Opens in a new tab
vmblog logo 2024 wht (updated)

Sumo Logic's Chas Clawson on AI-Driven Security Operations and Fifth Gen SIEM at RSA Conference 2025

Share: 

David Marshall | Published: April 16, 2025

The RSA Conference (RSAC), the premier cybersecurity industry event, returns to San Francisco’s Moscone Center April 28-May 1, 2025, bringing together thousands of security professionals, vendors, and thought leaders from across the globe. This annual gathering serves as the definitive forum for the latest cybersecurity innovations, trends, and best practices, featuring hundreds of educational sessions, keynotes from industry luminaries, and an expansive expo floor showcasing cutting-edge security solutions. For organizations navigating today’s complex threat landscape, RSAC provides unparalleled networking opportunities, hands-on training, and essential insights to help bolster defense strategies against evolving cyber threats. 

In this exclusive VMblog interview, Chas Clawson, Field CTO, Security at Sumo Logic, discusses how the company is transforming security operations through its cloud-native, AI-driven Log Analytics Platform.

Clawson shares insights on how Sumo Logic is addressing the shift toward Fifth Generation SIEM solutions, leveraging AI to provide actionable security context rather than just more alerts, and helping organizations consolidate their security tools for improved threat detection and response. Ahead of RSA Conference 2025, where the company will showcase its latest innovations at Booth 6261, Clawson explains how Sumo Logic’s unified platform is designed to reduce operational friction, accelerate investigations, and turn security teams from overwhelmed responders into proactive defenders. 

++

    VMblog:  Give VMblog readers a quick overview of your company and its core mission in the cybersecurity space.

    Chas Clawson:  Sumo Logic is a leading cloud-native, AI-driven Log Analytics Platform that helps make the digital world faster, more reliable, and more secure. At the core of our mission is the belief that logs are the most powerful, naturally generated source of insight in digital systems. By harnessing the power of logs, we unify data across development, security, and operations teams to help protect against modern threats and drive greater visibility into complex cloud infrastructures.

    Sumo Logic transforms security teams from overwhelmed responders into proactive defenders-reducing risk, accelerating threat containment, and strengthening resilience. Our platform enables an Intelligent Security Operations (SecOps) strategy by centralizing security log management at scale and empowering TDIR with real-time analytics, automation, and cross-cloud visibility. By reducing mean-time-to-detect (MTTD) and mean-time-to-respond (MTTR), Sumo Logic turns raw data into actionable insights, helping organizations connect the dots and protect critical assets faster.

    VMblog:  What were your key learnings from 2024’s security landscape, and how have those insights shaped your solutions for 2025?

    Clawson:  In 2024, it became clear that security teams don’t need more alerts or disconnected tools-they need actionable context and automation that drives outcomes. Teams were overwhelmed by noisy threat feeds and siloed systems that slowed investigations and increased risk. That’s why our 2025 roadmap focuses on reducing operational friction and helping teams act faster through AI-driven capabilities like Mo Copilot and AI-powered alerting, which enrich, correlate, and prioritize signals to surface what matters most.

    At the same time, the SIEM market underwent a major shift. Vendor consolidation, tool fatigue, and rising costs prompted organizations to reevaluate legacy solutions. This shift is driving the rise of Fifth Gen SIEM-platforms purpose-built for modern, cloud-native security operations with AI and automation at their core. At Sumo Logic, we’re embracing this evolution by strengthening our Cloud SIEM with AI-powered analytics, real-time normalization, behavior-based detection, built-in threat intelligence, and MITRE ATT&CK mapping. These advancements are designed to help teams reduce complexity, accelerate detection and response, and drive business continuity through Intelligent SecOps.

    VMblog:  With AI being a major focus in cybersecurity, how is your company leveraging or addressing AI both as an opportunity and a potential threat vector?

    Clawson:  AI is transforming cybersecurity-and fast. But while many vendors race to integrate AI into their solutions, the real opportunity lies in how it’s applied. At Sumo Logic, we’ve embedded AI as a foundational part of our cloud-native platform, helping security teams reduce risk, accelerate threat containment, and ensure a more resilient security posture.

    Our approach focuses on using AI to deliver actionable context, not just more alerts. Capabilities like Mo Copilot and AI-powered alerting help analysts cut through noise, accelerate investigations, and prioritize meaningful threats. Combined with integrated threat intelligence and behavioral analytics, these capabilities support the shift to Fifth Gen SIEM and Intelligent SecOps-where automation, context, and real-time analytics converge to enable frictionless security operations.

    We’re also mindful that AI introduces new risks. As threat actors begin to target and manipulate AI systems, we continuously monitor, test, and refine our models to ensure they remain accurate, reliable, and resilient against adversarial inputs. AI must be engineered for trust-built to perform under pressure and deliver in real-world security operations.

    VMblog:  How does your solution help organizations address regulatory compliance and emerging privacy requirements?

    Clawson:  Sumo Logic addresses compliance and privacy requirements by delivering centralized, cloud-native log management with built-in support for major frameworks like PCI-DSS, GDPR, HIPAA, and SOC 2. Our platform ingests and normalizes logs from across hybrid environments, providing continuous visibility, anomaly detection, and long-term retention for audit and forensics.

    Prebuilt dashboards and alerting policies reduce the need for manual configuration, while automated workflows streamline evidence collection and reporting. This enables teams to meet compliance mandates efficiently and adapt quickly to evolving regulatory landscapes-all within a unified security and observability platform.

