
Post-RSAC Conference 2026 Recap: Agentic AI, Data Sovereignty, and the New Security Perimeter | A Brand Highlight Conversation with Thyaga Vasudevan, EVP, Product of Skyhigh Security
About this episode
If you walked RSAC Conference 2026 expecting incremental updates, you left with something very different. Thyaga Vasudevan, EVP, Product at Skyhigh Security, describes this year as unlike any prior conference -- not because of a single announcement, but because the customers asking how to secure agentic AI were the same customers already building and deploying it. The urgency was real, immediate, and universal across organization sizes.
The defining theme was agentic security. Vasudevan frames it around three core questions every security team now needs to answer: who is acting (agent identity), what are they accessing (data and APIs), and what are they trying to do (actions and permissions). The ChatGPT launch in November 2022 marked a generational shift -- and at RSAC 2026, Skyhigh Security observed that the industry had moved decisively from data-in and data-out protection to governing the actions of autonomous agents themselves.
Data sovereignty was the other major conversation thread, driven by geopolitical realities and tightening regional data regulations. Vasudevan spoke with CISOs from financial services, healthcare, public sector, and not-for-profit organizations, each with different infrastructure approaches -- from on-prem data centers to sovereign clouds to full cloud deployments -- but all navigating the same fundamental challenge. DSPM and hybrid architectures are no longer optional for global enterprises. And quietly but significantly, browser security emerged as a front-and-center priority, reflecting the browser's growing role as a primary cloud endpoint.
This is a Brand Highlight. A Brand Highlight is a ~5 minute introductory conversation designed to put a spotlight on the guest and their company. Learn more: https://www.studioc60.com/creation#highlight
GUEST
Thyaga Vasudevan, EVP, Product, Skyhigh Security
LinkedIn: https://www.linkedin.com/in/thyaga12/
RESOURCES
Skyhigh Security: https://www.skyhighsecurity.com
RSAC Conference 2026 Coverage: https://itspmagazine.com/rsac26
Are you interested in telling your story?
▶︎ Full Length Brand Story: https://www.studioc60.com/content-creation#full
▶︎ Brand Spotlight Story: https://www.studioc60.com/content-creation#spotlight
▶︎ Brand Highlight Story: https://www.studioc60.com/content-creation#highlight
KEYWORDS
Thyaga Vasudevan, Skyhigh Security, Sean Martin, Marco Ciappelli, brand story, brand marketing, marketing podcast, brand highlight, agentic AI security, data sovereignty, SSE, Security Service Edge, DSPM, zero trust, browser security, cloud security, RSAC Conference 2026, RSAC 2026, AI agent security, MCP security
Get every episode summarized
Each time The ITSPmagazine Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
107 searchable segments. Every word is indexed and playable.
Full transcript
The ITSPmagazine Podcast — Post-RSAC Conference 2026 Recap: Agentic AI, Data Sovereignty, and the New Security Perimeter | A Brand Highlight Conversation with Thyaga Vasudevan, EVP, Product of Skyhigh Security. Machine-transcribed; use the interactive transcript above to jump the player to any line.
It was a good week, I wish you were still that week, now let's produce some hot stuff. So I had to ride that week, like sky high perhaps even, that's right, that was a really good conversation. And I remember clearly all the going back to the hybrid and the sovereignty and a bunch of other good stuff that we discussed and so it's stick with me, I may use it in my article actually. I know, I'm a nerd, I like data sovereignty, that's just me, I think it's you and Tiaga as well. I like that stuff too, right Tiaga? It is good to have that, I love that, but maybe I should have you guys, you two talk to each other. No, good to see you again as well, but yeah, this is kind of a catch up after the show
and to hear how things went and there's anything you want to share with folks that caught your attention or conversation you had that stuck out here. But before we get to all that stuff, Tiaga, maybe a few words about your role at sky high and I'll say the elevator pitch for sky, so folks have that in their mind as well. Yeah, absolutely. Great to be talking to both you and Marco again and I'm Tiaga Vasudevan, I'm the EVP of product at sky high and sky high security is a leader in the SSE space and we are our vision and mission is all about ensuring that customers can adopt cloud applications and with a very, and protecting their access as part of these, for these cloud applications
and beyond access also protecting the data as they access these applications and really providing a pure comprehensive zero trust protection for both access and data security. And so now that we're back, you're back in your office, we're back in our office, how was RSA conference? Was it good for you guys, was it good for you, good network in here, good stories over there? I think I must say that this year's RSA conference was something like that I've never experienced before and I say this primarily because there were so many unique things that I heard about from an innovation standpoint, but all of them had one key theme which was front
and center. It was all about a genetic security and organizations, small, big, medium size, customers of ours, partners, analysts that we spoke to media, that we spoke to, you know, we was all very clear that November of 2022 was a generational shift moment for all of us because of chat GPT introduction and since then we've been focused on protecting data going in and coming out, great, awesome, we got that covered now, but guess what, now the puck has moved towards agent security, that's the new control blame, identity and data with agents. So really everything collapses into three questions if you may, who's acting, who the identities of the agent, if it's a shadow agent, identify them, if it's an agent that has been created
