Cybersecurity Together: Unlocking the Power of Community
Hugh Thompson (Executive Chairman · RSAC)
RSA Conference 2025 · Day 2 · West Stage · Keynote
Overview
Hugh Thompson opened RSA Conference 2025 by making the case that community — not any single technology or vendor — is the security industry's deepest competitive advantage. Drawing on a statistician's framework for reasoning under uncertainty, he challenged the 44,000-person audience to approach the week with a Bayesian mindset: stay open to changing your priors, seek out unfamiliar perspectives, and treat every hallway conversation as a data point worth incorporating. The conference itself, he announced, is evolving into a year-round platform. ---

Key moments
- 0:00 RSA Conference 2025 hits record 44,000 attendees from 140+ countries
- 1:00 Record 2,800 speaker submissions signals unprecedented community depth
- 8:27 Bayesian vs. frequentist framework: update priors or fall behind adversaries
- 18:46 Cybersecurity Atlas maps how AI has diffused across every security domain
- 16:12 Agentic AI and AI-augmented SOC dominate 2025 practitioner priorities
- 17:41 RSAC launches year-round community platform, shifting from annual event
- 2:07 Innovation Sandbox sees 40% startup surge, measuring community momentum
Cybersecurity Together: Unlocking the Power of Community
Speaker: Hugh Thompson, Executive Chairman, RSAC
Event: RSA Conference 2025 — April 28–May 1, 2025, Moscone Center, San Francisco
Track: Keynote — West Stage
Watch: YouTube
Reading time: ~6 minutes
TL;DR
Hugh Thompson opened RSA Conference 2025 by making the case that community — not any single technology or vendor — is the security industry's deepest competitive advantage. Drawing on a statistician's framework for reasoning under uncertainty, he challenged the 44,000-person audience to approach the week with a Bayesian mindset: stay open to changing your priors, seek out unfamiliar perspectives, and treat every hallway conversation as a data point worth incorporating. The conference itself, he announced, is evolving into a year-round platform.
Introduction
The New York Stock Exchange does not often ring its opening bell from the West Coast, but on the morning of April 28, 2025, it did exactly that — transmitting the bell to Moscone Center in San Francisco, where RSA Conference 2025 had just opened its doors. For Hugh Thompson, the RSAC Executive Chairman who delivered the conference's first keynote address, that moment captured something he has spent years trying to articulate: the security industry has become genuinely central to how society functions, and the world is beginning to recognize it.
Thompson's address was not a threat briefing or a product announcement. It was, at its core, an argument for community as infrastructure — the connective tissue that makes everything else the industry does more durable. With 44,000 attendees from more than 140 countries and a record 2,800 speaker submissions, the numbers themselves made the point before he had to.
A Record-Breaking Gathering in a Time of Uncertainty
RSA Conference 2025 marked the event's thirty-fourth year and its largest attendance in history. Thompson noted that the conference draws practitioners from every sub-discipline and geography in cybersecurity — from application security engineers to national-level policymakers, from startup founders competing in Innovation Sandbox to veterans with fifteen or more consecutive RSA appearances. ▶ Watch: Conference scale and diversity (4:00)
The scale is not incidental to Thompson's argument — it is the argument. Forty percent more startups submitted to Innovation Sandbox this year than last. The program committee, drawn from the community itself, adjudicated 2,800 proposals to produce what Thompson called the strongest educational program in the conference's history. The community's willingness to contribute — to share knowledge, submit ideas, and volunteer judgment — is what makes the event function.
Thompson framed that openness against a backdrop of mounting uncertainty: AI adoption accelerating across every sector, threat actor behavior shifting rapidly, and regulatory environments in flux across the US, Europe, and Asia. "How do we operate with purpose in a time of great uncertainty?" he asked. "How do we defend in the very heart of change?" Those are not questions with clean technical answers. They are questions that require collective reasoning — which is why the conference exists.
The Bayesian Mindset: A Framework for the Week and the Field
The centerpiece of Thompson's keynote was an extended analogy drawn from his academic background as a statistician and former Columbia University professor. He contrasted two schools of statistical thinking — frequentist and Bayesian — as metaphors for how security practitioners should approach both the conference and their professional lives. ▶ Watch: Frequentist vs. Bayesian thinking (8:01)
Frequentists, Thompson explained, derive predictions from accumulated historical data. They are systematic, thorough, and comfortable counting the same minerals in Antarctic core samples thousands of times. They are optimized for stability. Bayesians take a different posture: they begin with a hypothesis, actively seek new information, and remain perpetually willing to revise their beliefs when the data warrants it. They are extroverts. They stay until last call. They get changed by the people they meet, and those people get changed too.
