Highlights of the upcoming 2020 RSA Conference, exploring RSA's human element theme, and why fist bumps are probably socially acceptable this year. These stories and more in this week's ISMG Security Report. Hello, I'm Nick Holland. It's that time again, the world's largest cybersecurity event, the 2020 RSA Conference in San Francisco, is only days away.
The ISMG editorial team will be out in force with two video recording studios, one at the Marriott Marquis Hotel and another in Broadcast Alley at Moscone West. Please do come and say hi if you pass us. There's a good chance we can meet in person. This week's Security Report podcast is a prequel to the event.
You'll be hearing from RSA's former CEO, Art Coviello, on what he predicts will be the key themes for this year. You'll also hear from internationally renowned pandemic and disaster management expert Regina Phelps about steps that you can take to minimize exposure to viruses and other pathogens while enjoying the conference's abundant networking opportunities. But first, here's ISMG's Executive Editor, Data Breach Today in Europe, Matthew Schwartz, with his rundown of key highlights for next week's show. Who's heading to RSA?
The largest annual gathering of information security professionals is coming up fast. Running from February 24th to 27th at San Francisco's Moscone Center, this will be the conference's 29th edition. As in years past, the event will kick off on a Monday with keynote speeches debuting Tuesday, featuring some of the biggest names in cybersecurity addressing today's hottest topics, technologies, conundrums, and aspirations. Some of the many luminaries delivering keynotes this year include Chris Krebs, who heads the U.S.
Cybersecurity and Infrastructure Agency, British expert in human nature and cybersecurity Jessica Barker, Golden Sachs cyber advisor Phil Venables, bug bounty expert Katie Moussouris, CrowdStrike CEO George Kurtz, RSA president Rohit Ghai, Cisco's Wendy Nather, Industrial cybersecurity expert Rob Lee, NSA researcher Celeste Paul, and Bruce Schneier. Guests and speakers also include astronauts Mike Massimino and Peggy Whitson. And for anyone who sticks around to the bitter end on Friday, magicians Penn and Teller. The conference will cover a lot of ground.
This year's RSA theme is the human element, which encapsulates not just the requirement for cybersecurity to be designed with humans in mind and not to blame humans for technology and design shortcomings, but also reflects the increasing discussion about mental health and sustainability in what is often a high-stress, nonstop profession. What else is hot? Organizers received more than 2,400 responses to their call for speakers this year and said some of the other dominant themes being discussed by the industry right now include secure product design, privacy and compliance, especially after GDPR, security and IT frameworks, workforce development, security awareness and training, DevSecOps, and threat intelligence. As that massive range of topics reflects, the industry has matured massively in recent years.
But then again, so too has RSA. For anyone not in the know, RSA takes its letters from the initials of Ron Rivest, Adi Shamir, and Leonard Adleman, who first publicly described the pioneering RSA public key cryptosystem in 1977. They then co-founded RSA Security in 1982, which later came to launch and organize the RSA Conference. Subsequently, the renamed RSA was sold to EMC, which was later acquired by Dell.
This week, Dell announced the pending sale of RSA, conference included, to a private equity group. Business dealings aside, one of the highlights of the conference remains Ravastin Shamir taking to the stage as part of the annual Cryptographers panel. Shamir, an Israeli citizen, was unfortunately absent last year because the U.S. government declined to give the world-famous cryptography expert a visa.
But he's due back this year to join Whitfield Diffie, Arvind Narayanan, and Tal Rabin on stage. Overall, there will be more than 30 keynotes happening across two stages as part of a total of more than 500 educational sessions featuring more than 700 speakers. This year's conference has 30 tracks, including analytics, intelligence, and response, application security and DevOps, applied crypto and blockchain, as well as hackers and threats, machine learning and AI, and technology operations and infrastructure, for starters. As that suggests, this year's RSA conference, which is expected to draw more than 40,000 attendees, will cover a huge amount of territory.
In and amongst it all, hope to see you there. For Information Security Media Group, I'm Matthew Schwartz. You're listening to the ISMG Security Report on ISMG Radio. ISMG, your number one source for information security news.
