Actionability: The Next Frontier Rooted in Fundamentals
Dean Sysman (Executive Chairman and Co-Founder · Axonius)
RSAC 2026 Conference · Main Stage Keynote
Overview
In his RSA Conference talk, "Actionability: The Next Frontier Rooted in Fundamentals," Dean Sysman, Executive Chairman and Co-Founder of Axonius, delved into the critical yet often elusive concept of actionability in cybersecurity. Sysman articulated a vision of a "perfect cybersecurity world" characterized by self-healing environments, where security policies are not just declared but are continuously monitored, deviations detected, decisions made, and corrective actions automatically or semi-automatically executed and validated. The core thesis of the presentation centered on the idea that achieving this state of pervasive actionability is not a futuristic dream but an attainable reality, provided organizations return to fundamental principles of understanding their environments.
Key moments
- 0:00 Introduction to actionability and the self-healing security dream.
- 1:06 Four stages of achieving a self-healing security environment.
- 3:00 The challenge of validating declared security policies.
- 4:18 Real-world data on missing critical security agents.
- 6:17 AI's dual nature: deterministic systems, probabilistic behavior.
- 7:50 The journey from security visibility to true actionability.
- 8:50 Fragmentation: the biggest barrier to security actionability.
Actionability: The Next Frontier Rooted in Fundamentals
Speakers: Dean Sysman, Executive Chairman and Co-Founder, Axonius
Conference: RSA Conference
YouTube: https://www.youtube.com/watch?v=Rz_lvK0hRxg
Overview
In his RSA Conference talk, "Actionability: The Next Frontier Rooted in Fundamentals," Dean Sysman, Executive Chairman and Co-Founder of Axonius, delved into the critical yet often elusive concept of actionability in cybersecurity. Sysman articulated a vision of a "perfect cybersecurity world" characterized by self-healing environments, where security policies are not just declared but are continuously monitored, deviations detected, decisions made, and corrective actions automatically or semi-automatically executed and validated. The core thesis of the presentation centered on the idea that achieving this state of pervasive actionability is not a futuristic dream but an attainable reality, provided organizations return to fundamental principles of understanding their environments.
Sysman argued that despite significant advancements in security technology, the industry struggles with a foundational challenge: transforming raw data and insights into meaningful, timely, and effective actions. This struggle is exacerbated by the increasing complexity of modern IT landscapes, the proliferation of security tools, and the transformative, often unpredictable, impact of artificial intelligence (AI). The talk highlighted that while the industry is often preoccupied with the 'action' phase, the true pathway to self-healing environments lies in the preceding stages of comprehensive visibility, contextual understanding, and informed decision-making.
The presentation underscored why actionability matters: it empowers security practitioners and leaders to move beyond reactive firefighting to proactive, policy-driven security management. By dissecting the journey from policy declaration to validated action, Sysman illuminated the pervasive challenges of data fragmentation, inconsistent visibility, and ambiguous ownership that prevent organizations from achieving true cyber resilience. The insights shared are crucial for any organization grappling with the scale and velocity of modern cyber threats, offering a roadmap to operationalize security policies and reduce risk effectively.
Background
▶ Watch: Introduction to actionability and the self-healing security dream. (0:00)
The aspiration for a self-healing cybersecurity environment forms the conceptual bedrock of Sysman's talk. This ideal state envisions systems that inherently understand their desired security posture, automatically detect deviations, determine appropriate corrective measures, and execute them without human intervention. This vision is not merely theoretical; it represents the ultimate evolution of cybersecurity operations, moving from manual, reactive processes to intelligent, proactive defense.
Achieving this self-healing capability requires a structured, iterative process:
- Declare: Explicitly define the desired security policy and posture for all assets and environments. This involves granular specifications, such as "every Windows endpoint must have an EDR agent."
- Detect: Continuously monitor the environment to identify any drift or deviation from the declared policy. This involves gathering data from diverse sources to ascertain the current state of every asset.
- Decide: Analyze detected drifts, understand their implications, prioritize them based on risk and business context, and determine the most appropriate corrective action. This stage often involves identifying the responsible owner.
- Act: Execute the chosen remediation or enforcement action, which could range from deploying an agent to reconfiguring a system.
- Validate: Verify that the action taken successfully resolved the drift and that the asset now conforms to the declared policy, closing the loop.
Sysman emphasized that while the "Act" phase often receives the most attention, the preceding steps – particularly comprehensive detection and informed decision-making based on robust context – are paramount. The challenge lies in the sheer complexity of modern IT environments. Policies, though seemingly simple to declare (e.g., "every Windows endpoint should have our EDR Agent on it"), are incredibly difficult to prove and enforce. This difficulty stems from the need to understand every single Windows device, verify agent installation, confirm its updated status, and ensure correct configuration – information often scattered across numerous, disparate systems.
