
About this episode
Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.
Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.
For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.
They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.
Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.
Topics include:
Why cybersecurity may be a software quality problem
Why users are blamed for insecure software
CISA’s Secure by Design initiative
Why default passwords should disappear
AI agents behaving in unexpected ways
AI and the future of zero-day attacks
Memory safety, C, C++ and Rust
Government regulation and vendor accountability
The EU Cyber Resilience Act
Why Patch Tuesday may eventually become unacceptable
How AI could help defenders find and fix vulnerabilities
Jen Easterly’s advice for cybersecurity professionals
If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.
// Jen Easterly’s SOCIAL //
LinkedIn: / jen-easterly
// Website REFERENCE //
https://www.cisa.gov/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: [email protected]
// MENU //
0:00 - Coming up
0:55 - Jen Easterly introduction & background
04:20 - Advice for the youth
07:10 - Advice for ethical hackers and leadership
11:35 - Software security // Who's to blame?
17:39 - Power and responsibility
21:17 - Secure by design
26:38 - Is it important to attend RSAC? // Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#rsac #bhusa2026 #securebydesign
Get every episode summarized
Each time David Bombal publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from David Bombal

#600: This Free Tool Decodes Game Boy ROM From a Photograph
David Bombal

#599: This Pocket Tool Diagnoses Wi-Fi in 45 Seconds
David Bombal

#598: AI Can’t Understand Intent. That’s a Security Problem
David Bombal

#597: The Hacking Gadgets You Need to Know
David Bombal