LIVE SESSIONS
Discover the future of data security with Varonis, a global leader committed to protecting your most valuable asset: your data. As a Platinum Plus Sponsor at RSAC 2025, we're excited to show you innovative solutions that classify critical data, remove exposures, and detect threats with AI-powered automation.
Explore Varonis' cutting-edge cybersecurity solutions at booth #N-5658. Our experts will be on hand to demonstrate how our platform:
ABOUT VARONIS
MEET US AT
RSAC2026
PLATINUM PLUS SPONSOR
INSIDE A DB HONEYPOT: LESSONS FROM REAL-WORLD RANSOMWARE ATTACKS
Examine real attacker behavior through a managed database honeypot deployed in cloud environments. By analyzing live ransomware-driven intrusions against intentionally misconfigured Cloud SQL instances, we'll highlight how attackers discover, compromise, and impact managed databases and what these attacks reveal about common security blind spots and detection gaps.
LIVE SESSIONS
LIVE SESSIONS
LIVE SESSIONS
MEET WITH THE VARONIS EXECUTIVE TEAM
Schedule a personalized 1:1 meeting with Varonis executive leadership or product leaders to map your 2026 security outcomes.
LOOKING TO TAKE YOUR DATA SECURITY TO THE NEXT LEVEL?
MEET WITH THE VARONIS EXECUTIVE TEAM
LOOKING TO TAKE YOUR DATA SECURITY TO THE NEXT LEVEL?
Schedule a personalized 1:1 meeting with Varonis executive leadership or product leaders to map your 2026 security outcomes.
Catch live theater talks, deep‑dive demos, and meet the experts behind Varonis Threat Labs. Grab awesome swag, customize your own swag and meet the Varonis team.
Discover the fastest path to secure, trustworthy AI with a live demo of Varonis Atlas. Visit booth N-5457 to see how one platform helps you:
VISIT US IN THE EXPO
Apply real-time guardrails to stop risky AI behavior automatically
Test AI systems for prompt injection and unsafe data exposure
Get full visibility into cloud AI, code-based AI, and shadow AI
FREE EXPO PASS WITH THE VARONIS CODE: 52E1320XP
LIVE SESSIONS
SESSION
WEDNESDAY, MARCH 25 | 11:00 AM
VARONIS BOOTH N-5457
SESSION
MAY THE FORCE BE WITH YOU: 5 SALESFORCE ATTACKS & HOW TO STOP THEM
MOSCONE WEST 2018
MONDAY, MARCH 23 | 2:20 PM
In the ever-evolving cyberthreat space, more and more attackers, including famous APT’s such as ScatteredSpider(UNC3944) & ShinyHunters(UNC6040), are setting their sights on Salesforce. From Community Sites to OAuth apps, SOQL injection to shadow admin, and even insiders stealing data, this session will explore five attack techniques, including a novel one, and show how to detect and help secure your workloads.
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
CLIFF EMBRY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
TAMIR YEHUDA
CLOUD SECURITY RESEARCH TEAM LEAD
DANIEL REYHANIAN
CLOUD SECURITY RESEARCHER
YOGEV MADAR
DIRECTOR OF SECURITY RESEARCH
KEYNOTE: ROBOTS VS. ROBOTS – STORIES FROM THE FRONTLINES OF THE AGENTIC REVOLUTION
AI isn't just accelerating cyberattacks, it's breaking the security model built to control it. In this session, Yaki Faitelson shares real stories from the frontlines that reveal three major ways AI is reshaping enterprise security in real time. From novel AI vulnerabilities to weaponizing trust, we’ll deep dive into techniques and frameworks to help future-proof your AI and data security programs.
KEYNOTE
WEDNESDAY, MARCH 25 | 11:05 AM
RSAC MAIN STAGE
SESSION
FROM PROMPTS TO PERMISSIONS: THE NEW DATA RISK MODEL FOR AI
MOSCONE SOUTH ESPLANADE 153
TUESDAY, MARCH 24 | 8:30 AM
AI assistants and agents change how data is accessed, inferred, and exposed. New attack techniques exploit prompts, retrieved content, and permissions inside trusted systems, bypassing traditional controls. This session will examine emerging AI-driven data risks, why discovery alone isn’t enough, and how security teams can apply controls that scale with AI adoption.
