What's Your Why?
Hugh Thompson (Executive Chairman · RSAC), Jen Easterly (CEO · RSAC)
RSAC 2026 Conference · Main Stage Keynote
Overview
This talk, delivered by Hugh Thompson, Executive Chairman of RSAC, and Jen Easterly, CEO of RSAC, served as the opening keynote for the RSA Conference 2026, marking its 35th anniversary. Titled "What's Your Why?", the address transcended traditional technical presentations, instead focusing on the profound personal motivations that drive cybersecurity professionals. It explored the deep-seated human need to protect, connecting individual purpose to the collective strength of the cybersecurity community, particularly in an era profoundly shaped by artificial intelligence.
Key moments
- 0:00 Welcome to RSAC 2026: 35th Anniversary highlights
- 2:05 AI's transformative impact on cybersecurity and defense
- 4:10 The core 'why': a deep need to protect others
- 5:15 Hugh's personal story: protecting family from harm
- 8:08 The central question: 'What's your why?'
- 10:05 Audience shares 'whys,' fostering community connection
What's Your Why?
Speakers: Hugh Thompson, Executive Chairman RSAC; Jen Easterly, CEO RSAC
Conference: RSA Conference
YouTube: https://www.youtube.com/watch?v=39iRUMJONdU
Overview
This talk, delivered by Hugh Thompson, Executive Chairman of RSAC, and Jen Easterly, CEO of RSAC, served as the opening keynote for the RSA Conference 2026, marking its 35th anniversary. Titled "What's Your Why?", the address transcended traditional technical presentations, instead focusing on the profound personal motivations that drive cybersecurity professionals. It explored the deep-seated human need to protect, connecting individual purpose to the collective strength of the cybersecurity community, particularly in an era profoundly shaped by artificial intelligence.
The speakers underscored the critical role of human connection and purpose in navigating the rapidly evolving threat landscape, where AI is both a powerful tool for adversaries and an indispensable asset for defenders. Thompson and Easterly argued that understanding one's "why"—the core reason for engaging in cybersecurity work—is essential for resilience against burnout and for fostering the collaborative spirit necessary to secure a complex digital world. The talk was a powerful call to introspection and community building, setting a foundational tone for a conference dedicated to advancing security knowledge and practice.
The significance of this keynote lies in its emphasis on the human element amidst a technology-driven field. By highlighting the personal sacrifices and the profound sense of mission that characterize cybersecurity professionals, the speakers aimed to fortify the community's resolve and encourage deeper connections. In a domain often characterized by technical complexity and relentless challenges, "What's Your Why?" served as a poignant reminder of the shared purpose that binds defenders, empowering them to confront future threats with renewed vigor and collective strength.
Background
▶ Watch: Welcome to RSAC 2026: 35th Anniversary highlights (0:00)
The cybersecurity industry operates under immense pressure, characterized by an ever-escalating arms race between sophisticated attackers and dedicated defenders. Professionals in this field frequently grapple with high-stakes scenarios, from nation-state intrusions and devastating data breaches to the relentless demands of ransomware attacks. As Hugh Thompson articulated, this environment often leads to "extreme stress and intensity," where seeing one's company in headlines after a breach or experiencing the helplessness of a system shutdown due to a ransom demand are not uncommon occurrences. This backdrop of persistent threat and pressure necessitates a strong internal drive, often beyond mere professional obligation, to sustain individuals in their roles.
Historically, the appeal of cybersecurity has often stemmed from a deep-seated desire to protect. Thompson eloquently described this as "a deep and abiding need to protect others," a "calling" that transcends a mere job description. This intrinsic motivation is crucial, as the work is largely unseen by the public, involving "long hours" and "tradeoffs" away from loved ones, as Jen Easterly highlighted. The challenge, then, is not just technical, but existential: how do professionals maintain this protective drive, combat burnout, and find sustained meaning in a field where success often means the absence of incident, and failure can have catastrophic consequences?
Compounding this inherent challenge is the rapid emergence and integration of Artificial Intelligence (AI). As Thompson emphasized, AI is "rapidly changing everything around us," forcing a fundamental "rethink how we defend" and "reimagine how our adversaries are going to attack." This technological paradigm shift introduces unprecedented complexity, as both defenders and attackers now have access to increasingly powerful AI capabilities. The problem, therefore, is not just about adapting to new tools, but about understanding the profound strategic implications of AI and ensuring that cybersecurity professionals are not "passive observers" but active architects of its secure deployment. The RSA Conference, in its 35th year, recognized this dual challenge—the human need for purpose and community, intertwined with the imperative to master AI—as central to its mission for 2026.