Further compounding these challenges is the accelerating pace of technological change and the pervasive adoption of AI. The velocity of changes has drastically increased; vulnerabilities once exploited in weeks are now leveraged within minutes of public disclosure. Asset types have multiplied to include a vast array of identities, devices, applications, and data, all requiring clear ownership. Traditionally, cybersecurity has viewed systems as deterministic (predictable compute, storage, memory) and people as probabilistic (unpredictable behavior). AI, however, blurs this distinction, presenting both deterministic security challenges in its underlying infrastructure and probabilistic behavioral risks akin to human users. This dual nature of AI necessitates a more sophisticated approach to security, where understanding and actionability become even more critical to mitigate exponentially higher risks associated with incorrect actions.
The fundamental impediment to achieving actionability, Sysman highlighted, is fragmentation. No single technological environment relies on a sole vendor or tool. Organizations typically employ dozens, if not hundreds, of different security and IT tools, each providing a partial and often inconsistent view of the environment. These fragmented perspectives—covering identity, cloud, endpoint, network, and more—create a cacophony of data that obstructs a unified understanding of assets and their security posture. This lack of a consolidated, accurate picture makes it exceedingly difficult to detect drift, assign ownership, prioritize risks, or take decisive, validated actions.
Key Findings
▶ Watch: The challenge of validating declared security policies. (3:00)
Dean Sysman's talk presented compelling data points, derived from Axonius's observations across billions of assets, millions of networks, and thousands of organizations, illustrating the widespread challenges in achieving cyber actionability:
- Pervasive Missing Agents: A median organization manages nearly 300,000 different devices. Despite the fundamental importance of security controls, an alarming 13 percent of devices on average are missing critical agents. This includes essential security, IT, and networking technologies, highlighting a significant gap in basic security hygiene for even the most common and critical systems.
- Lack of Unified Asset Visibility: The majority of organizations (specific percentage not given but implied as high) do not possess a unified view of their environment. They attempt to piece together their asset inventory by examining individual data sources, akin to solving a puzzle one piece at a time without seeing the whole picture.
- Reliance on Outdated Manual Processes: Among organizations that do attempt to achieve a unified environment, the majority still rely on spreadsheets for consolidation. This manual "stare and compare" approach is inherently inefficient and quickly becomes irrelevant due to the rapid pace of change in IT environments.
- Infrequent Data Updates: Due to manual processes and fragmented data, almost none of the surveyed organizations update their asset inventory daily. The most up-to-date versions of their environment are typically at least a few days old, rendering them inadequate for real-time risk assessment and response.
- Fragmentation of Risk Data: Organizations face not only fragmented visibility but also fragmentation of risk data. The average organization uses more than five different sources of exposure data, encompassing vulnerabilities, misconfigurations, improper access, and internet exposure. Reconciling these disparate risk perspectives from various tools (e.g., vulnerability scanners, cloud security posture management, identity providers) is a major hurdle to effective prioritization.
- Top Challenges in Exposure Remediation: When asked about their biggest challenges in remediating exposures, organizations cited three primary issues:
- 26 percent reported inability to prioritize exposures effectively.
- 25 percent struggled with identifying the owner responsible for fixing the issue.
- 21 percent pointed to inconsistent data across their various security tools as a major blocker.
- Accelerated Threat Landscape: The advent of AI and increasing technological adoption has drastically accelerated the velocity of changes and threats. While vulnerabilities once took weeks to exploit, they are now being exploited within minutes of being reported and publicized. This rapid pace demands equally rapid detection and action.
- AI's Dual Nature: AI introduces unique security challenges by acting as both a deterministic system (in terms of its underlying compute, access, and networking infrastructure) and a probabilistic entity (in its unpredictable behavioral aspects, similar to human users). This dual nature complicates risk assessment and control strategies.
These findings collectively paint a picture of an industry grappling with fundamental data management and operational challenges, severely hindering its ability to achieve proactive, actionable security.
Technical Deep Dive
▶ Watch: Real-world data on missing critical security agents. (4:18)
The core technical challenge illuminated by Sysman is the pervasive fragmentation of data across modern enterprise environments. Organizations deploy a multitude of security and IT tools, each designed for a specific domain – Identity (e.g., Okta, Active Directory), Cloud (e.g., AWS Security Hub, Azure Security Center), Endpoint (e.g., CrowdStrike, SentinelOne), and Network (e.g., firewalls, network access control solutions). Each of these tools provides a distinct "view" of the environment, often with its own data schema, reporting mechanisms, and asset identification methods. This leads to conflicting or incomplete information, making it impossible to establish a single, authoritative understanding of an asset's true state.
