San Francisco, 23–26 March. The 35th annual RSA Conference filled Moscone with the usual mix — 700-plus speakers, 31 tracks, more than 570 sessions and 600-plus exhibitors — but the underlying industry mood was noticeably more grown-up than it was two or three cycles ago. The 2026 conference theme was “Power of Community”; the more honest through-line, walking the halls, was that the cybersecurity community has spent the last twelve months learning how to defend against tools that its own defenders now use.
Agentic AI on both sides of the fight — as attack tooling and as defensive infrastructure — dominated more sessions than any other topic. Identity remained the most-cited root cause in incident postmortems. Post-quantum cryptography migration moved from research topic to a project plan sitting on regulated buyers’ desks. And the RSAC Innovation Sandbox, the show’s annual startup competition, quietly told the venture market where the next round of enterprise security money is going.
A keynote line-up designed to broaden the room
The RSAC organisers used the keynote roster to pull the conversation off the vendor-executive treadmill. Former New Zealand Prime Minister Dame Jacinda Ardern keynoted on democratic resilience, disinformation, and the trust dimension of critical infrastructure — a framing that landed harder than it would have five years ago, given the run of election-year cyber and cognitive incidents the industry has processed since Christchurch. Ben Horowitz of Andreessen Horowitz gave a venture-perspective keynote on where security capital is actually deploying, with a heavy tilt toward agentic AI-defensive tooling and identity-native infrastructure. Michael Lewis and Adam Savage brought their respective non-industry frames — narrative journalism and applied engineering — into a room that has, historically, defaulted to too much CISO-to-CISO groupthink.
The pattern of the keynote roster mattered. RSAC 2026’s message was that cybersecurity is now too consequential to be discussed only inside its own vocabulary. The community-theme framing was, at its best, an argument for cross-disciplinary participation.
Agentic AI: the attack surface just got redrawn
The dominant technical narrative of the 2026 show was the maturation of agentic AI as an attack surface — and, in parallel, as defensive infrastructure. On the offensive side, red-team demonstrations showed reproducible attack patterns against enterprise AI agents: prompt injection through untrusted document contexts, tool-chain confusion attacks that trick agents into misusing legitimate integrations, over-permissioned agent identities that expand blast radius when compromised, and audit-log gaps that hide entire multi-step attack sequences.
The defensive-side story was a step further along than at the 2025 conference. Vendors led with least-privilege agent identities, structured tool interfaces with strict schemas, provenance-verifiable inputs, and observability platforms designed specifically for agent-driven workloads rather than retrofitted from user-behaviour analytics. Several of the more credible enterprise-AI security offerings were building on the identity infrastructure their customers had bought over the previous three years — an unglamorous but correct architectural bet.
The candid version of the 2026 conversation, in the corridors: agentic AI has raised the tempo on both sides without shifting the underlying discipline. The organisations winning the operational fight in 2026 are the ones with tight identity governance, disciplined logging, and the willingness to say no to agent deployments that cannot be audited. The tooling helps. The discipline decides.
Identity is still the perimeter
The other consistent through-line was identity. In the incident-response case studies presented on stage and on the sidelines, session hijack, MFA fatigue, help-desk social engineering, and service-principal takeover continued to lead the root-cause list — as they have every year of the recent conference cycle. What was different in 2026 was the maturity of the vendor response. Identity threat detection and response has become a category in its own right, with its own analyst coverage, its own pricing category, and — importantly — a defensible integration story with SIEM, XDR, and cloud-security platforms.
Zero trust, after several years of being flattened into a marketing bumper sticker, has arrived at the enforcement stage in a growing number of large deployments. Nobody is announcing “we did zero trust” as a slide any more. The people who did it are quietly running it.