Key Findings
▶ Watch: The core 'why': a deep need to protect others (4:10)
While "What's Your Why?" was not a research presentation yielding traditional "findings," it delivered several profound insights and core tenets designed to resonate deeply with the cybersecurity community. These insights serve as a framework for understanding the human and strategic dimensions of the field:
- The Indispensable Power of Personal Purpose ("The Why"): The central insight is that a deep, personal motivation – "the why" – is the ultimate fuel for resilience and dedication in cybersecurity. This "calling" to protect others, whether family, community, or society at large, is what sustains professionals through intense stress and challenges. Hugh Thompson's personal anecdote of stepping on glass to protect his daughter vividly illustrated this protective instinct, crystallizing the idea that one would rather endure harm than see a loved one suffer. This intrinsic drive is portrayed as essential for combating burnout and maintaining engagement in a demanding field.
- Community as a Force Multiplier for Defense: The talk strongly emphasized that cybersecurity professionals are "stronger when we are bonded" and that the community provides "the power of connection." In a field that can feel "so lonely at times," collaboration, shared insights, and mutual support are not just beneficial but critical for collective strength against evolving threats. Jen Easterly expanded on this, noting that while personal "why" often begins with an "inner circle" of loved ones, the cybersecurity community expands that circle to encompass "a child in a hospital, a town relying on clean water, a small business trying to keep the doors open." This communal "why" elevates individual effort to a shared mission of broader societal protection.
- AI's Transformative, Intertwined Role in Cybersecurity: The speakers unequivocally positioned Artificial Intelligence (AI) as the most consequential technology of our lifetime, fundamentally altering the cybersecurity landscape. They highlighted that AI is not an optional consideration but an integral force, "rapidly changing everything around us." Critically, AI is framed as a double-edged sword: it forces defenders to "rethink how we defend" and "reimagine how our adversaries are going to attack," as both sides will leverage its capabilities. The core message here is that AI and cybersecurity are "so deeply intertwined" that AI "cannot operate sustainably anywhere... without cybersecurity." This underscores that AI has "made our jobs way bigger" and demands active, responsible engagement from the security community.
- The Expanded Scope of Protection: The talk articulated a progression of the "why," moving from personal protection to a broader, societal responsibility. While individual motivations often start with loved ones, the cybersecurity profession inherently extends this protective impulse to a global scale. This includes safeguarding critical infrastructure, public services, and the digital trust necessary for modern society to function. This expansion of purpose, from the individual to the collective, is presented as a unifying force that gives the community a shared, elevated mission: "building a safer, more secure digital world."
Technical Deep Dive
▶ Watch: Hugh's personal story: protecting family from harm (5:15)
This keynote address, "What's Your Why?", was primarily motivational and strategic in nature, focusing on the human element and community building rather than presenting specific technical research, vulnerabilities, or tools. Therefore, a traditional "Technical Deep Dive" into protocols, code, or architectures is not applicable to the content of this particular talk.
However, the speakers did provide significant strategic insights into the overarching technical landscape, particularly concerning the profound impact of Artificial Intelligence (AI) on cybersecurity. These insights, while not delving into the mechanics of AI, illuminate the critical technical challenges and opportunities that the cybersecurity community must address:
- AI as a Dual-Use Technology: Hugh Thompson explicitly stated that AI is forcing the industry to "rethink how we defend" and "reimagine how our adversaries are going to attack." This highlights AI's role as a dual-use technology, equally accessible and potent for both offensive and defensive operations. Defenders must therefore not only understand how to integrate AI into their own security stacks but also anticipate and counter AI-powered adversarial tactics, such as advanced phishing, automated exploit generation, or sophisticated malware development. The implication is a need for continuous adaptation and innovation in AI-driven threat intelligence and response.
- The Interdependence of AI and Cybersecurity: A core tenet articulated by Thompson was that "AI cannot operate sustainably anywhere in businesses, in governments, or in homes without cybersecurity." This establishes a fundamental interdependence: the widespread adoption and societal benefit of AI are contingent upon robust security foundations. This isn't merely about securing AI systems from attack, but about embedding security principles into the very design, deployment, and operation of AI. This includes considerations for AI trustworthiness, data privacy in AI models, bias detection, and robustness against adversarial attacks on AI algorithms themselves (e.g., data poisoning, model evasion). The talk implies that cybersecurity professionals are now directly responsible for the secure future of AI.
