RSA Conference LLC announced on January 15, 2026, that former Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly had been appointed chief executive officer of RSAC. The private-sector role covers more than the annual San Francisco conference: Easterly will oversee international programming, Innovation Sandbox, professional membership, education, and initiatives involving artificial-intelligence security, secure software development, and global collaboration.
What was announced
The appointment was announced by RSA Conference LLC, the company behind the RSAC brand. The release does not name a predecessor, describe a succession process, or disclose Easterly’s compensation, contract term, reporting structure, or ownership details.
This is not a government appointment and does not change U.S. cyber policy. It places a former senior government and enterprise security leader at the head of a private cybersecurity organization.
RSAC is broader than its flagship conference
“RSAC” now refers to the broader organization and its year-round community, events, education, startup activity, and professional membership efforts. Its flagship annual event is being referred to as RSAC Conference, although many people still use the historical name “RSA Conference.” WIRED describes RSAC as a separate company with year-round initiatives, rather than simply a once-a-year trade show: WIRED’s coverage.
#1 Best Overall
That distinction matters because Easterly’s mandate is a platform-leadership job. The announcement points toward an effort to keep the San Francisco event as the anchor while expanding continuing engagement with cyber professionals, policymakers, researchers, investors, vendors, and startups.
What Easterly will oversee
| Area | What the announcement identifies |
|---|---|
| Flagship event | The annual conference in San Francisco |
| International work | Expanded programs and global collaboration |
| Innovation Sandbox | The startup contest and wider emerging-company ecosystem |
| Professional community | An emerging or expanding year-round membership platform |
| Education | Learning and professional-development initiatives |
| Security priorities | AI security and secure software development |
In comments reported by WIRED, Easterly also highlighted deeper internationalization, support for AI-driven cybersecurity companies, secure-by-design innovators, and the early-stage expo and startup ecosystem.
Why her background is significant
Easterly brings more than three decades of public- and private-sector experience, according to RSAC. Her career includes U.S. Army service, senior work at the National Security Agency, involvement in building U.S. Cyber Command, and nearly five years leading global cybersecurity at Morgan Stanley. She later directed CISA.
- Government credibility: Her federal experience can help RSAC convene agencies, critical-infrastructure operators, and policymakers.
- Operational perspective: National-security and cyber-operations work gives her familiarity with high-consequence threats and incident coordination.
- Enterprise experience: Morgan Stanley exposed her to the governance, resilience, and risk decisions of a major financial institution.
- Cross-sector bridge: Her résumé spans government, the military, financial services, technology, and security operations—constituencies RSAC tries to bring into the same forum.
Those are implications of her documented career, not promises that a particular program or policy will result.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsWhy AI security is central to the new role
Easterly has described AI and cybersecurity as inseparable, and RSAC lists AI security among its priorities. That phrase covers several distinct problems:
Using AI to defend systems
Security teams are applying machine learning and generative systems to detection, response, vulnerability management, software assurance, and security operations.
Rank #3
Securing AI systems
Models, training data, data pipelines, agents, inference infrastructure, and AI-enabled applications create their own attack surfaces and governance requirements.
Managing AI-amplified cyber risk
Attackers can use automation for phishing, fraud, exploit development, insecure code generation, and abuse at greater speed or scale.
Free tools Windows power users keep installed
One-click scans. No signup required.
The appointment announcement establishes the convergence as a strategic theme. It does not announce a new RSAC standard, certification, research laboratory, investment fund, or AI-governance framework. Specific deliverables remain to be defined.
Rank #4
How her CISA record connects to RSAC’s priorities
SecurityWeek associates Easterly’s CISA tenure with several initiatives and areas of work, including secure-by-design principles, private-sector collaboration against ransomware, the Known Exploited Vulnerabilities catalog, and critical-infrastructure protection: SecurityWeek’s report.
| CISA-era experience | Possible relevance to RSAC |
|---|---|
| Secure-by-Design work | Programming and ecosystem discussions about making software safer before deployment |
| Public-private collaboration | Convening government, vendors, researchers, and operators around shared risks |
| Critical-infrastructure protection | Keeping discussions tied to services whose disruption affects the public and economy |
| Known Exploited Vulnerabilities and risk awareness | Emphasizing practical exposure and prioritization over abstract product claims |
| Ransomware coordination | Maintaining an operational focus for enterprise and government audiences |
These initiatives were agency efforts carried out during her tenure; the available reporting does not support crediting Easterly personally with creating every program.
The political and institutional context
WIRED reports that Easterly led CISA for more than three years and was not asked to remain during the transition at the end of 2024. The Trump administration criticized election-integrity work conducted by CISA under Easterly and her predecessor, Chris Krebs. Easterly has characterized cybersecurity as nonpartisan and said RSAC is a nonpolitical organization open to insights and collaboration from officials across governments.
Best Value
In this setting, “nonpolitical” is best understood as cross-partisan and mission-focused, not as detached from policy. Cybersecurity conferences necessarily address regulation, national security, critical infrastructure, and geopolitical risk. There is no evidence in the announcement that the RSAC appointment was politically motivated or that it represents a change in federal policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What RSAC said about the 2026 conference
The January 15 announcement said RSAC 2026 was scheduled for March 23–26 at Moscone Center in San Francisco. Organizers expected more than 40,000 attendees, 700 speakers, 450 sessions, and 650 exhibitors.
Those were organizer projections published before the event, not audited final results. The release is available at RSAC’s announcement. Final attendance and program figures should be checked against later official reporting rather than assumed from the projection.
What the appointment does—and does not—establish
- Established: Easterly is CEO of RSAC, with responsibility extending across the flagship conference and broader programs.
- Established: International growth, year-round membership, Innovation Sandbox, AI security, and secure software are stated areas of focus.
- Not established: A detailed first-100-days plan, membership targets, revenue goals, new product, AI standard, certification, or investment fund.
- Not disclosed: Compensation, contract length, reporting arrangements, and a named predecessor.
What to watch next
- Whether RSAC publishes concrete membership tiers, benefits, and growth figures.
- How international events and year-round programming expand beyond the San Francisco flagship.
- Changes to Innovation Sandbox, including selection rules, startup support, and outcomes.
- Whether AI-security and secure-by-design themes become education, standards, research, or partnership programs with measurable outputs.
- How RSAC balances government access, vendor sponsorship, startup promotion, and editorial or programming independence.
- Official final attendance, exhibitor, and session data for RSAC Conference 2026.
The central question is execution. Easterly’s appointment supplies a leader whose background can connect public policy, enterprise operations, and innovation, but it does not by itself prove that RSAC’s planned expansion has occurred.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →The Bottom Line
Easterly’s appointment signals an intended shift from a flagship annual cybersecurity event toward a year-round, international community and innovation platform. The direction is clear; the measurable operating plan and results are not yet public.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