Every year, the RSA conference has an overarching theme. These have ranged from 2016's Connect to Protect, focusing on the power of networks, to 2018's Now Matters, relating to the immediacy of focusing on tomorrow's threats today, to 2019's single word, Better, with an emphasis on everyone owning a piece of the collective cybersecurity responsibility. This year, the theme is the human element. And who better to discuss this than the former CEO of RSA, Art Coviello?
I asked Art what he thought this theme meant and what some of the other prevailing themes would be this year. Here he is. Yeah, I think it's a great choice for the theme. There'll probably be in the neighborhood of 600 or 700 companies, technology companies, exhibiting.
And when you talk about security, everybody talks about people, process, and technology. And unfortunately, we tend to look at technology as the be-all, end-all. But if you miss out on the people and process part, you're doomed to failure. So there's all kinds of elements around the people side.
You know, the skill shortage that exists in terms of people staffing security infrastructures, the skill shortage around people to develop the technology. There's such a competition for talent just across the board. And then there's the inevitable education side of the human element. The rather glib expression is who needs a zero-day attack when it's stupid?
So there's all kinds of human element stories and themes that can be played out at the conference. And I think it's a good choice. Very good. So, I mean, talking about themes for the conference, I mean, what's your hunch about this year's biggest themes other than, I have to say, Purell hand sanitizer?
Yeah, well, I think everybody is conscious of that human virus. So we tend to focus on the more technology viruses at the conference. But, you know, I think big things will be around nation-state attacks. You know, China was just called out as the perpetrator of the Equifax attack.
And they were the perpetrators of the attack on the Office of Personnel Management a few years back. So clearly, they're gathering all kinds of information about individual citizens. Iran, because of the stepping back from the treaty, has been very active now. They've obviously been active in the Middle East.
Russia, of course. And one of the things I didn't foresee coming was really the scourge of social media and how that is being misused to spread misinformation, not only about elections, but it makes for quite a successful attack venue for social engineering type attacks. So I think those will be some of the macro themes. I'm actually on a panel with former Secretary Chertoff and former DNI Admiral Blair.
And we'll be talking about 5G security, especially as it relates to implementation of Huawei switches. So there'll be nation-state oriented themes. And then, again, at high level, themes around artificial intelligence and how to secure cloud. Third-party risk is going to be another very large one.
For such a large international conference, with attendees flying in from every corner of the globe, the elephant in the corner for this year's RSA conference are concerns relating to the spread of the novel coronavirus originating out of China. The virus has already had an impact on other large conferences, forcing the cancellation of this year's Mobile World Congress in Barcelona. And closer to home, causing some high-profile sponsors, such as IBM and AT&T, to pull out of the RSA conference. Tom Field, ISMG's SVP of editorial, reached out to internationally renowned pandemic and disaster management expert Regina Phelps to put the recent virus outbreak into context and to give some advice on what you can do at the conference to mitigate your risk of infection from, well, most things.
For the squeamish, I'll spare you her comments on airport self-check-in counters and seat-back trays and leave you with some sage advice on how to maintain social interaction norms at the conference. Hope to see you there. So, I mean, your hands are like the dirtiest thing in the universe, right? I know we look at our hands and think, wow, they look great.
I frankly would be very inclined to say, I'm not going to shake your hand just because of, you know, there's a lot of bugs going around and not make a big deal out of it. I try to really not shake anybody's hands, to be honest with you, in the last month. So a couple of things. If you're going to engage in a conversation with people, it's not saying that you should not be social.
You should not be talking to people. I frankly would probably just resist shaking anybody's hand and just say, hey, you know, there's a lot of germs going around. I'm just going to not shake anybody's hand. Flu season has been bad this year.
Secondly, I would say is I would carry hand sanitizer in my pocket if I was at RSA. And I would just be, every once in a while, every 15 minutes or something, if I'm walking from one booth to the next booth or I'm talking to another person, I just put them on my hands. Every time you walk by a bathroom, stop and wash your hands. And the last thing I'd like to share with you guys, which