Sysman emphasized the need for reconciliation of this fragmented data to achieve durable context. Just as a crime scene investigator collects evidence from multiple witnesses and sources to reconstruct the truth, security teams must correlate data from all available tools to form a comprehensive and accurate picture of their assets. This process involves:
- Data Ingestion: Collecting raw data from every deployed security and IT tool. This includes asset attributes (IP addresses, hostnames, installed software, user accounts), security posture data (vulnerabilities, misconfigurations, compliance status), and operational context (owner, business criticality, location).
- Normalization and Correlation: Transforming disparate data into a common format and linking related records across different sources. For instance, an endpoint identified by an IP address in a network scan might be linked to a hostname in an EDR report and a user account in an identity management system. This requires sophisticated matching algorithms that can handle inconsistencies and partial information.
- Contextual Enrichment: Augmenting the technical data with business context. This is crucial for prioritization and decision-making. Knowing that a server has a vulnerability is one thing; knowing that it hosts a critical production database for a revenue-generating application, is internet-facing, and owned by the finance department adds the necessary context to determine its true risk and the urgency of remediation.
- Policy Definition and Mapping: Translating high-level, natural-language security policies (e.g., "all critical applications must be behind Single Sign-On") into machine-readable, verifiable rules. This involves mapping policy requirements to specific attributes and states that can be derived from the reconciled data. For example, "every endpoint to have the EDR Agent on it" requires checking the agent's presence, version, and operational status across endpoint, network, and potentially cloud dimensions. Similarly, "every app to be behind Single Sign-On" necessitates verifying authentication mechanisms through identity and application security tools.
The concept of "should" versus "is" is central to detecting drift. The "should" represents the declared policy and desired state, while the "is" represents the current, observed state derived from the reconciled, contextualized data. The gap between "should" and "is" signifies a security drift that requires action. This durable context, combining security data, asset data, and business context, becomes even more critical in the AI era. AI agents, while powerful, lack inherent common sense or risk awareness. An AI instructed to reduce storage use might delete a critical database if it lacks the durable context to understand the implications of such an action. The risk of unintended or catastrophic consequences from automated actions becomes exponentially higher without this robust contextual understanding.
The technical framework for actionability, therefore, is a continuous loop:
- Declaration: Formalizing security policies.
- Visibility: Cutting through fragmentation to gain a unified understanding of the environment and identify gaps (drift). This requires merging data from all dimensions (network, cloud, endpoint, identity, applications, data).
- Context: Enriching this visibility with organizational context, including asset criticality and ownership, to facilitate informed decision-making. This is where the "who owns this?" question, which 25% of organizations struggle with, is answered.
- Decision: Selecting the appropriate remediation action based on prioritized risks and business impact.
- Action: Executing the chosen remediation through integrated tools and controls.
- Validation: Verifying that the action was successful and the environment is back in its declared secure state, and continuously reporting on compliance.
This holistic approach, moving beyond siloed tools to an integrated, contextualized data fabric, is the technical foundation for achieving true actionability and realizing the dream of self-healing security environments.
Demo / Proof of Concept
▶ Watch: The journey from security visibility to true actionability. (7:50)
The talk by Dean Sysman at RSA Conference primarily focused on conceptual frameworks, statistical findings from Axonius's market observations, and strategic insights into achieving cybersecurity actionability. While the presentation effectively used data visualizations to illustrate key challenges and proposed solutions, it did not include a live demonstration or a detailed proof of concept of any specific tool or technology in action. The emphasis was on the overarching principles and the critical need for unified data and context rather than a product-specific showcase.
Defensive Implications
▶ Watch: Fragmentation: the biggest barrier to security actionability. (8:50)
The insights shared by Dean Sysman carry profound implications for cybersecurity defenders seeking to enhance their operational effectiveness and move towards a more proactive security posture. Overcoming the challenges of fragmentation and achieving true actionability requires a strategic shift in how organizations manage their security programs:
- Prioritize Unified Asset Visibility: Defenders must recognize that a complete, accurate, and up-to-date inventory of all assets (devices, identities, applications, data) is the foundational requirement for any effective security program. This means moving beyond siloed tools and manual spreadsheets to implement solutions that can aggregate, normalize, and correlate data from every source across the IT environment. This unified view is essential for understanding the "is" state of the environment and detecting drift from declared policies.
- Automate Data Collection and Contextualization: Manual data reconciliation via spreadsheets is no longer sustainable given the velocity of change and the scale of modern environments. Defenders should invest in platforms and processes that automate the collection and contextualization of data from all security and IT tools. This includes enriching technical data (e.g., vulnerabilities) with critical business context, such as asset ownership, criticality, and associated business processes, to enable risk-based prioritization.