- Expanded Scope and Complexity of the Cybersecurity Role: Thompson noted that AI "just made our jobs way bigger in cybersecurity." This isn't just about more work, but about an expanded scope of technical expertise and strategic thinking required. Professionals must now understand not only traditional network, application, and data security, but also the intricacies of machine learning models, neural networks, data pipelines, and the ethical implications of AI. This demands a continuous learning imperative and a capacity to integrate AI into existing security frameworks while simultaneously building new ones tailored to AI-specific risks. The "single individual cannot keep up with the changes," as Thompson remarked, reinforcing the need for community and specialized expertise to tackle this expanded technical domain.
- Proactive Engagement with AI: The speakers urged the audience not to "be passive observers on this AI journey" but rather to embrace the responsibility "to make AI work for us." This is a call for active technical leadership. It means developing and deploying AI-powered security solutions (e.g., AI-driven threat detection, automated incident response, vulnerability analysis), shaping AI policy, and educating organizations on secure AI practices. It also means critically evaluating AI tools for their own security vulnerabilities and ensuring their ethical deployment.
In essence, while the talk did not present new technical findings, it provided a high-level strategic roadmap for how the cybersecurity community must technically engage with AI: as an inevitable, transformative force that demands proactive, collaborative, and deeply ethical consideration for the future of digital security.
Demo / Proof of Concept
▶ Watch: The central question: 'What's your why?' (8:08)
This keynote address did not feature a traditional technical demonstration or a proof of concept related to cybersecurity vulnerabilities, tools, or research. Instead, the "demo" component of the talk was an interactive, audience-participation exercise designed to reinforce the central theme of personal purpose and community connection.
Hugh Thompson engaged the entire audience in a live, introspective activity. Attendees were asked to find a blank card and a pen under their seats. Thompson then prompted them to "quickly write down the first thing that comes to your mind when you hear the question, what's your why for you?" He encouraged participants to be honest and uninhibited, suggesting diverse examples like "your pets," "your family," "Pokémon Go," or "live action Star Wars reenactments." After a brief moment of reflection and writing, he invited everyone to hold up their cards, allowing them to look around and "soak that in," observing the myriad "whys" of their fellow attendees.
This interactive segment served as a powerful, non-technical "proof of concept" for the talk's core message: that shared purpose fosters connection and strengthens community. The visible display of diverse yet deeply personal motivations created a tangible sense of unity and empathy among the thousands of conference attendees, demonstrating in real-time the shared human element that underpins the technical world of cybersecurity. It was a demonstration of the power of connection and shared purpose, rather than a technical exploit or solution.
Defensive Implications
▶ Watch: Audience shares 'whys,' fostering community connection (10:05)
The "What's Your Why?" keynote, despite its non-technical nature, carries profound defensive implications for cybersecurity professionals and organizations. By focusing on motivation, community, and the strategic impact of AI, the speakers outlined a critical framework for building resilient, effective defense strategies in the modern threat landscape.
- Cultivate and Leverage Personal Purpose for Resilience: Defenders must actively identify and lean into their personal "why." Understanding the intrinsic motivation—be it protecting family, community, or a broader sense of digital trust—serves as a powerful antidote to burnout, a pervasive issue in cybersecurity. Organizations should foster environments where employees can connect their daily tasks to this larger purpose, recognizing that a deeply motivated workforce is more resilient, innovative, and committed to long-term defense. This can involve leadership emphasizing the societal impact of their work and creating opportunities for professionals to share their personal stories and motivations.
- Prioritize Community Building and Collaboration: The talk strongly advocated for the power of community as a critical defensive asset. In an environment where no single individual can keep up with the pace of change, collaboration across organizations, sharing threat intelligence, best practices, and lessons learned becomes paramount. Defenders should actively participate in industry forums, conferences (like RSAC), and peer networks to build connections and allies. This collective intelligence and support system enhances defensive capabilities, allowing for faster response to emerging threats and a more robust overall security posture than isolated efforts could achieve.
- Proactively Embrace and Secure AI: The strategic imperative regarding AI is clear: defenders cannot be passive. They must actively engage with AI as both a defensive tool and a potential attack vector. This means investing in AI-powered security solutions (e.g., advanced threat detection, anomaly analysis, automated incident response) while simultaneously developing expertise in securing AI systems themselves. Organizations must establish frameworks for AI security, ensuring data privacy, model integrity, and resilience against adversarial AI attacks. This also includes training security teams to understand AI's capabilities and limitations, preparing them to defend against AI-enhanced attacks and to responsibly deploy AI in their own operations.
