#596: This is the Real Cybersecurity Problem episode artwork

EPISODE · Aug 20, 2026 · 28 MIN

#596: This is the Real Cybersecurity Problem

from David Bombal · host David Bombal

Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.Topics include:Why cybersecurity may be a software quality problemWhy users are blamed for insecure softwareCISA’s Secure by Design initiativeWhy default passwords should disappearAI agents behaving in unexpected waysAI and the future of zero-day attacksMemory safety, C, C++ and RustGovernment regulation and vendor accountabilityThe EU Cyber Resilience ActWhy Patch Tuesday may eventually become unacceptableHow AI could help defenders find and fix vulnerabilitiesJen Easterly’s advice for cybersecurity professionalsIf you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.// Jen Easterly’s SOCIAL // LinkedIn: / jen-easterly // Website REFERENCE // https://www.cisa.gov/ // David's SOCIAL // Discord: discord.com/invite/usKSyzbTwitter: www.twitter.com/davidbombalInstagram: www.instagram.com/davidbombalLinkedIn: www.linkedin.com/in/davidbombalFacebook: www.facebook.com/davidbombal.coTikTok: tiktok.com/@davidbombalYouTube: / @davidbombalSpotify: open.spotify.com/show/3f6k6gE...SoundCloud: / davidbombalApple Podcast: podcasts.apple.com/us/podcast...// MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: [email protected] // MENU // 0:00 - Coming up 0:55 - Jen Easterly introduction & background 04:20 - Advice for the youth 07:10 - Advice for ethical hackers and leadership 11:35 - Software security // Who's to blame? 17:39 - Power and responsibility 21:17 - Secure by design 26:38 - Is it important to attend RSAC? // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #rsac #bhusa2026 #securebydesign

Episode metadata supplied by the publisher feed · Published Aug 20, 2026

Embed this episode

Ready to play

#596: This is the Real Cybersecurity Problem

0:00 28:03

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of David Bombal?

This episode is 28 minutes long.

When was this David Bombal episode published?

This episode was published on August 20, 2026.

Can I download this David Bombal episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!