RSA Conference 2026: what the product trends tell us about the state of cybersecurity
–

In our first article on RSA Conference 2026, we discussed the practical side of attending: what it costs, how to position yourself on the floor, and whether the trade mission was worth it. This article goes a layer deeper. Beyond the logistics, the conference is a mirror held up to the entire cybersecurity industry. What it reflected back this year was fascinating, a little concerning, and in some places, genuinely exciting.
Walking the floor with a product and marketing lens, a few things became impossible to ignore. The dominant colours were blue and purple, to the point where a single orange stand would have stopped traffic. The dominant message was AI, agentic, automated, and the dominant feeling, at least in the central halls, was noise. A lot of noise. Here is what we actually saw, and what we think it means.
The product categories that took over the floor
Three categories were so heavily represented they felt inescapable. The first was AI security, in every conceivable form: AI for the SOC, AI for pentesting, AI for exposure management, AI for identity. The second was application security (AppSec), with vendors ranging from established players to a wave of newer entrants all crowding the same space. The third was identity and access management, which was very heavily present across both halls.
What was conspicuously absent was OT security. In Europe, operational technology security is a hot topic, partly driven by NIS2 compliance pushing companies to take it seriously. At RSA 2026, the category was almost invisible. Nozomi Networks was one of the very few OT-focused vendors we spotted.
Similarly, quantum readiness, a topic that gets discussed constantly in European cybersecurity circles, appeared exactly once on the floor. If your company operates in either of those spaces, that is worth paying attention to: the gap between European market priorities and what dominates RSA is real.
AI was everywhere. The actual debate was more interesting.
Saying “AI was everywhere at RSA” is a bit like saying “there were stands at the trade show.” True, but not the interesting part. What was more revealing was the disagreement underneath the surface. Some vendors were claiming full automation, that their product could handle everything end to end without human intervention. Others were more cautious, saying the technology simply is not there yet. Both groups were standing in the same hall, sometimes as little as ten metres apart, telling completely different stories to the same audience.
The honest answer probably lies somewhere in the middle, and likely closer to the cautious end than the bold claims suggest. It is hard to believe that a company would openly claim full automation if they genuinely could not deliver it, but the incentive to keep pace with competitor messaging is clearly pulling some vendors further than their product reality justifies.
One outside perspective we came across after the event made an observation that resonated: AI is becoming a way to finally execute on security fundamentals at scale, rather than replacing those fundamentals or the people responsible for them. That framing felt much more grounded than most of what the stands were actually saying.
There was also a notable moment of meta-irony: one large brand (Wiz) had created what they were calling an “anti-AI zone,” positioning themselves as a counterpoint to the hype, while simultaneously promoting their own AI features elsewhere on the stand. I do have to admit that while people were talking about this “stunt” online, I almost missed it as the actual event so I do wonder if it was mostly hype.
Shadow AI: the problem everyone agreed on
If there was one AI-related topic where genuine consensus emerged, it was shadow AI, and AI governance in general. The concern is straightforward: employees are using AI tools to be more productive, and security teams often have very limited visibility into where company data is going as a result. It is the shadow IT problem with a new name and a faster adoption curve.
Several of the larger vendors were positioning new solutions specifically around this, which makes sense: they already have the enterprise relationships and the existing client base to make it an upsell rather than a cold sale. Whether those solutions are actually convincing is another matter. The honest reaction from the floor was scepticism. The products exist, the problem is real, but none of the solutions on show felt like a definitive answer yet.
The messaging problem, and who is actually getting it right
We wrote in our first article about the monoculture of booth messaging at RSA. Standing in front of stand after stand that said some variation of “discover, protect, automate” in blue and white, it was genuinely difficult to understand what most companies actually did differently. Some stands had so much text that nobody stopped to read any of it. Others had so little that they were essentially invisible. One stand in the startup section, a cloud security company, had messaging so opaque that even after a direct conversation with a sales rep, the product’s core value was still unclear.
While I expected to see a lot of innovation I quickly realised that with the high cost involved, the bigger share of the event evolves around the big names. Companies which aren’t generally known for their innovative character. The start-up section, however, was a nice exception.
The production values were lower, the backdrops were folding banners, the whole aesthetic was more European trade show than Las Vegas spectacle but the conversations were better. It felt less pushy, less transactional, and more like talking to people who were actually interested in what you thought. The messaging was often still weak, but the human interaction made up for some of it. If you are at RSA looking for real innovation or genuine conversation, the startup rows are where to go, even if you have to seek them out deliberately because they are easy to miss.
I guess that at startups it’s easier to do messaging right. The theory is that the bigger the company, the more approvals a message goes through, and the more it gets smoothed into something inoffensive and forgettable. A startup with one founder and a clear problem to solve has a structural advantage in saying something specific. That rings true from what we saw on the floor.
What this all points to
Walking away from RSA 2026, the product landscape feels like an industry at an inflection point that has not quite tipped yet. There is an enormous amount of money, energy, and ambition concentrated into a relatively small number of product categories, all racing in the same direction with very similar language. In five years, a meaningful percentage of the companies on that floor will not exist in their current form.
The more interesting signal, though, is what was not there. The absence of OT security, the near-absence of quantum readiness, the very cautious real-world AI adoption among security leaders we spoke to, all of that suggests the gap between what the RSA floor is selling and what European enterprise security teams are actually buying is wider than the conference makes it appear. For European cybersecurity companies thinking about where to position themselves, that gap might be exactly where the opportunity is.
Michelle is an expert in understanding target audiences in security and IT, and transforming the product positioning of complex products into sharp, compelling marketing strategies that hit the mark.

Senior Growth Marketing Manager



