The RSA Conference (RSAC), the premier cybersecurity industry event, returns to San Francisco’s Moscone Center April 28-May 1, 2025, bringing together thousands of security professionals, vendors, and thought leaders from across the globe. This annual gathering serves as the definitive forum for the latest cybersecurity innovations, trends, and best practices, featuring hundreds of educational sessions, keynotes from industry luminaries, and an expansive expo floor showcasing cutting-edge security solutions. For organizations navigating today’s complex threat landscape, RSAC provides unparalleled networking opportunities, hands-on training, and essential insights to help bolster defense strategies against evolving cyber threats.
In this exclusive pre-RSA Conference 2025 interview, Chad Cragle, CISO at Deepwatch, shares insights on how the leading managed detection and response (MDR) provider is transforming security operations through intelligent automation and enhanced integration.
Following their recent acquisition of Dassana, Deepwatch is focused on helping security teams cut through the noise of overwhelming alerts and tool sprawl to enable faster, more decisive action against emerging threats.
While not maintaining a booth on the main expo floor this year, Deepwatch will host personalized suite meetings and showcase their new Cyber Risk and Exposure platform at Mel’s Drive-In, offering attendees a pressure-free environment to experience their detection and response workflows firsthand.
++
VMblog: Give VMblog readers a quick overview of your company and its core mission in the cybersecurity space.
Chad Cragle: Deepwatch is a top managed detection and response (MDR) provider that enables security teams to stay proactive against threats around the clock. We serve as an extension of our clients’ teams, providing comprehensive visibility, customized threat detection, and quick cyberattack responses. Our mission is clear: to enhance every security team’s effectiveness, confidence, and resilience. With our recent acquisition of Dassana, we are strengthening these results through more intelligent automation and improved integration throughout the SOC stack.
VMblog: Where can attendees find you at RSA 2025? What’s your booth number, and what kind of experience can visitors expect when they stop by?
Cragle: Although we won’t have a booth on the main expo floor this year, we will host meetings in a suite a short distance away. These meetings will allow in-depth discussions and demonstrations in a more personalized setting.
We’ll also offer live demos of our new Cyber Risk and Exposure platform, Dassana, at Mel’s Drive-In. This will be an informal “tech talk” in a relaxed, sales-pressure-free atmosphere where you can enjoy some BBQ and experience the power of our detection and response workflows. You’ll see firsthand how Deepwatch and Dassana work together to deliver comprehensive threat protection.
VMblog: What is your message to RSA attendees coming out to the show this year?
Cragle: This year, our main goal is to simplify and streamline the overwhelming amount of security information, cutting through the noise. The cybersecurity landscape is saturated with dashboards and detection mechanisms, but security teams need less distraction, faster decision-making, and relevant, impactful context. This is where the combined expertise of Deepwatch and Dassana comes in.
Together, we’re helping customers turn alert fatigue into actionable insights and SOC chaos into streamlined, decisive action. We achieve this by directly integrating your existing tool stack, providing a more comprehensive and clear risk assessment of your operational environment. Our integrations include various industry-leading tools like Wiz, Crowdstrike, AWS, Azure, Defender, and Tenable.
VMblog: What were your key learnings from 2024’s security landscape, and how have those insights shaped your solutions for 2025?
Cragle: The 2024 surge in identity-centric attacks and MFA bypasses underscored the necessity of context-driven detection over signature-based methods. The Deepwatch 2025 roadmap emphasizes deeper identity analytics, purposeful automation, and adaptive, real-time response workflows customized to each customer’s environment. We also target asset management by enhancing visibility across cloud, datacenter, and mobile assets through expanded integrations. Additionally, we prioritize detecting and preventing AI-driven attacks, such as advanced phishing, by strengthening perimeter defense and employee protection through a shift-left approach.
VMblog: With AI being a major focus in cybersecurity, how is your company leveraging or addressing AI both as an opportunity and a potential threat vector?
Cragle: Deepwatch leverages AI to address critical SOC challenges by prioritizing alerts, enriching signals with external threat intelligence, correlating logs, and reducing false positives. We also recognize AI’s potential threat and actively monitor how adversaries utilize generative AI for phishing, evasion, and malware development. Our proactive approach to defense and detection, shifting left, enables us to identify threats earlier for faster remediation.
VMblog: What market challenges or pain points is your company addressing at RSA 2025? How have these evolved from previous years?
Cragle: There are three significant issues that we aim to address:
- An overwhelming number of alerts without enough context leads to SOC overload.
- Security teams must manage too many disconnected tools, resulting in tool sprawl.
- There are two challenges to slow response times: understanding the situation and responding quickly.
The Deepwatch and our new Cyber Risk and Exposure platform, Dassana, are designed to solve these issues by combining managed detection with orchestration that can be customized to fit each customer’s specific tools and workflow. These pain points aren’t new, but the stakes are higher. What’s changed is the urgency-and the need for solutions that work right now, not just in theory.
VMblog: How is your company addressing the growing concerns around supply chain security and third-party risk management?
Cragle: Our MDR services help customers monitor and respond to risks from third-party vendors, cloud platforms, and external attack surfaces. We also ingest external telemetry and threat intel related to supply chain actors, helping customers quickly correlate that intelligence against their environment. It’s proactive defense, not just reactive cleanup.
VMblog: What role does zero trust play in your security strategy and solutions? How are you helping organizations implement zero trust effectively?