- Recognize the Expanded Scope of Protection: The "why" for defenders extends beyond organizational boundaries to critical infrastructure, public services, and societal trust. This expanded scope demands a holistic approach to security, recognizing interdependencies and the cascading effects of breaches. Defenders should advocate for and participate in initiatives that strengthen national and international cybersecurity, understanding that their individual and organizational efforts contribute to a much larger collective defense. This perspective fosters a sense of shared responsibility and motivates collaboration across sectors.
- Foster Continuous Learning and Adaptability: While not explicitly stated as a defensive implication, the rapid pace of change, particularly driven by AI, implicitly demands continuous learning. Defenders must commit to ongoing education, staying abreast of new technologies, threat intelligence, and defensive strategies. This adaptability, fueled by a strong "why" and supported by a robust community, ensures that defensive capabilities evolve at a pace commensurate with the threat landscape.
In summary, the defensive implications of "What's Your Why?" are about building a human-centric, community-driven, and AI-aware defense. It's about empowering individuals through purpose, strengthening collective capabilities through connection, and strategically leveraging technology to protect an increasingly complex digital world.
Key Takeaways
- Personal Purpose is Foundational: Understanding one's "why"—the deep, intrinsic motivation to protect others—is crucial for resilience, combating burnout, and sustaining long-term commitment in the demanding field of cybersecurity.
- Community is a Defensive Superpower: Connectivity and collaboration within the cybersecurity community are vital for shared strength, knowledge exchange, and collective defense against evolving threats, making the whole greater than the sum of its parts.
- AI Transforms Everything: Artificial Intelligence is the most consequential technology impacting cybersecurity, demanding that professionals actively engage with it, both as a tool for defense and a vector for attack, rather than remaining passive observers.
- Cybersecurity is Indispensable for AI: The sustainable operation and societal benefit of AI across all sectors are fundamentally contingent upon robust cybersecurity, making the security community central to the future of AI.
- The Scope of Protection is Expanding: The "why" of cybersecurity professionals extends beyond individual or organizational protection to safeguarding critical infrastructure, public services, and the digital trust of society at large.
- Active Engagement and Connection are Key: To navigate the rapidly changing landscape, cybersecurity professionals must proactively embrace new technologies like AI, continuously learn, and consciously build connections within their community to foster allies and share insights.
About the Speaker(s)
Hugh Thompson serves as the Executive Chairman of the RSA Conference. With an extensive background in the cybersecurity industry, he has been a prominent figure at RSAC for many years, notably serving as the program committee chair for 18 years. Thompson is known for his ability to connect with the audience on a deeply personal level, often sharing anecdotes that highlight the human element of cybersecurity. His core message often revolves around the importance of community, personal purpose ("the why"), and the critical role these play in sustaining professionals through the inherent stresses of the field. His leadership at RSAC emphasizes fostering connections and shared understanding among security practitioners.
Jen Easterly is the CEO of the RSA Conference, bringing her leadership to one of the industry's most significant events. Her contributions to the keynote echoed and expanded upon Hugh Thompson's themes, particularly reinforcing the power of community and the expansive nature of the "why." Easterly emphasized how the cybersecurity community extends the protective instinct from an "inner circle" of loved ones to a broader societal mission, safeguarding critical services and ensuring digital trust for everyone. Her involvement underscores the strategic importance of human connection and collective purpose in building a safer, more secure digital world, especially in an era of rapid technological advancement like AI.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
A motivational keynote from RSAC leadership that belongs at a corporate retreat, not a security conference. 'What's Your Why?' is feel-good community theater dressed up with AI buzzwords and a card-writing exercise. There is zero technical content, zero research, zero original contribution to the field. This is conference marketing masquerading as a talk, delivered by the people who run the conference, about why you should care about the conference. The fact that this was submitted for review as if it contains technical merit is itself a red flag.
Heather Calloway (CISO) — WEAK
A well-intentioned opening keynote that prioritizes emotional resonance over operational clarity. Thompson and Easterly are credible voices, and the instinct to anchor a technical community in human purpose is not wrong — but 'What's Your Why?' delivers inspiration where the moment called for judgment. At RSA 2026, with AI reshaping both the threat landscape and the defender's toolkit, the audience deserved more than affirmation. What they got was a motivational framework dressed in strategic language, with no governance accountability, no usable decision path, and no honest reckoning with what AI actually means for how security programs should be structured, resourced, or led.