Are you getting ready for the upcoming RSA Conference, the world’s leading information security conference and exposition? The event is quickly approaching, taking place May 6 – 9, 2024 at the Moscone Center in San Francisco. This year’s theme: The Art of Possible – as we collectively create works that will change our perspective on what we can accomplish. Let’s celebrate limitless opportunities, challenge the status quo, and explore new horizons together.
Ahead of the show, VMblog received an exclusive interview with Curtis Simpson, Chief Information Security Officer and Chief Advocacy Officer at Armis, the asset intelligence cybersecurity company.
VMblog: To kick things off, give VMblog readers a quick overview of the company.
Curtis Simpson: Armis is the asset intelligence cybersecurity company. Our AI-powered cybersecurity technology enables organizations to see, protect and manage all physical and virtual assets – from the ground to the cloud – ensuring the entire attack surface is both defended and managed in real-time.
Armis CentrixTM is our cyber exposure management platform. It is powered by the Armis AI-driven Asset Intelligence Engine, monitoring billions of assets worldwide in order to identify cyber risk patterns and behaviors. Armis CentrixTM is a seamless, frictionless, cloud-based platform that proactively mitigates all cyber asset risks, remediates vulnerabilities, blocks threats and protects the entire attack surface.
Armis secures Fortune 100, 200 and 500 companies as well as national governments, state and local entities to help keep critical infrastructure, economies and society safe and secure 24/7.
VMblog: How can attendees find you at the show? How many folks are you sending? What can attendees expect?
Simpson: Armis has a number of events planned for RSAC this year. Of course, attendees can stop by our booths (S-734 and S-3411) to connect with our experts and learn more about Armis CentrixTM. Throughout the week we’ll have in-booth presentations and product demos as well as threat hunts. We’ll also be scanning for a cause again this year, so every badge scanned will result in a donation to St. Jude’s Children’s Research Hospital.
Other activities include:
- RSAC Public Sector Day (May 6) – Connect with our federal and SLED teams to learn more about the cyber threat challenges faced by all levels of government, including data protection, ransomware, election security and the potential for attacks on critical infrastructure.
- Live the Suite Life (May 7) – Join Armis for a happy hour event alongside Panorays and IONIX, featuring lively conversations, hors d’oeuvres and cocktails. Learn more and RSVP here.
- RSAC Speaking Session (May 8) – Armis’ Co-Founder and CTO, Nadir Izrael, will be presenting at RSAC in a session surrounding, From Boardrooms to Polling Places: Securing Critical Infrastructure in 2024. The session will take place on Wednesday, May 8, from 8:30-9:20 am PT in Moscone South, 156. Reserve a seat.
- CISO Luncheon (May 8) – RSVP for this candid panel discussion as I speak with fellow CISOs on the most pressing security concerns and how to solve them.
- OT Breached! Tabletop Exercise (May 8) – Work with your peers and gain insights from OT cybersecurity experts at Armis, Booz Allen, ThreatModeler and DeepSeas. Register now!
With nearly 80 of my Armis colleagues attending the show this year, including 19 executive leaders who you can book a meeting with, it’s sure to be an exciting week! More details on what we have in store can be found here.
VMblog: What made you sponsor RSAC this year? Is this a must sponsor event for your company?
Simpson: RSA Conference continues to be one of the flagship shows in the cybersecurity industry, so it is a must-sponsor event for Armis. Year after year, we’ve held meaningful conversations at RSAC with our customers, partners and prospects. It’s also great to connect with other industry vendors and professionals in person to discuss key trends and developments happening within the space.
VMblog: What key challenges are leaders facing today? What examples can you cite?
Simpson: Organizations have historically taken a reactive approach to cybersecurity, with security teams in a constant cycle of responding to threats and attacks after they occur, resulting in compromised data, damaged reputations and significant financial loss. This reactive stance has often left organizations playing an endless game of catch-up with cybercriminals, who continuously evolve their tactics to exploit new vulnerabilities.
VMblog: What is your message to RSAC attendees coming out to the show this year?
Simpson: Security teams today should feel empowered to stay ahead of emerging threats and proactively protect their critical physical and virtual assets. They must flip the script on bad actors, stopping attacks before they impact their organization. Armis is here to help with this. RSAC is a great opportunity to connect to discuss how we can support you and your organization’s unique needs.
VMblog: What market needs or problems are you addressing in the security space?
Simpson: We live in a rapidly evolving, perimeter-less world where traditional cybersecurity boundaries no longer exist. Legacy on-premises systems and point solutions are no longer fit for purpose, leaving the attack surfaces of organizations and their most critical assets open and exposed to cyber criminals.
Organizations need a comprehensive platform that can address the entire lifecycle of cybersecurity threats. We have built our AI-powered Armis CentrixTM platform to encompass all facets of cyber threat exposure management – from asset discovery and management to early warning threat detection and vulnerability discovery, prioritization and remediation.
VMblog: What are some of the key takeaways of your solution that RSA Conference goers should be aware of? And what sets you apart from the competition?
Simpson: Armis CentrixTM delivers a true modular approach to cyber exposure management covering the most critical cybersecurity needs for customers across five solutions:
- Asset Management and Security: Continuously discovers all of an organization’s assets, including IT, IoT, cloud and virtual, managed or unmanaged.
