The best part of Black Hat USA has never been the booths or the swag. It’s the people you get to see, and the conversations you didn’t know you needed to have.
This week’s #FollowFriday is dedicated to just a few of the people I had the pleasure of catching up with at Black Hat USA 2026. Some are longtime friends. Some are people I’m still getting to know. All of them gave me something useful to think about long after I escaped Las Vegas.
Jon France

I caught up with Jon France, CISO of ISC2, at a particularly interesting moment for the organization. ISC2 has begun developing a vendor-neutral AI Security certification and is asking cybersecurity professionals around the world to help define its knowledge domains and exam content. Jon has more than 25 years of experience in technology, security and risk, including previous leadership roles with GSMA and LexisNexis, so he brings the kind of perspective this conversation badly needs.
What I appreciated about our Black Hat conversation was that this isn't being treated as another opportunity to slap "AI" onto an existing security credential. The industry is trying to figure out what AI security actually requires from practitioners while the technology itself is changing underneath us. Building a meaningful certification in that environment is a hell of a challenge, and Jon and ISC2 are trying to involve the people who will actually have to do the work.
LinkedIn: Jon France
Raj Mallempati

Raj Mallempati, co-founder and CEO of BlueFlag Security, caught me up on the company's mission, and it lands squarely in one of the areas I've been watching closely: the identities surrounding the software development lifecycle. BlueFlag's argument is that securing the SDLC can't stop at finding vulnerable code. Developers, service accounts, integrations, non-human identities and now AI agents all have access to the machinery producing that code and attackers increasingly understand that those identities can be the easier way in.
Raj has been around this problem from several angles, including previous leadership roles tied to CloudKnox, Microsoft, MobileIron and VMware. BlueFlag is now extending identity governance into AI agents inside development environments, looking at behavioral baselines, privileges, anomalous activity and auditability. That's a mission worth watching because AI is becoming another identity with permissions, access and the ability to act, and most organizations are still figuring out how to govern that.
LinkedIn: Raj Mallempati
Bob Ackerman

Catching up with Bob Ackerman is also an opportunity to catch up with a sizable chunk of cybersecurity history. Before cyber venture capital became its own ecosystem, Bob was already building it. He founded Allegis Capital in 1996, eventually focused the firm entirely on cybersecurity as AllegisCyber Capital, and helped raise what has been described as the world's first dedicated cybersecurity venture fund. He's also co-founder and managing partner of DataTribe, the cyber startup foundry that has built companies around talent and technology emerging from the national-security community.
His history goes back further than investing. Bob was a technology entrepreneur before becoming a VC, including leading InfoGear Technology Corporation, the company behind an early device actually called the iPhone, years before Apple's version became the center of the mobile universe. When someone has watched cybersecurity evolve from an investment niche into one of technology's defining markets, I listen. Bob has spent decades watching technologies, founders, threats and investment cycles come and go, which makes his perspective especially useful amid today's AI gold rush.
LinkedIn: Bob Ackerman
Daniel Rheault

Daniel Rheault of FireMon gave me some numbers at Black Hat that should make anyone responsible for network security policy uncomfortable. FireMon's analysis of 9.2 million policy checks found that 58% of firewalls failed high-severity compliance checks and 48% failed at critical severity. Even more telling: 69% of firewall rules were unused, 45% lacked an owner or documentation, and 17% were redundant or shadowed.
The larger point Daniel shared is bigger than firewall hygiene. Hybrid environments have become too complex to manage policy manually at scale. FireMon's data also found that automated policy workflows showed a 67% lower change-related risk delta than manual changes. That's an important distinction in the current AI conversation: automation is most interesting when we can actually measure whether it reduces operational risk, rather than simply admiring the fact that somebody added an AI button to a dashboard.
LinkedIn: Daniel Rheault
Danny Jenkins

It was also great catching up with Danny Jenkins, co-founder and CEO of ThreatLocker. Danny has been working in cybersecurity since the late 1990s, with a background spanning corporate IT, ethical hacking and incident response. ThreatLocker itself grew out of his frustration with watching businesses get hammered by attacks despite all the security products they had deployed. His answer has been unapologetically proactive: default-deny and Zero Trust controls designed to stop software and activity that shouldn't be running in the first place.
That philosophy is becoming even more interesting as AI changes both sides of the security equation. At Black Hat, Danny was talking about the hidden risks created by workplace AI tools and demonstrating how AI can be used to generate, evade and deliver malware. That's one reason I always enjoy talking with him: Danny tends to drag cybersecurity discussions away from abstractions and back toward the simple question that matters: what can actually execute in your environment, and why are you allowing it?
LinkedIn: Danny Jenkins
Christian Schnedler

One of my more fascinating conversations was with Christian Schnedler of Rilian, a young cybersecurity and defense company built around an unusual idea: take Western cyber and defense capabilities into front-line environments, battle-test them under real-world conditions, and bring what is learned back to the United States and its allies. Rilian is already working across Central Europe and has a major engagement with the UAE Cybersecurity Council involving six sector-specific SOCs and a national SOC. Christian's own path runs through post-9/11 counterterrorism technology, the NYPD Counter Terrorism Bureau, IBM's public-safety practice, defense contracting and cyber/defense investing.
Then there's Caspian, Rilian's agentic platform. Christian walked me through a three-tier architecture in which specialized agents understand individual tools, secondary agents understand classes of technology, and primary agents orchestrate entire workflows and contextualize the results. The use cases range from SOC automation and threat hunting to threat intelligence, red teaming and regulatory scanning, with longer-term ambitions extending into physical security, financial crime and human-trafficking investigations. Bonus points for the company's wonderfully nerdy C.S. Lewis naming scheme: Rilian, Caspian and Dawn Treader. Amid a Black Hat floor overflowing with "agentic AI," this was one of the conversations where the architecture and intended mission were far more interesting than the buzzword.
LinkedIn: Christian Schnedler
Duncan Greatwood

Finally, I caught up with Duncan Greatwood, CEO of Xage Security, and got brought up to speed on all things Xage. Duncan's own background is worth a look: before Xage, he was an Apple executive working on search technologies, CEO of social-search pioneer Topsy before Apple acquired it, and founder and CEO of PostPath before Cisco acquired that company. He joined Xage as CEO in 2017, and today the company's focus has expanded well beyond its early industrial-security roots.
The big story now is Xage's push to apply identity-driven Zero Trust across IT, OT, cloud and AI infrastructure. That's a significant evolution for a company that made its name protecting operational environments and critical infrastructure. Those worlds aren't neatly separated anymore, and AI infrastructure is creating another layer of privileged identities, systems and connections that organizations have to control. Xage is betting that a unified Zero Trust architecture can span all of them. Given how quickly the boundaries between enterprise IT, industrial systems and AI are disappearing, Duncan gave me plenty to keep watching.
LinkedIn: Duncan Greatwood
Black Hat is supposed to be about what's next in cybersecurity. Sometimes you find that on a stage or in a product demo. More often, I find it in conversations like these — with people who have been around long enough to recognize what's actually changing and who are still curious enough to keep challenging their own assumptions.
That's what makes the week worth the sore feet and lack of sleep.