Skip to content
Artwork for David Bombal
David Bombal · August 20 · 28 min

#596: This is the Real Cybersecurity Problem

Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people. Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem. For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place. They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it. Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders. Topics include: Why cybersecurity may be a software quality problem Why users are blamed for insecure software CISA’s Secure by Design initiative Why default passwords should disappear AI agents behaving in unexpected ways AI and the future of zero-day attacks Memory safety, C, C++ and Rust Government regulation and vendor accountability The EU Cyber Resilience Act Why Patch Tuesday may eventually become unacceptable How AI could help defenders find and fix vulnerabilities Jen Easterly’s advice for cybersecurity professionals If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss. // Jen Easterly’s SOCIAL // LinkedIn: / jen-easterly // Website REFERENCE // https://www.cisa.gov/ // David's SOCIAL // Discord: discord.com/invite/usKSyzb Twitter: www.twitter.com/davidbombal Instagram: www.instagram.com/davidbombal LinkedIn: www.linkedin.com/in/davidbombal Facebook: www.facebook.com/davidbombal.co TikTok: tiktok.com/@davidbombal YouTube: / @davidbombal Spotify: open.spotify.com/show/3f6k6gE... SoundCloud: / davidbombal Apple Podcast: podcasts.apple.com/us/podcast... // MY STUFF // https://www.amazon.com/shop/davidbombal // SPONSORS // Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com // MENU // 0:00 - Coming up 0:55 - Jen Easterly introduction & background 04:20 - Advice for the youth 07:10 - Advice for ethical hackers and leadership 11:35 - Software security // Who's to blame? 17:39 - Power and responsibility 21:17 - Secure by design 26:38 - Is it important to attend RSAC? // Conclusion Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel! Disclaimer: This video is for educational purposes only. #rsac #bhusa2026 #securebydesign

0:00-28:03

transcript

No transcript — this publisher did not publish one.

show notes

Thank you to Threatlocker for sponsoring my trip to Black Hat so I can interview amazing people.


Jen Easterly joins David Bombal to discuss why today’s cybersecurity problem may actually be a software quality problem.


For decades, users and organizations have been blamed for failing to patch systems, change default passwords, or enable MFA. Jen argues that the bigger question is whether software vendors should be held responsible for shipping insecure products in the first place.


They discuss Secure by Design, software vulnerabilities, memory safety, AI security, zero-day attacks, rogue AI agents, critical infrastructure, vendor accountability, and how artificial intelligence could dramatically shorten the time between discovering a vulnerability and weaponizing it.


Jen also shares lessons from her career at the NSA, the White House, CISA, Morgan Stanley, the U.S. Army, and now RSAC, including her advice for hackers, cybersecurity professionals, and future leaders.


Topics include:

Why cybersecurity may be a software quality problem

Why users are blamed for insecure software

CISA’s Secure by Design initiative

Why default passwords should disappear

AI agents behaving in unexpected ways

AI and the future of zero-day attacks

Memory safety, C, C++ and Rust

Government regulation and vendor accountability

The EU Cyber Resilience Act

Why Patch Tuesday may eventually become unacceptable

How AI could help defenders find and fix vulnerabilities

Jen Easterly’s advice for cybersecurity professionals


If you work in cybersecurity, ethical hacking, software development, networking, AI security, or critical infrastructure, this is a conversation you don’t want to miss.


// Jen Easterly’s SOCIAL //

LinkedIn: / jen-easterly


// Website REFERENCE //

https://www.cisa.gov/


// David's SOCIAL //

Discord: discord.com/invite/usKSyzb

Twitter: www.twitter.com/davidbombal

Instagram: www.instagram.com/davidbombal

LinkedIn: www.linkedin.com/in/davidbombal

Facebook: www.facebook.com/davidbombal.co

TikTok: tiktok.com/@davidbombal

YouTube: / @davidbombal

Spotify: open.spotify.com/show/3f6k6gE...

SoundCloud: / davidbombal

Apple Podcast: podcasts.apple.com/us/podcast...


// MY STUFF //

https://www.amazon.com/shop/davidbombal


// SPONSORS //

Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com


// MENU //

0:00 - Coming up

0:55 - Jen Easterly introduction & background

04:20 - Advice for the youth

07:10 - Advice for ethical hackers and leadership

11:35 - Software security // Who's to blame?

17:39 - Power and responsibility

21:17 - Secure by design

26:38 - Is it important to attend RSAC? // Conclusion


Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!


Disclaimer: This video is for educational purposes only.

#rsac #bhusa2026 #securebydesign