Cragle: Our comprehensive approach empowers customers to validate their Zero Trust architectures through continuous, real-time monitoring and analysis of potential security threats. This includes vigilant tracking of lateral movement, privilege escalation, and policy violations that may occur across various endpoints, user identities, and cloud-based services. By proactively identifying and mitigating these risks, organizations can strengthen their security posture and ensure compliance with Zero Trust principles.
VMblog: With the rise in sophisticated ransomware attacks, how does your solution help organizations better prepare and respond?
Cragle: We focus on speed and precision. When ransomware hits, every second counts. Before encryption begins, our threat detection is built to surface early signs, like initial access, command and control, or lateral movement. Our 24/7 SOC then works with customers to contain the threat, escalate confidently, and get back to business quickly.
VMblog: How is your company addressing the challenges of securing hybrid and multi-cloud environments?
Cragle: The Deepwatch cloud-native MDR services integrate with all major cloud providers (AWS, Azure, GCP) and on-prem environments through data sources. We ingest telemetry from all sources, correlate it, and apply context-aware analytics for a complete picture. Our new Cyber Risk and Exposure platform, Dassana, also integrates with cloud providers to enhance risk management and threat exposure.
VMblog: What’s your perspective on the most critical cybersecurity trends shaping the industry in 2025-2026?
Cragle: Key future cybersecurity threats and changes:
- AI-powered attacks: Advanced AI can generate adaptable, self-learning malware that is difficult to detect and counter. Additionally, AI can be leveraged to develop sophisticated phishing attacks and convincing deepfakes.
- Cloud-native attacks: Attackers will target IAM systems and APIs, exploiting vulnerabilities in cloud environments.
- CISO as business enabler: CISOs will transition into the role of strategic business partners, becoming crucial to enabling business growth. They will achieve this by harmonizing security measures with overarching business objectives and adeptly managing cyber risk.
Overall, the future of cybersecurity will be marked by rapid technological advancements, evolving threat actors, and a greater emphasis on risk management and business alignment. Organizations that can adapt to these changes and proactively address emerging threats will be best positioned for success in the digital age.
VMblog: How does Deepwatch MDR help organizations address regulatory compliance and emerging privacy requirements?
Cragle: Deepwatch MDR enables organizations to meet regulatory and privacy requirements by delivering continuous threat detection and response aligned with NIST, ISO 27001, HIPAA, PCI DSS, and GDPR standards. Our services provide 24/7 monitoring, audit-ready reporting, and strong data privacy practices, helping customers demonstrate control effectiveness and maintain compliance. Deepwatch identifies security gaps, maps findings to regulatory frameworks, and supports third-party risk management for cloud and SaaS environments.
VMblog: How can security leaders better prepare their organizations for the evolving threat landscape in 2025 and beyond?
Cragle: Deepwatch empowers security leaders to stay ahead of threats with a proactive MDR approach that combines real-time detection, AI-driven automation, and actionable threat intelligence. By helping organizations shift left to reduce exposure, improve response workflows, and align security operations with business risks, Deepwatch strengthens cyber resilience. We also provide board-ready metrics, playbooks, and strategic insights that elevate security maturity and prepare teams for the future of cybersecurity.
VMblog: Is your company involved in any parties or gatherings that a show attendee can participate in?
Cragle: Join the Deepwatch team at Mel’s Drive-In for great food, conversation, and a hands-on look at how our Dassana Product changes the MDR game.
VMblog: As an experienced RSA sponsor, what advice would you give to attendees to make the most of their conference experience?
Cragle: Be selective. Don’t just chase swag or sit through another generic pitch. Look for the tech that solves a problem you have today. And talk to real humans-whether they’re founders, CISOs, SOC leads, or engineers-because that’s where the good stuff is.
VMblog: Why did Deepwatch acquire Dassana?
Cragle: The acquisition of Dassana was driven by our recognition of their innovative approach to security operations. Their platform stood out not as just another tool in the arsenal, but as a robust, adaptable foundation for context-driven automation. Integrating Dassana into our operations allows us to bridge the gap between MDR and tool integrations, creating a seamless transition from alert to action. This strategic move emphasizes our commitment to speed, scalability, and enhancing the efficiency of security defenders by streamlining processes and reducing manual intervention.
VMblog: Why should organizations prioritize MDR in 2025 and beyond?
Cragle: Because the threat landscape never sleeps-and neither should your detection and response. MDR gives organizations access to a 24/7 SOC without the overhead of staffing, tooling, and training one internally. That means faster response times, fewer missed alerts, and clarity when it matters most. It also allows security leaders to right-size their teams, focusing internal resources on higher-value strategic initiatives instead of chasing down false positives. In short, MDR delivers scale, expertise, and peace of mind in one package.
VMblog: And finally, what’s next for Deepwatch?
Cragle: Deepwatch is revolutionizing MDR, envisioning a future where it transcends service to become an integrated, automated, and context-aware security ecosystem. Our acquisition of Dassana is not merely a business move; it strategically accelerates this vision. Deepwatch creates a powerful synergy by combining advanced detection engineering with dynamic response capabilities.
Consequently, our customers can anticipate a significant enhancement in their security posture. Alerting will be faster and more efficient, threat correlations will be smarter and more insightful, and the platform will adapt to the specific nuances of each customer’s environment. This is not just about keeping up with threats; it’s about anticipating, understanding, and neutralizing them with precision and speed.
##