    VMblog:  What sets your solution apart in today’s crowded cybersecurity marketplace? Why should RSA attendees prioritize visiting your booth?

    Clawson:  What sets Sumo Logic apart is our cloud-native, AI-driven platform that integrates logs-first analytics, Cloud SIEM, and SOAR to quickly ingest, normalize, and analyze terabytes of data-orchestrating automated responses to evolving threats. In a market flooded with siloed tools and partial integrations, we offer true end-to-end visibility across cloud, hybrid, and on-prem environments-so nothing critical gets missed.

    Rather than adding to tool sprawl, we help security teams consolidate and streamline their workflows-bringing together detection, investigation, and response in one unified platform. This reduces operational friction, improves time to detection and response, and gives teams the clarity and scale they need to protect critical assets.

    At RSA 2025, we’re addressing some of the most persistent challenges in the industry: fragmented tools, overwhelming alert volumes, and the growing complexity of cloud security. We’ll be unveiling new innovations across AI, threat intelligence, and detection workflows-built to help teams stay ahead of evolving threats. Visit us at Booth 6261 to see how Sumo Logic supports the shift to Intelligent SecOps-turning raw data into action and transforming overwhelmed responders into proactive defenders.

    VMblog:  How can security leaders better prepare their organizations for the evolving threat landscape in 2025 and beyond?

    Clawson:  To prepare for the evolving threat landscape, security leaders must shift from reactive, tool-heavy environments to an intelligent, outcome-driven security strategy. Centralized log management and AI-powered TDIR are critical to enabling this shift-reducing response times, eliminating alert fatigue, and increasing visibility across the enterprise.

    This approach isn’t just about improving detection-it’s about delivering measurable business outcomes: reduced risk exposure, faster incident resolution, improved compliance, and greater operational efficiency.

    By investing in platforms that unify data and automate investigation workflows, security leaders can empower their teams to act faster, make smarter decisions, and align security more closely with the needs of the business

    VMblog:  Where can attendees find you at RSA 2025? What’s your booth number, and what kind of experience can visitors expect when they stop by?

    Clawson:  You can find Sumo Logic at Booth 6261 in the North Hall at RSA Conference 2025. Stop by to experience the future of Intelligent Security Operations firsthand. We’ll be showcasing live demos of our unified, AI-driven platform-including our latest innovations in Threat Intelligence, UEBA, and Copilot for security investigations. Connect with our experts, catch one of our presentations on detection engineering, agentic SecOps, the role of AI in improving detection fidelity, and of course-grab some great swag while you’re there.

    VMblog:  Are you participating in any speaking sessions or panel discussions at RSA 2025? Can you tell us more about these presentations?

    Clawson:  Yes-we’re excited to be hosting a live speaking session at RSA 2025. Greg Nudelman, Distinguished Product Designer and UX Architect at Sumo Logic, will present “Accelerate Security Investigations with AI-Powered Assistance from Mo Copilot” on Tuesday, April 29 at 4:20 PM in the Executive Briefing Center – North Hall.

    In this session, Greg will demonstrate how Sumo Logic Mo Copilot uses AI-driven insights and natural language queries to streamline investigations, automate analysis, and enhance analyst workflows. Attendees will get a firsthand look at how security teams can reduce investigation time from hours to minutes-unlocking a faster, smarter approach to modern SecOps.

    Don’t miss this opportunity to see the future of AI-powered security in action.

    VMblog:  What exciting demos or interactive experiences can attendees expect at your booth?

    Clawson:  Sumo Logic will be hosting live demos and daily theater presentations at Booth 6261 in the North Hall, Tuesday through Thursday at RSA 2025. Highlights include:

    AI vs. Alert Fatigue: Optimizing Detection in the Security Arms Race

    Presented by Christopher Beier

    • Tuesday, April 29 | 10:30-10:45 AM and 3:50-4:05 PM
    • Wednesday, April 30 | 10:30-10:45 AM
    • Thursday, May 1 | 10:30-10:45 AM

    Detection Engineering: The Backbone of Modern Security Operations

    Presented by Paul Tobia, Senior Product Manager

    • Tuesday, April 29 | 11:20-11:35 AM
    • Wednesday, April 30 | 3:00-3:15 PM

    A Glimpse into the Future of Agentic Security Operations

    Presented by Tej Redkar, Chief Technology Officer, and Oren Shevach, Senior Director of Product Management

    • Tuesday, April 29 | 11:45 AM-12:00 PM
    • Wednesday, April 30 | 11:20-11:35 AM and 4:15-4:30 PM
    • Thursday, May 1 | 10:55-11:10 AM

    Attendees can also experience firsthand how Sumo Logic delivers AI-powered threat detection and response that dramatically reduces resolution time. For deeper conversations, book a 1:1 meeting or private demo with our executive team, technical experts, or product leaders to explore how we can support your 2025 priorities and security goals.

    VMblog:  What is your message to RSA attendees coming out to the show this year?

    Clawson:  This year at RSAC, we’re focused on helping security teams go from alerts to answers-with AI-powered security that thinks like an analyst. The pace and complexity of modern threats demand more than reactive tools-they require an intelligent approach to SecOps that transforms raw data into real-time insight. As mentioned, we will be unveiling a number of security innovations during RSAC to help unify logs-first analytics, Cloud SIEM, SOAR, and threat intelligence to help teams detect, investigate, and respond faster-with context that drives action. Stop by our booth for one of our theater presentations or book a demo online, here, to learn more!

    ##