- Establish Clear Ownership and Accountability: The talk highlighted that 25% of organizations struggle with identifying who owns the remediation of exposures. Defenders need to establish clear lines of ownership and accountability for specific assets, security policies, and remediation tasks within their organizations. This involves cross-functional collaboration between security, IT operations, and business units to ensure that every identified gap has a responsible party assigned.
- Implement Continuous Policy Validation: Security policies should not be static documents. Defenders must implement mechanisms for continuous validation of these policies against the real-time state of the environment. This involves defining policies in a verifiable manner and using aggregated data to automatically detect deviations (drift) as soon as they occur, rather than relying on periodic audits.
- Focus on Prioritization Driven by Risk and Business Context: With fragmented risk data and numerous exposures, effective prioritization is paramount. Defenders must adopt methodologies that allow them to prioritize remediation efforts based on the true risk to the business, considering both technical severity (e.g., CVE score) and business impact (e.g., asset criticality, data sensitivity). This requires integrating threat intelligence with contextualized asset data.
- Bridge the Gap Between Detection and Action: The ultimate goal is to move from detection to decisive action. Defenders should seek to integrate their visibility and context platforms with their remediation tools. This could involve orchestrating automated actions for low-risk, high-confidence issues (e.g., deploying missing agents) or generating actionable tickets for human intervention with all necessary context pre-populated.
- Address AI-Specific Security Challenges: As AI becomes more integrated into operations, defenders must adapt their strategies. This includes securing the underlying deterministic infrastructure of AI systems (compute, network, storage) and establishing robust monitoring for the probabilistic behaviors of AI agents. Given AI's potential for rapid, unintended consequences, the need for durable context to inform AI actions and prevent dangerous outcomes is critical.
- Validate Remediation Effectiveness: The security loop isn't closed until an action is validated. Defenders must ensure that once a remediation action is taken, there are automated processes to verify its effectiveness and confirm that the asset now conforms to the declared policy. This continuous feedback loop ensures that security efforts are truly impactful.
By strategically addressing these defensive implications, organizations can move beyond the reactive cycle of fragmented data and manual interventions, building a foundation for truly actionable and resilient cybersecurity operations.
Key Takeaways
- Actionability is the ultimate goal for cybersecurity, enabling self-healing environments. It requires a continuous loop of declaring policies, detecting drift, making informed decisions, taking action, and validating the results.
- Fragmentation of data is the primary obstacle to achieving actionability. Organizations struggle with disparate security tools, inconsistent asset views, and multiple sources of risk data, leading to a lack of unified understanding.
- Basic security hygiene remains a significant challenge. On average, 13% of devices are missing critical security, IT, or networking agents, and most organizations lack a unified, up-to-date asset inventory, often relying on outdated manual processes.
- Effective prioritization and clear ownership are major blockers for remediation. Organizations frequently struggle to determine which exposures to fix first and who is accountable for taking action, hindering efficient risk reduction.
- AI significantly amplifies the need for durable context. The accelerated velocity of threats and the dual deterministic/probabilistic nature of AI systems demand real-time, comprehensive understanding to prevent exponentially higher risks from incorrect or unintended actions.
- Achieving actionability requires consolidating data into "durable context." This means reconciling fragmented security, asset, and critical business context to provide a single source of truth, enabling informed decision-making and efficient, validated remediation.
About the Speaker(s)
Dean Sysman is the Executive Chairman and Co-Founder of Axonius. In his role, he brings extensive experience in cybersecurity and a deep understanding of the challenges organizations face in managing their complex IT environments. His work at Axonius focuses on developing solutions that provide comprehensive asset visibility and security policy enforcement, directly addressing the fragmentation issues highlighted in his talk. Sysman is a recognized voice in the cybersecurity community, advocating for foundational approaches to security that empower practitioners and leaders to achieve greater actionability and resilience.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
Dean Sysman, co-founder of Axonius, delivers a polished but ultimately hollow talk that dresses vendor marketing in the language of original research. The core message — 'you can't secure what you can't see, and fragmented data is bad' — is a foundational security principle that has been repeated at every conference since at least 2010. The statistical observations cited come from Axonius's own customer base, the solutions proposed map suspiciously cleanly to Axonius's product capabilities, and there is zero original technical contribution. This is a keynote-style thought leadership talk masquerading as security research, and it would be more honestly placed in a vendor track or a CISO…
Heather Calloway (CISO) — WEAK
Sysman identifies a real and persistent problem — fragmented asset visibility prevents organizations from closing the loop between policy and action — and he has the data to back it up. But the talk never escapes its own gravity: it is a vendor framing asset management problems that Axonius happens to solve. The framework is clean, the statistics are credible, and the 'declare-detect-decide-act-validate' loop is useful shorthand. But the presentation stops exactly where a governance conversation should begin — at ownership, accountability, and the institutional conditions that keep these problems alive — and ends with a product category pitch dressed as strategic insight.