- OT/IoT Security: Secures manufacturing and critical infrastructure by achieving full visibility across IT, OT and IoT assets. Control, monitor and protect critical OT assets and critical infrastructure using the industry’s most advanced cyber exposure platform.
- Medical Device Security: Discovers and secures every clinical asset and tracks inventory utilization. Get complete visibility and maximize security across all managed or unmanaged medical devices, clinical assets and the entire healthcare device ecosystem.
- Vulnerability Prioritization and Remediation: Enables vulnerability managers to see all vulnerabilities and prioritize them based on vulnerability criticality and business risk.
- Actionable Threat Intelligence: An early warning, AI-based system that leverages the dark web, dynamic honeypots and human intelligence to anticipate threats, understand their potential impact and take preemptive action to neutralize them, effectively moving the security posture from defense to offense.
We also have the world’s largest AI-driven Asset Intelligence Engine – tracking over four billion assets and growing – that understands “known good” behavior baselines. Armis learns from past attack attempts on one company and immediately applies those learnings to all of our global customers.
Only Armis CentrixTM protects all verticals and industries including Manufacturing, Health and Medical, Information Technology, Energy and Utilities, Financial Services, Transportation, Telecommunications and Media, Public Sector and many more.
VMblog: What will you be showing off at the show this year?
Simpson: We’re excited to showcase the latest updates to Armis CentrixTM at RSAC. Our newest solution, Armis Centrix TM for Actionable Threat Intelligence, leverages a combination of AI and machine learning that scours the dark web to proactively identify preparatory indicators of attacks and exploits.
In addition, our recent acquisition of Silk Security enhances the prioritization and remediation capabilities of Armis CentrixTM for Vulnerability Prioritization and Remediation. This includes consolidating and organizing security findings, automating prioritization, assigning remediation owners and much more.
VMblog: What are some top priorities for security leaders at RSAC to consider this year?
Simpson: AI is certainly top of mind for everyone. The business reality is that manual processes and legacy solutions are no longer fit for purpose. Only AI-powered solutions can combat AI-driven cyber threats.
Legacy technology also continues to be an issue. Our research found industries still using end-of-life (EoL) or end-of-support (EoS) OSs that are no longer actively supported or patched for vulnerabilities and security issues by the manufacturer include Educational Services (18%), Retail (14%), Healthcare (12%), Manufacturing (11%) and Public Administration (10%).
On top of that, businesses are struggling with effective vulnerability prioritization. Patch rates for critical CVEs are not prioritized, and, irrespective of the weaponization status of a CVE, organizations consistently grapple with patch rates at 62% for non-weaponized and 61% for weaponized vulnerabilities.
VMblog: What are some of the security best practices you would deem critical?
Simpson: Organizations must adopt a comprehensive cybersecurity strategy that proactively mitigates all cyber asset risks, remediates vulnerabilities and blocks threats to protect the entire attack surface. This should include segmenting legacy technology and prioritizing exposures of the greatest significance so that security teams can focus their efforts on the most pressing vulnerabilities.
Additionally, it’s important that CISOs empower their teams with AI-driven solutions and automation. Security teams are already short-staffed, and the overload of threat information is exacerbated by the increased sophistication of cyber attackers. By leveraging AI-powered technologies, organizations can better defend and manage the attack surface in real-time.
VMblog: The keynote stage will be talking about major themes this year. But what trends is your company seeing that we should be aware of in 2024 and beyond?
Simpson: In the biggest global election year in history, we are seeing that democracy is at risk due to nation-state threat actors. Armis’ second annual cyberwarfare report, The Invisible Front Line: AI-Powered Cyber Threats Illuminate the Dark Side, revealed that 66% of U.S. IT leaders doubt the American government can defend its citizens and enterprises against an act of cyberwarfare and 40% believe cyberwar could affect the integrity of an electoral process.
Armis Labs also uncovered that several threat actors from Russia, North Korea, Iran and China are actively using AI to advance their cyber capabilities. Meanwhile, 54% of U.S. security professionals admit their organization has stalled or stopped digital transformation projects due to the threat of cyberwarfare. It’s essential that security teams continue to innovate so they don’t fall further behind – the only way to fight AI-fueled cyber threats is with AI-powered solutions.
VMblog: Does your company have any speaking slots at RSAC? If so, can you tell us more about those sessions so people can get them on their schedules?
Simpson: Yes! As mentioned, our Co-Founder and Chief Technology Officer, Nadir Izrael, has a session surrounding, From Boardrooms to Polling Places: Securing Critical Infrastructure in 2024 on Wednesday, May 8, 2024, from 8:30-9:20 am PT. He will highlight findings from Armis’ recently released threat intelligence report and highlight how AI-powered cyber exposure management can empower security teams to proactively improve their organization’s cybersecurity postures and stop attacks before they happen.
VMblog: As a show sponsor, do you have any tips for attendees to better prepare or handle the conference?
Simpson: RSAC goes by in the blink of an eye! We highly recommend planning out your schedule in advance so that you have enough time to attend must-see sessions and stop by vendor booths as well as network with fellow security professionals.
##