ROB SOBERS
CMO
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
BRIAN VECCI
FIELD CTO
YAKI FAITELSON
CEO
BRIAN VECCI
FIELD CTO
Join Varonis, KPMG, and Microsoft for a high-energy evening of networking, bowling, and bites at Lucky Strike during Microsoft Ignite. Whether you’re looking to unwind after a day of sessions or spark new partnerships, this is your chance to connect with industry leaders and peers in a fun, relaxed setting. Expect great conversations, friendly competition, and a few surprises along the way!
*Must be registered to attend and don’t forget your badge!
STRIKE UP CONNECTIONS WITH VARONIS, KPMG & MICROSOFT
LUCKY STRIKE BOWLING ALLEY
200 KING ST, SAN FRANCISCO, CA 94107
NOVEMBER 19 | 7:00 P.M. – 9:00 P.M.
MEET US AT
RSAC 2026
PLATNIUM PLUS SPONSOR
Catch live theater talks, deep‑dive demos, and meet the experts behind Varonis Threat Labs. Grab awesome swag, customize your own swag and meet the Varonis team.
Discover the fastest path to secure, trustworthy AI with a live demo of Varonis Atlas. Visit booth N-5457 to see how one platform helps you:
VISIT US IN THE EXPO
Apply real-time guardrails to stop risky AI behavior automatically
Test AI systems for prompt injection and unsafe data exposure
Get full visibility into cloud AI, code-based AI, and shadow AI
FREE EXPO PASS WITH THE VARONIS CODE: 52E1320XP
LIVE SESSIONS
SESSION
FROM PROMPTS TO PERMISSIONS: THE NEW DATA RISK MODEL FOR AI
AI assistants and agents change how data is accessed, inferred, and exposed. New attack techniques exploit prompts, retrieved content, and permissions inside trusted systems, bypassing traditional controls. This session will examine emerging AI-driven data risks, why discovery alone isn’t enough, and how security teams can apply controls that scale with AI adoption.
TUESDAY, MARCH 24 | 8:30 AM
MOSCONE SOUTH ESPLANADE 153
BRIAN VECCI
FIELD CTO
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
BRIAN VECCI
FIELD CTO
Join Varonis, KPMG, and Microsoft for a high-energy evening of networking, bowling, and bites at Lucky Strike during Microsoft Ignite. Whether you’re looking to unwind after a day of sessions or spark new partnerships, this is your chance to connect with industry leaders and peers in a fun, relaxed setting. Expect great conversations, friendly competition, and a few surprises along the way!
*Must be registered to attend and don’t forget your badge!
STRIKE UP CONNECTIONS WITH VARONIS, KPMG & MICROSOFT
LUCKY STRIKE BOWLING ALLEY
200 KING ST, SAN FRANCISCO, CA 94107
NOVEMBER 19 | 7:00 P.M. – 9:00 P.M.
SESSION
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
Discover how an enterprise organization is decreasing AI risks while threats, data, and agents continue to increase. One essential element to powering secure Copilot use at scale is accurate and automated classification and labeling. Learn how security teams are effortlessly improving data protections for petabytes and hundreds of resources while reducing their workload.
DATA PROTECTION AND AI:
AN INTERSECTION BETWEEN TRADITIONAL AND NEW SECURITY THINKING
TUESDAY, MARCH 24 | 11:00 AM
PWC
VIMAL NAVIS
PRINCIPAL, CYBER, DATA AND TECH RISK, PWC
CLIFF EMBRY
SECURITY ARCHITECT TEAM LEAD
SESSION
BRIAN VECCI
FIELD CTO
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
AI assistants know your files, schedule, location and conversations – and they'll happily leak it all to an attacker. Discovered by Varonis Threat Labs, Reprompt is a novel attack chain against AI that turns a single click on a legitimate-looking URL into a persistent, stealthy data exfiltration pipeline – no plugins, no user interaction, no re-authentication required. Join us as we demo the full kill chain live and discuss what this means for the trust model underpinning AI assistants everywhere.
