
← David Bombal20 Aug · 28 min
#596: This is the Real Cybersecurity Problem
Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.
Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.
For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.
They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.
Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.
Topics include:
Why cybersecurity may be a software quality problem
Why users are blamed for insecure software
CISA’s Secure by Design initiative
Why default passwords should disappear
AI agents behaving in unexpected ways
AI and the future of zero-day attacks