This is the Real Cybersecurity Problem
Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.
Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.
For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.
They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.
Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.
Topics include:
Why cybersecurity may be a software quality problem
Why users are blamed for insecure software
CISA’s Secure by Design initiative
Why default passwords should disappear
AI agents behaving in unexpected ways
AI and the future of zero-day attacks
Memory safety, C, C++ and Rust
Government regulation and vendor accountability
The EU Cyber Resilience Act
Why Patch Tuesday may eventually become unacceptable
How AI could help defenders find and fix vulnerabilities
Jen Easterly’s advice for cybersecurity professionals
If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.
// Jen Easterly’s SOCIAL //
LinkedIn: https://www.linkedin.com/in/jen-easterly
// Website REFERENCE //
https://www.cisa.gov/
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
X: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/@davidbombal
Spotify: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: https://soundcloud.com/davidbombal
Apple Podcast: https://podcasts.apple.com/us/podcast/david-bombal/id1466865532
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming up
0:55 - Jen Easterly introduction & background
04:20 - Advice for the youth
07:10 - Advice for ethical hackers and leadership
11:35 - Software security // Who's to blame?
17:39 - Power and responsibility
21:17 - Secure by design
26:38 - Is it important to attend RSAC? // Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#rsac #bhusa2026 #securebydesign
David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Linux, Python, Ethical Hacking, Networking, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos upload...