REPROMPT: ONE CLICK TO SILENTLY EXFILTRATE EVERYTHING YOUR AI KNOWS ABOUT YOU
THURSDAY, MARCH 26 | 12:30 PM
CLOUD VILLAGE
DOR YARDENI
DIRECTOR OF SECURITY RESEARCH
MARK VAITSMAN
SECURITY RESEARCH TEAM LEAD
KEYNOTE
ROB SOBERS
CMO
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
AI isn't just accelerating cyberattacks, it's breaking the security model built to control it. In this session, Yaki Faitelson shares real stories from the frontlines that reveal three major ways AI is reshaping enterprise security in real time. From novel AI vulnerabilities to weaponizing trust, we’ll deep dive into techniques and frameworks to help future-proof your AI and data security programs.
KEYNOTE: ROBOTS VS. ROBOTS –STORIES FROM THE FRONTLINES OF THE AGENTIC REVOLUTION
WEDNESDAY, MARCH 25 | 11:05 AM
RSAC MAIN STAGE
YAKI FAITELSON
CEO
© 2026 Varonis
© 2026 Varonis
Join us for a rare, after-hours experience inside San Francisco’s most
historic bank.
Caviar. Oysters. Jamón Ibérico. Live art. A touch of good fortune. Transportation will be provided.
*Spots are limited to Varonis customers — an RSVP is required to attend.
VARONIS SOCIETY
THE BANK AT AMADOR
25 LUSK ST., SAN FRANCISCO, CA 94107
MARCH 24 | 6:00 P.M. – 10:00 P.M.
Kick off the RSA Conference with tasty drinks, bites, and hear from your favorite Axios reporters at our exclusive event.
*Space is limited. Please register and we’ll confirm your spot.
VARONIS + AXIOS
THE CONSERVATORY AT ONE SANSOME
ONE SANSOME ST., SAN FRANCISCO, CA 94104
MARCH 23 | 4:00 P.M. – 6:00 P.M.
Join Varonis at 25 Lusk as we kick off Microsoft Ignite with an intimate reception on Monday, November 17. This will be an exclusive evening designed for meaningful peer conversations, dining experiences, and exceptional company!
Spots are limited — request yours today!
JOIN US FOR AN UNFORGETTABLE EVENING
25 LUSK
25 LUSK ST, SAN FRANCISCO, CA 94107
NOVEMBER 17 | 6:00 P.M. – 9:00 P.M.
Start your day at RSAC 2026 with an Open Cybersecurity Schema Framework breakfast event designed to spark insight and conversation. Connect with industry leaders as they share the latest OCSF updates, real-world implementations, and impactful deployments driving the next era of cybersecurity.
AWS-LED OCSF BREAKFAST AT RSAC 2026
INTERCONTINENTAL SAN FRANCISCO
888 HOWARD ST.
SAN FRANCISCO, CA 94103
MARCH 25 | 7:30 A.M. – 10:00 A.M.
Varonis Interceptor is on a mission to stop real AI-phishing threats. Watch real attacks unfold and see how Varonis Interceptor detects and stops them. Plus, take home your Lego Spaceship.
INTERCEPTOR LAB
MOSCONE CENTER
SR201 ESPLANADE BALLROOM | MOSCONE S
EVERY AFTERNOON | 2:00 PM – 4:00 PM
Kick off the RSA Conference with tasty drinks, bites, and hear from your favorite Axios reporters at our exclusive event.
*Space is limited. Please register and we’ll confirm your spot.
VARONIS + AXIOS
THE CONSERVATORY AT ONE SANSOME
ONE SANSOME ST.
