized practical preparation:

  • Wear comfortable shoes.
  • Stay hydrated.
  • Expect heavy traffic throughout San Francisco.
  • Plan your meetings in advance.

The consensus: RSA can be overwhelming, and attendees get the most value when they arrive with a clear plan rather than wandering the expo floor.

Theme #1: AI Is Everywhere

Unsurprisingly, the dominant theme expected at RSA 2025 was artificial intelligence.

But this year’s conversation is different from previous years.

Organizations are no longer asking whether to adopt AI—they’re asking how to do so securely.

The Rise of AI Governance

Josh explained that enterprises are increasingly embracing:

  • Microsoft Copilot
  • Google Gemini
  • AWS AI services
  • Salesforce AI capabilities
  • Custom and local large language models (LLMs)

The challenge isn’t enabling AI. It’s controlling it.

Organizations want to ensure users can take advantage of AI-powered productivity without:

  • Exposing sensitive customer data
  • Sharing proprietary information
  • Violating compliance requirements
  • Introducing unacceptable risk

This has created demand for a new category of controls that sit between users and AI systems.

These solutions focus on:

  • Prompt-level inspection
  • Data leakage prevention
  • AI governance
  • Usage monitoring
  • Risk management

AI Creates New Security Challenges

Christian noted that AI adoption introduces challenges extending beyond external threats.

Organizations must consider:

  • What data is feeding their AI systems
  • Who can access AI-generated outputs
  • How local LLMs are governed
  • Whether AI usage aligns with privacy and compliance requirements

The rise of AI regulations—including the EU AI Act and emerging governance frameworks such as ISO 42001—means AI security is becoming as much a governance issue as a technical one.

How to Evaluate AI Vendor Claims

One concern shared by the panel was the growing number of vendors marketing themselves as “AI-powered.”

The recommendation?

Ask direct questions:

  • Is the solution leveraging an LLM?
  • Is it using an external or proprietary model?
  • Is it agentic AI or traditional machine learning?
  • How transparent are AI-generated decisions?
  • How is customer data protected?

Not every product labeled “AI” is actually using modern AI technologies, and understanding the distinction matters.

Theme #2: The Automated Security Operations Center

Another major topic expected at RSA is AI-driven security operations.

For years, organizations have tried to reduce alert fatigue and accelerate investigations through automation.

AI is adding a new layer to that effort.

Can AI Accelerate Incident Response?

Christian believes there is real value in AI-assisted security operations.

Potential benefits include:

  • Faster alert triage
  • Automated correlation and enrichment
  • Improved threat detection
  • Reduced false positives
  • Accelerated investigation workflows

By processing enormous volumes of security telemetry, AI can help identify patterns that human analysts might overlook.

Human Oversight Still Matters

However, the panel repeatedly emphasized a critical caveat:

AI should augment analysts—not replace them.

Organizations need visibility into:

  • How decisions are being made
  • Why alerts are escalated
  • How false positives are determined

Josh stressed that security leaders must be able to explain how AI-driven workflows operate.

If a breach occurs and an AI system misses it, “the AI made a mistake” will not be an acceptable explanation.

Transparency remains essential.

Theme #3: The Emergence of Non-Human Identity (NHI)

One of the fastest-growing areas in cybersecurity is the management of non-human identities.

These include:

  • Service accounts
  • API keys
  • Certificates
  • Application identities
  • Bots
  • Machine-to-machine credentials

Why NHI Matters

Mark highlighted that non-human identities often outnumber human identities by a significant margin.

Many organizations have mature employee onboarding and offboarding processes, but:

  • Machine identities are frequently overlooked.
  • Ownership is often unclear.
  • Credentials are rarely rotated consistently.

As organizations continue moving to the cloud and automating workflows, managing these identities becomes increasingly important.

What Security Leaders Should Evaluate

When assessing NHI platforms, the panel recommended focusing on:

Discovery

Can the platform identify all non-human identities across environments?

Visibility

Can it establish ownership and accountability?

Risk Analysis

Can it identify abnormal usage patterns?

