Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free TrialIn another keynote, Tom Gillis, senior vice president and general manager at Cisco, agreed about the need to protect critical infrastructure and said cybersecurity leaders should harness the power of AI to bolster defenses while avoiding getting caught up in the hype around the technology.
Tim GillisAs AI gets weaponized by adversaries, the only way to stop those attacks is by making sure that you can use AI natively in your defenses.
RSAC speaker Elie Bursztein, an AI cybersecurity technical and research lead at Google’s DeepMind, shared optimistic thoughts with attendees concerning AI. His talk highlighted the ways in which cybersecurity can use GenAI for the better, such as identifying and fixing security risks in open-source repositories or remediating software vulnerabilities.
Elie BurszteinAI is eventually going to give us back the advantage [over AI-empowered adversaries] because the upside of using it is really, really large.
While AI looks promising for SSCS, more research and innovation needs to happen before the technology can reach its full potential in outpacing adversaries, he said.
RSAC has usually been an avenue for government officials to share key updates regarding cybersecurity policies and initiatives. This year’s show was no exception, and SSCS was in the spotlight.
In his keynote speech, U.S. Secretary of State Antony J. Blinken laid out his department’s goals in securing the digital systems that power the nation’s critical infrastructure.
Antony J. BlinkenThe distinction between the digital and physical realms is eroding.
To account for this concern, Blinken unveiled the new U.S. International Cyberspace and Digital Strategy, which he said treats digital solidarity "as our North Star." Blinken defined digital solidarity as the shared understanding among the tech world that it is necessary to be responsible and safe with emerging technologies.
This new strategy aims at aiding SSCS efforts, confirming the need to ensure that new software products and version releases are secure from threats. Those threats include malicious tampering with code, the exposure of software secrets and credentials, and more. Blinken said that the U.S. government is using its discretion to further SSCS and other cybersecurity goals.
Antony J. BlinkenThe United States is forging tech partnerships that will make critical technology supply chains more resilient, more diverse, [and] more secure. It is crucial that we work with trustworthy vendors and exclude untrustworthy ones from the ecosystem.
Jen Easterly, director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA), unveiled new efforts from the agency that align with Blinken’s concern for digital solidarity. The CISA’s Secure by Design initiative, released over a year ago, has now expanded to include the Secure by Design Pledge, which is described as a “voluntary pledge focused on enterprise software products and services.”
The goal is that software producers that sign the pledge will promise to make a good-faith effort during the ensuing year to adopt seven goals, which include reducing entire classes of vulnerabilities and increasing visibility for product customers into cybersecurity intrusions. Several notable companies have already signed the pledge, including Microsoft, CrowdStrike, Google, and SentinelOne. The CISA is encouraging software firms that are interested in taking the Secure by Design Pledge to email the agency at SecureByDesign@cisa.dhs.gov.
Join ReversingLabs for a live discussion with two top cybersecurity experts (and RSAC 2024 speakers) on Wednesday, May 22 at 12 pm ET. Speakers include Devici's Chris Romeo and BlackGirlsHack's Tennisha Martin, who will share their top takeaways from this year’s big show — and answer your questions.

While prompt injection and data disclosure remain concerns, excessive agency climbed the list — not surprising with recent security incidents.
The post-mortems of two compromises by rogue AI agents show that security teams need to focus on guardrails, not the AI model.