by sanctioned tools, identify them, what are the accessing, what's the data that has been exchanged, are they going directly through API or through MCP service, what are they trying to do, so understand the action, understand the permissions of these agents. So I think the focus is now about controlling the action apart from controlling the data, so I think that has that new dimension of controlling the actions is very, very interesting and so that is one and the reason I say, like never before, is typically the customers curve of adopting this new security technologies, there is a gap, they say, oh yeah, that's nice, new shiny ball will get there, but let's first talk about reality. This year, that reality for the customer and the innovation was converging at a ferocious
space, so most of these customers were already adopting agentic applications or building agents, and they wanted us to know, tell them how we can protect them, so that's why it felt the pace at which this innovation is being adopted is just phenomenal. Now apart from that, we heard a lot of other things as well, we heard about sovereignty, obviously there's a lot of focus now on that, given all the geopolitical environment that we're all living in, that is data regulations in every region, so you know, a lot of discussion around DSPM, by the way, the sovereignty brings itself, the discussions are about hybrid, like the way we were talking about, and then everybody acknowledged that the browser has quietly become a very critical point, an end point to protect, so browser security again
was front and center, so these were probably most of the themes that we encountered at RSA, but a very, very interesting RSA. Yeah, did you find, because clearly, data sovereignty has, as you pointed out, the geopolitical driver behind it, which then leads to organizations in one or more places, right, geographies, so did you find there was a lot of international representation and kind of what levels of the organization did you have, CSOs from different countries or practitioners, what did that look like? Yes, and the answer is 100%, and so these were CSOs from large global organizations in financial services, healthcare, some public sector, some not for profit organizations as well, and they're all thinking about data sovereignty in their own unique
ways, some where they're talking about data or traffic processing and data storage within their own data centers, some thinking about storing it on sovereign clouds to have a hybrid structure in place, but they're global companies, they're also thinking about if you are in a region where it's okay to adopt cloud fully, they're okay to place it on completely on cloud as well, so there is a whole gamut of customers with their own use cases that we talked to. And I guess you go there with some objective as a company, you go at the booth, you know, this is what we're going to push, did you learn anything that if you were going to go back to RSA tomorrow, would you change your strategy in the interaction with the client something unexpected that come on the floor? Yeah, that's a very good point. I think this time we went very well prepared on a few things,
like the positioning that we are going to be having about our products and the messaging that we wanted to push. I think what we felt in some of the discussions where some of the customers were still unsure about some of our recent product releases and offerings and these are our existing customers. And so one of the learnings that we had was before we went and met up with some customers that we know we are going to be meeting. Send a pre-read to these customers in advance that hey, these are the product releases, this is what is coming down the pipe and this is what we're going to be talking about. So that the discussion more is about how do we leverage that new technology for their purpose as opposed to tell me more about the technology, right? So I think we can,
yeah, so we can do that going forward. But again, there's always learnings. Of course. But some of the customers who were obviously very much engaged with us prior to RSA, they knew. And so it was a little bit more around operationalization of the newer innovation that we had recently announced. So those were very productive conversations. Very good. Where we are looking forward to maybe have more conversations with you as some other events. If you know where you're going to be next, this is a good opportunity to say goodbye to everybody and meet you wherever else you're going to be and that's what we're going to do as well. Yeah, immediately we are going to be participating in the Gartner conferences that's coming up. There's one coming up in June, the Gartner SRM conference. I believe it's in Maryland, National Hava in Maryland. And then another one in Sao Paulo, Brazil,
that's potentially we might be going there. How come with you? How about that? Can I come? That's right. We also got a Sao Paulo. And then we also have virtual events. So we have a we have our sky high virtual event that is scheduled for the end of April where we're inviting all of our customers and partners to be part of it so that they can hear from management about a company where we are a financial you know update and where we're going from a company standpoint. And of course product strategy, roadmap demos and all that good stuff. Perfect. All right, we're going to wrap these say and by bye to everybody to the nice opportunity to listen to our coverage is of course meet with you on the booth or whatever other events are going to be and Sean. There's only one RSA conference every year so you know you're just going to have to wait. It's only one only one Tiaga at sky high security as well and
we're grateful we had the time to spend with them once and great to have you on for this recap too. Yeah, keep keep all my friends. No, absolutely. Thank you and I was great talking to both you Sean and Marco. Thank you. Bye bye. See you everybody soon.
More episodes
More from The ITSPmagazine Podcast

Marketing Volume Held Steady. Scrutiny Went Up. | Lens Four by Sean Martin | Rea...
The ITSPmagazine Podcast

Executives Can Now Invite Their Lawyer, Banker, and Dog Walker Into a Verified C...
The ITSPmagazine Podcast

Executives Can Check a Country's Risk and a Caller's Identity From the Same Blac...
The ITSPmagazine Podcast

A Secure and Compliant Business Is the Destination. Steel Patriot Partners Maps...
The ITSPmagazine Podcast