The parable may seem whimsical, but its application to security is precise. The field is one in which the adversary, the regulatory environment, and the underlying technology all change faster than any static model can track. Practitioners who update only from historical data — who assume the next attack will look like the last — are structurally disadvantaged against adversaries operating at the frontier. A Bayesian orientation — seeking input, updating priors, staying curious — is not just a conference networking tip. It is a professional survival strategy. ▶ Watch: Bayesian thinking applied to cybersecurity (12:00)
Thompson punctuated the analogy with an interactive demonstration: he invited first-time attendees to stand, then those who had attended five or more conferences, then those with fifteen or more. The visual contrast in the room — veteran practitioners surrounded by first-timers — illustrated his point more effectively than any slide. The room contained both the richest knowledge base available and the freshest perspectives. The value lies in their interaction.
Cybersecurity Atlas: Mapping What's on the Industry's Mind
Thompson introduced a data tool Cisco helped develop for the conference: Cybersecurity Atlas, a visualization of topics emerging from the record call-for-speakers submissions, analyzed by a team of data scientists RSAC hired to serve as both a mirror and a lens for the community. ▶ Watch: Cybersecurity Atlas introduction (18:00)
The Atlas maps cybersecurity sub-domains as circles, colored by area of focus, and displays their relative weight and interconnections as the corpus of submissions shifts over time. The contrast Thompson displayed between 2021 — pre-large language models, when AI in security was synonymous with machine learning — and 2025 was dramatic. AI has ceased to be a cluster in one corner of the map and has diffused throughout nearly every domain in the field.
Two themes dominated 2025 submissions above all others. The first was agentic AI — autonomous AI systems operating with minimal human supervision, with open questions around identity, governance, and traceability. The second was AI applied to the SOC, where practitioners are exploring whether AI can finally address the alert-fatigue and analyst-shortage dynamics that have plagued security operations for years. Both topics would recur throughout the conference week.
Thompson also revealed that RSAC's data scientists had used the historical submission corpus to test predictive validity — asking whether trends visible five or six years ago accurately foreshadowed what became dominant later. The implication was that Cybersecurity Atlas is not just a retrospective dashboard but a potential leading indicator of where the field is heading.
A Year-Round Community Platform
Perhaps the most consequential announcement in Thompson's keynote was not about content — it was about continuity. After eighteen months of conversations with hundreds of practitioners, RSAC has built an initial version of a community platform designed to sustain connection and learning throughout the year, not just during the annual conference week. ▶ Watch: Year-round community platform announcement (16:00)
The need, Thompson argued, has always been present. Security practitioners have the same questions, the same knowledge-sharing instincts, and the same calibration needs in February and September as they do during conference week. The infrastructure to support those needs year-round, however, has not existed inside RSAC's ecosystem — until now. Thompson positioned the platform as a first version, explicitly inviting the community to test it, critique it, and help shape its direction.
The announcement fits the broader argument of the keynote: that community is not a byproduct of the conference but its actual product, and that the conference itself is a delivery mechanism for something that should persist long after the Moscone Center empties.
Notable Quotes
"Community. It's what makes us strong in cybersecurity. It's community."
"There has never been a more important time for us to come together as a community. So much is changing."
"Bayesians are way more fun at parties. Let me just tell you, a hundred percent."
"Approach it as a Bayesian would. Look for every opportunity to interact with somebody else. There are so many people from so many sub-disciplines of cyber, from every vertical across the world."
"We convene because we need each other. We convene because we need to learn from each other. We convene because we need to calibrate with each other."
Key Takeaways
- Community is the field's structural advantage. No vendor, no government, and no individual practitioner can outpace a well-connected, knowledge-sharing community. Thompson's framing positions RSAC not as an annual event but as the organizing infrastructure for that community.
- Adopt a Bayesian professional posture. The security field changes too quickly for fixed mental models. Practitioners who actively seek new perspectives, update their assumptions, and treat uncertainty as an invitation rather than a threat are better positioned for long-term effectiveness.
- Agentic AI and AI-augmented SOCs are the defining topics of 2025. The Cybersecurity Atlas data reflects what practitioners are actually thinking about: autonomous AI systems raise unresolved identity and governance questions, while AI in security operations holds the promise of finally closing the analyst-capacity gap.
- The conference is going year-round. RSAC's new community platform signals that the organization views its value proposition as continuous rather than episodic — a meaningful structural shift for a field that needs sustained knowledge exchange.
- First-timers and veterans belong in the same room. The most productive conversations at RSA Conference 2025 are likely to happen between practitioners who have never met before. Structural openness to new connections is not just good networking — it is how the industry calibrates and updates itself.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Hugh Thompson opens RSA by celebrating the conference's own scale and encouraging people to network — with a Bayesian statistics metaphor stapled on for intellectual texture. The Cybersecurity Atlas is genuinely the most useful data point here, but it's buried under twenty minutes of motivational speaking. A conference chairman talking about why you should come to the conference is not a keynote.
Heather Calloway (CISO) — SOLID
Hugh Thompson's RSAC community keynote uses Bayesian versus frequentist reasoning as a framework for why security programs that update only from historical data will fail against novel threats. The Cybersecurity Atlas confirms agentic AI and AI-augmented SOC dominate 2025 planning discussions.