Opens in a new tab
vmblog logo 2024 wht (updated)

FireMon at RSAC 2026: VP of Marketing Mark Byers on Policy Governance, Zero Trust Operations, and What’s Coming in the Booth – VMblog QA

Share: 

David Marshall | Published: March 20, 2026
RSAC 2026 Q&A

As enterprise security environments grow more complex — spanning on-premises firewalls, multi-cloud platforms, microsegmentation, and Zero Trust Network Access controls — the challenge facing security teams is no longer whether they have the right enforcement tools. It’s whether they can actually govern the policies behind them. Ahead of RSA Conference 2026, VMblog caught up with Mark Byers, VP of Marketing at FireMon, to get his read on the themes dominating this year’s show and what his team is bringing to the floor.

From the evolution of Zero Trust from architectural framework to operational reality, to the growing role of AI in analyzing policy drift at scale, Byers offers a practitioner-focused perspective on where enterprise security is headed. He also pulls back the curtain on FireMon’s booth experience, where the company will be live-demoing its security policy control plane across network access, segmentation, and cloud enforcement — making the case that unified policy governance isn’t just a nice-to-have, it’s the missing layer most hybrid environments are crying out for.

++

VMblog: What are the biggest security challenges organizations are facing as they approach RSA 2026?

Mark Byers: One of the biggest challenges security teams face today is not a lack of security tools. It is a lack of control over the policies that those tools enforce. Modern enterprise environments are highly distributed. You have firewalls in the data center, cloud security groups across multiple providers, microsegmentation platforms at the workload layer, and increasingly Zero Trust Network Access controls for users.

Each of these systems enforces policy independently, but they rarely share a common way to validate whether those policies actually align with the organization’s security intent. As a result, teams often end up with fragmented policy models and limited visibility into how access decisions are being made across the environment.

Organizations are starting to realize that Zero Trust is not just about deploying enforcement technologies. It is about governing the policies behind them. That shift toward policy governance is becoming a central topic in many conversations leading up to RSA.

VMblog: What trends do you expect to dominate the conversations at RSA this year?

Byers: Zero Trust will still be part of the conversation, but the tone around it is changing. A few years ago, the focus was on frameworks and architectural models. Now, most enterprises already have some form of Zero Trust controls in place. The question security teams are asking today is much more operational: how do we run this environment day-to-day without creating complexity that slows the business down?

One trend I expect to see discussed heavily is the gap between security architecture and security operations. Many organizations have invested in firewalls, segmentation technologies, and cloud security controls, but the policies across those systems are often managed independently. Security teams are realizing that deploying enforcement tools is only part of the problem. Maintaining policy consistency across hybrid environments is becoming a harder challenge.

Another major topic will be automation and AI applied to security operations. There is a lot of excitement around AI, but practitioners are also trying to figure out where it actually provides value. In many cases, the most immediate impact is helping teams analyze large volumes of configuration and policy data to identify risk, misconfigurations, and policy drift that would be difficult to detect manually.

Finally, I think we will hear more discussion about security operating at infrastructure scale. Enterprise environments now span on-premises networks, multiple cloud providers, containers, and distributed workloads. That has dramatically increased the number of access policies organizations must manage. Security teams are looking for ways to simplify operations and maintain control across these environments without introducing additional complexity.

VMblog: What will FireMon be showcasing at RSA this year?

Byers: At RSA, FireMon is showcasing how organizations establish a true control plane for security policy, specifically across network access policy, segmentation policy, and cloud enforcement policy in hybrid environments.

Firewalls, cloud platforms, and segmentation technologies enforce controls. FireMon operates above them to define, validate, and continuously govern how policy behaves across those enforcement layers.

In the booth, we’re focused on three live demo experiences:

  • Unified policy visibility across access, cloud, and segmentation controls

 A single, normalized view of firewall rules, cloud security groups, and microsegmentation policy so teams can understand how access is actually enforced across the environment.

  • Change simulation and impact analysis

The ability to model how policy changes affect access, risk, and connectivity before they are implemented, reducing uncertainty and preventing unintended consequences.

  • Continuous compliance validation and policy drift detection

Ongoing validation of policy against standards, with detection of drift and misalignment between intended and enforced access, along with audit-ready evidence.

Across all three, the focus is control. FireMon ensures that access, segmentation, and cloud policies remain aligned to intent, continuously validated, and safe to change over time.

We are also highlighting how this applies to Zero Trust and microsegmentation. Many organizations have deployed segmentation controls but lack a way to continuously govern them. FireMon provides the layer that validates segmentation intent, detects cross-plane inconsistencies, and keeps policy aligned as environments evolve.

VMblog: Why is policy governance becoming such an important topic for security leaders?

Byers: The short answer is scale. Enterprise environments have grown dramatically in complexity over the past decade. Hybrid cloud adoption, containerized workloads, distributed applications, and remote work have all increased the number of policies organizations must manage.

Each new environment introduces additional access rules, connectivity paths, and potential points of exposure. Without a centralized way to analyze and validate those policies, security teams often rely on manual reviews and institutional knowledge.

That approach does not work well at enterprise scale. Security leaders need a consistent way to understand what their policies are doing, how those policies interact across platforms, and what the risk impact of changes might be.

Policy governance allows teams to move faster while reducing the likelihood of outages, misconfigurations, or unintended access.

VMblog: What advice would you give to organizations trying to operationalize Zero Trust?

Byers: Start by focusing on policy rather than only enforcement technologies.

Most organizations already have many of the enforcement tools they need, including firewalls, identity systems, segmentation platforms, and access controls. The real challenge is making sure the policies across those systems remain aligned as environments change.

Security teams should prioritize visibility and validation across all enforcement layers. This means analyzing policies from multiple platforms in a unified model, simulating changes before they go live, and continuously checking policies against compliance requirements and architectural intent.

When organizations treat policy governance as a core component of their security architecture, Zero Trust becomes much easier to implement and maintain.

VMblog: Where can attendees learn more about FireMon at RSA?

Byers: We encourage anyone attending RSA to stop by the FireMon booth to see how policy governance can help make Zero Trust operational. Our team will be demonstrating how organizations can analyze, validate, and control policy across hybrid environments, from traditional firewalls to cloud security controls and microsegmentation platforms.

It is a great opportunity to see how security teams are moving from fragmented policy management toward a unified approach to controlling security policy.

##