Post-quantum cryptography becomes a project plan
Post-quantum cryptography — the migration to algorithms designed to resist attack by future large-scale quantum computers — had its most operational RSAC yet. The US federal 2035 migration deadline, NIST’s finalised standards, and follow-on procurement guidance across the EU, UK, Japan and Australia have collectively created a real programme-management picture. Regulated buyers — financial services, defence, healthcare, telecommunications — presented cryptographic inventories, migration roadmaps, hybrid TLS deployments, and hardware-lifecycle plans that acknowledged the very expensive reality of the transition.
The bottleneck story was consistent across sectors. It is not the algorithms. It is inventory: knowing where cryptography lives across code, hardware, third-party dependencies, embedded systems, and legacy protocols. Vendors offering cryptographic-inventory tooling — a category that barely existed at RSAC 2023 — had queues at their booths. Post-quantum is now, unambiguously, an audit item and a board-level risk.
Offensive cyber caught up to defensive tempo
The offensive-tooling and adversary-simulation tracks were unusually well-attended. AI-augmented offensive tooling — reconnaissance, credential stuffing, phishing generation, initial-access automation — has closed the tempo gap with defensive automation. Several sessions candidly discussed the market for pre-trained offensive AI models on the criminal side and the disciplined red-team programmes that use similar tooling with authorisation.
Election-adjacent influence operations, election infrastructure resilience, and civic-cybersecurity readiness had their own dedicated track this year. The tone was operational rather than headline-hunting: shared threat intelligence between vendors and civic infrastructure operators, provenance mechanisms for public communications, and coordinated-disclosure playbooks for state-level election systems.
Resiliency as the new procurement bar
The word “resiliency” showed up more than “prevention” in this year’s stage material, and it wasn’t accidental. The maturing US Securities and Exchange Commission material-incident disclosure regime, the CIRCIA reporting framework, the EU’s NIS2 and DORA rules, and equivalent obligations in the UK, Australia and Japan have collectively shifted regulated-industry security posture. The benchmark is no longer “did you stop the intrusion?” It is “how quickly and completely did you recover, how honestly did you disclose it, and how much of your business held together while you did?”
That framing changes what security procurement optimises for. Backup and recovery, tabletop exercises, incident-response readiness, communications playbooks, and legal-technical coordination now sit alongside prevention in a serious buyer’s evaluation. Vendors that show up with capable prevention products but poor resiliency-integration stories are getting shorter meetings.
The Innovation Sandbox tells the venture story
The RSAC Innovation Sandbox — the annual startup competition that has historically been a fair leading indicator of where enterprise security money will deploy over the following 24 months — leaned this year toward agentic-AI defensive tooling, identity-native security fabrics, and post-quantum cryptography enablement. Several finalists in the AI-security category built explicitly on identity infrastructure rather than pitching a standalone agent-security platform. The venture-market read is that identity-adjacent AI security wins the enterprise budget; standalone AI security struggles to build defensible category.
What RSA 2026 actually moved
- Agentic AI is a category on both sides of the fight. Enterprises with tight identity governance and audit discipline are ahead.
- Identity is still the perimeter. The tooling matured; the discipline decides.
- Post-quantum is a project plan. Not a research topic.
- Resiliency is the procurement metric. Disclosure regimes reshaped the buyer’s evaluation.
- Community-theme framing pulled the room wider. Cybersecurity is too big to be discussed only in its own vocabulary.
Open questions
Does the enterprise agentic-AI security category consolidate into identity-adjacent offerings, or hold as a standalone stack? Does the post-quantum migration budget survive the first hard fiscal year for regulated buyers, or slip against competing security priorities? And does the resiliency framing outlive its regulatory drivers, or fall back into a prevention-first posture once the current disclosure cycle stabilises?
Bottom line: RSA 2026 was the year the cybersecurity community stopped pretending the AI conversation was optional and started running its actual operational playbook against it. Identity, resiliency and post-quantum are the three lines every serious buyer will justify to a board this year. The vendors that align to those lines are being bought. The vendors that don’t are running out of time.