SAN FRANCISCO, CA 94104
MARCH 23 | 4:00 P.M. - 6:00 P.M
Don’t miss this exclusive chance to connect with top cybersecurity leaders, celebrate innovation, and kick off the week with momentum. Space is limited – register today.
GUIDEPOINT SPONSOR:
RSAC PARTY
THE GRAND
520 4TH ST.
SAN FRANCISCO, CA
MARCH 23 | 6:30 P.M. - 9:00 P.M
ENCLAVE IN ACTION:
A REAL‑WORLD LOOK AT PROTECTING YOUR DATA
SESSION
TUESDAY, MARCH 24 | 2:00 PM
BOOZ ALLEN HAMILTON
SESSION
FROM PROMPTS TO PERMISSIONS: THE NEW DATA RISK MODEL FOR AI
TBD
TUESDAY, MARCH 24 | 8:30 AM
AI assistants and agents change how data is accessed, inferred, and exposed. New attack techniques exploit prompts, retrieved content, and permissions inside trusted systems, bypassing traditional controls. This session will examine emerging AI-driven data risks, why discovery alone isn’t enough, and how security teams can apply controls that scale with AI adoption.
ROB SOBERS
CMO
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
VIMAL NAVIS
PRINCIPAL, CYBER, DATA AND TECH RISK, PWC
JASON MADIGAN
DIRECTOR COMMERCIAL CLOUD SECURITY, BOOZ ALLEN HAMILTON
SESSION
DATA PROTECTION AND AI, AN INTERSECTION BETWEEN TRADITIONAL AND NEW SECURITY THINKING
PWC
TUESDAY, MARCH 24 | 11:00 AM
SESSION
BRIAN VECCI
FIELD CTO
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
In the ever-evolving cyberthreat space, more and more attackers, including famous APT’s such as ScatteredSpider(UNC3944) & ShinyHunters(UNC6040), are setting their sights on Salesforce. From Community Sites to OAuth apps, SOQL injection to shadow admin, and even insiders stealing data, this session will explore five attack techniques, including a novel one, and show how to detect and prevent.
ENCLAVE IN ACTION:
A REAL WORLD LOOK AT PROTECTING YOUR DATA
TUESDAY, MARCH 24 | 2:00 PM
BOOZ ALLEN HAMILTON
JASON MADIGAN
DIRECTOR COMMERCIAL CLOUD SECURITY, BOOZ ALLEN HAMILTON
Start your day at RSAC 2026 with an Open Cybersecurity Schema Framework breakfast event designed to spark insight and conversation. Connect with industry leaders as they share the latest OCSF updates, real-world implementations, and impactful deployments driving the next era
of cybersecurity.
AWS-LED OCSF BREAKFAST AT RSAC 2026
INTERCONTINENTAL SAN FRANCISCO
888 HOWARD ST., SAN FRANCISCO, CA 94103
MARCH 25 | 7:30 A.M. – 10:00 A.M.
Join us for a rare, after-hours experience inside San Francisco’s most historic bank.
Caviar. Oysters. Jamón Ibérico. Live art. A touch of good fortune.
Transportation will be provided.
*Spots are limited to Varonis customers — an RSVP is required to attend.
VARONIS
SOCIETY
THE BANK AT AMADOR
550 MONTGOMERY ST.
SAN FRANCISCO, CA 94111
MARCH 24 | 6:00 P.M. - 10:00 P.M
Don’t miss this exclusive chance to connect with top cybersecurity leaders, celebrate innovation, and kick off the week with momentum. Space is limited – register today.
GUIDEPOINT SPONSOR: RSAC PARTY
THE GRAND
520 4TH ST., SAN FRANCISCO, CA
MARCH 23 | 6:30 P.M. – 9:00 P.M.
Enjoy arcade games, live band, and a night to remember at the Optiv RSAC After Party!
OPTIV AFTER PARTY
AUGUST HALL
420 MASON ST., SAN FRANCISCO, CA 94102
MARCH 25 | 7:00 P.M. – 10:00 P.M.
Enjoy arcade games, live band, and a night to remember at the Optiv RSAC After Party!