Lifecycle Management

Can it automate:

  • Provisioning
  • Rotation
  • Revocation
  • Expiration monitoring

Integration

Can it work seamlessly across:

  • Cloud environments
  • On-premises infrastructure
  • Existing IAM solutions

The panel agreed that discovery alone is no longer enough. Organizations increasingly want actionable remediation and automation capabilities.

Theme #4: Post-Quantum Cryptography

Post-quantum cryptography (PQC) remains a developing topic, but one gaining increasing attention.

Is PQC an Immediate Concern?

Josh believes most organizations still have time.

The biggest risks currently apply to:

  • Nation-state targets
  • Critical infrastructure organizations
  • Highly regulated entities
  • Organizations concerned about “harvest now, decrypt later” scenarios

However, he argues every organization should begin understanding:

  • What cryptographic standards they use
  • Where certificates are deployed
  • How cryptographic systems are managed

Preparing now makes future migrations significantly easier.

Who Is Leading Adoption?

The panel expects to see the greatest interest from:

  • Governments
  • Financial institutions
  • Critical infrastructure providers

These sectors are likely to be the earliest adopters of post-quantum security strategies and technologies.

Theme #5: Threat Exposure Management Evolves

Traditional asset management and vulnerability management continue evolving into broader exposure management initiatives.

Christian expects AI to play a growing role in:

  • Asset discovery
  • Risk prioritization
  • Threat correlation
  • Exposure analysis

The goal is to move beyond static inventories and toward more dynamic risk visibility.

However, Mark raised an important question:

Does this become another dashboard security teams have to monitor, or will it effectively integrate into existing workflows?

That remains one of the most important questions organizations should ask vendors in this space.

Deepfake Prevention and Identity Verification

One of the more forward-looking topics discussed was deepfake detection and prevention.

The Hiring Challenge

Josh highlighted a growing concern:

Organizations are increasingly encountering sophisticated identity fraud during hiring processes, including:

  • Deepfaked video interviews
  • Synthetic identities
  • AI-generated personas

As remote work and remote hiring continue, verification becomes significantly more difficult.

Why This Matters

Deepfake technology creates entirely new insider-risk scenarios.

Security leaders may soon need to consider:

  • Identity verification services
  • Biometric validation
  • Video authenticity technologies
  • Enhanced hiring controls

The panel expects deepfake mitigation to become a larger cybersecurity category in the coming years.

The RSA Innovation Sandbox Remains a Must-Watch

One consistent recommendation from all three panelists was to pay attention to the RSA Innovation Sandbox.

Why It Matters

Historically, many Sandbox finalists have gone on to become major industry players.

Examples include:

  • Wiz
  • Axonius
  • Talon
  • SentinelOne

Many finalists are later:

  • Acquired by major vendors
  • Integrated into larger platforms
  • Responsible for defining entirely new security categories

As Josh noted:

“The Innovation Sandbox often shows us what cybersecurity will look like three to seven years from now.”

What Trends Are Less Exciting?

Not every security category generated enthusiasm.

DSPM Consolidation

Mark suggested that Data Security Posture Management (DSPM) may be entering a consolidation phase.

While valuable, many vendors currently provide similar capabilities around:

  • Discovery
  • Classification
  • Visibility

He expects the next stage of market maturity to focus on deeper integration and actionable remediation.

Traditional DevSecOps Tooling

The panel also noted that many DevSecOps tools have become highly commoditized.

While innovation still exists around:

  • Container security
  • Supply chain protection
  • Image validation

they are no longer generating the same level of excitement as newer categories such as AI governance and non-human identity management.

Final Advice for RSA Attendees

If there was one recurring theme throughout the discussion, it was this:

Start with your business problems—not vendor marketing.

Before evaluating any technology, security leaders should understand:

  • Their priorities
  • Their gaps
  • Their risks
  • Their operational requirements

Only then can they determine whether a platform, point solution, or emerging innovation provides genuine value.

As the panel concluded, RSA remains one of the best opportunities to see where cybersecurity is heading—but the most successful attendees will be the ones who arrive with clear objectives and leave with practical insights rather than just product brochures.

Looking to discuss RSA trends, AI governance, identity management, or exposure management?
The Tevora team regularly helps organizations evaluate security technologies, optimize security programs, and align emerging technologies with business objectives.

Authors