OPTIV AFTER PARTY
AUGUST HALL
420 MASON ST.,
SAN FRANCISCO, CA 94102
MARCH 25 | 7:00 P.M. - 10:00 P.M
REPROMPT: ONE CLICK TO SILENTLY EXFILTRATE EVERYTHING YOUR AI KNOWS ABOUT YOU
AI assistants know your files, schedule, location and conversations – and they'll happily leak it all to an attacker. Discovered by Varonis Threat Labs, Reprompt is a novel attack chain against AI that turns a single click on a legitimate-looking URL into a persistent, stealthy data exfiltration pipeline – no plugins, no user interaction, no re-authentication required. Join us as we demo the full kill chain live and discuss what this means for the trust model underpinning AI assistants everywhere.
SESSION
THURSDAY, MARCH 26 | 12:30 PM
CLOUD VILLAGE
SESSION
SCALING IDENTITY THREAT DETECTION WITH ML AND LLMS
VARONIS BOOTH N-5457
MONDAY, MARCH 23 | 6:00 PM
Most modern attackers don’t break in; they log in. And that shift has pushed traditional identity detection to its limits. In this session, we’ll share how we tackled that problem in the real world, moving from theory to production with a scalable, unsupervised ML approach to identity threat detection. If you’re wrestling with identity attacks that blend in as “normal,” this session will give you proven strategies for detecting them at scale.
ROB SOBERS
CMO
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
BRIAN VECCI
FIELD CTO
DOR YARDENI
DIRECTOR OF SECURITY RESEARCH
DOR YARDENI
DIRECTOR OF SECURITY RESEARCH
MARK VAITSMAN
SECURITY RESEARCH TEAM LEAD
SESSION
BRIAN VECCI
FIELD CTO
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
In the ever-evolving cyberthreat space, more and more attackers, including famous APT’s such as ScatteredSpider(UNC3944) & ShinyHunters(UNC6040), are setting their sights on Salesforce. From Community Sites to OAuth apps, SOQL injection to shadow admin, and even insiders stealing data, this session will explore five attack techniques, including a novel one, and show how to detect and help secure your workloads.
MAY THE FORCE BE WITH YOU:
5 SALESFORCE ATTACKS & HOW TO STOP THEM
MONDAY, MARCH 23 | 2:20 PM
MOSCONE WEST 2018
TAMIR YEHUDA
CLOUD SECURITY RESEARCH TEAM LEAD
DANIEL REYHANIAN
CLOUD SECURITY RESEARCHER
SESSION
INSIDE A DB HONEYPOT: LESSONS FROM REAL-WORLD RANSOMWARE ATTACKS
Examine real attacker behavior through a managed database honeypot deployed in cloud environments. By analyzing live ransomware-driven intrusions against intentionally misconfigured Cloud SQL instances, we'll highlight how attackers discover, compromise, and impact managed databases and what these attacks reveal about common security blind spots and detection gaps.
WEDNESDAY, MARCH 25 | 11:00 AM
VARONIS BOOTH N-5457
BRIAN VECCI
FIELD CTO
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
YOGEV MADAR
DIRECTOR OF SECURITY RESEARCH
SESSION
SCALING IDENTITY THREAT DETECTION WITH ML AND LLMS
Most modern attackers don’t break in; they log in. And that shift has pushed traditional identity detection to its limits. In this session, we’ll share how we tackled that problem in the real world, moving from theory to production with a scalable, unsupervised ML approach to identity threat detection. If you’re wrestling with identity attacks that blend in as “normal,” this session will give you proven strategies for detecting them at scale.
MONDAY, MARCH 23 | 6:00 PM
VARONIS BOOTH N-5457
BRIAN VECCI
FIELD CTO
CLIFF EBERY
SECURITY ARCHITECT TEAM LEAD
DAN HOLLAND
DEPUTY CISO @ TAMPA GENERAL HOSPITAL
DOR YARDENI
DIRECTOR OF SECURITY RESEARCH