RSA Conference 2026: PQC Migration
The RSA Conference 2026 wrapped up on 1 May. With 41,000 attendees, 670 exhibitors and 480 sessions, anyone returning from DACH is bound to have sore legs, a stack of business cards – and, ideally, a roadmap for 2026. The top five themes filtering out of the noise: Post-Quantum Cryptography as a migration mandate, Detection-as-Code as the new standard, AI in the SOC workflow, vendor consolidation as a board-level question, and Identity Threat Detection as an unexpectedly urgent gap. These five will dominate DACH CISO agendas over the next twelve months.
04.05.2026
Key Takeaways
- PQC is a migration mandate, not a research topic: NIST FIPS 203/204/205 are final, BSI TR-02102-1 Post-Quantum guidance 2026 is live. Starting a crypto inventory in 2027 is already too late.
- Detection-as-Code has become the standard: Sigma rules, detection libraries with Git workflows and CI validation have replaced the classic correlation-rule editor in major vendor demos. When RFP-ing SIEM in 2026, ask for the detection repo, not the UI.
- Vendor consolidation is now a board-level question: DACH conglomerates average 47 security tools (Gartner Q1/2026). By 2028, 78 % of CISOs aim to consolidate to 25 or fewer. This will dominate Q-reviews in 2026/2027.
Related:LiteLLM CVE-2026-42208: SQL Injection in AI Proxy Infrastructure / EU AI Act High-Risk Deadline 2 August 2026
What’s truly new in 2026
What does RSA Conference 2026 signal? A 41,000-attendee, 670-exhibitor, 480-session trade show held annually in San Francisco since 1995. It’s less a launch pad than a sorting mechanism: features appearing on multiple booth stages simultaneously become de-facto standards within twelve months; anything confined to a single demo pod is hype. CISOs returning from DACH rank takeaways by frequency, not stagecraft.
The 2026 edition pivots from grand platform visions to operational realities. Vendor consolidation, identity-layer hardening and PQC migration aren’t buzzwords – they’re roadmap items with budgets and deadlines. Keynotes from Cisco, CrowdStrike and Wiz traded disruption rhetoric for architectural substance.
The CISO’s Five Homework Assignments in the DACH Region
First, start the Post-Quantum Cryptography migration. NIST FIPS 203, 204 and 205 are final; BSI has activated the first PQC recommendations in TR-02102-1. RSAC sessions on crypto inventories were packed to capacity. The assignment: conduct a crypto inventory across TLS, VPN, code-signing, hardware-security modules and identify which components must speak hybrid PQC by 2027 or 2028 and pure PQC from 2030 onward. Realistic migration window: 18–24 months for inventory and architecture adjustments.
Second, make Detection-as-Code mandatory for every SIEM. Major SIEM vendors (Splunk, Elastic, Sumo Logic, Microsoft Sentinel) revealed at RSAC that their detection content will live natively in Sigma or YAML repos by 2026, with Git workflows, pull requests and CI validation. The SOC operating model is shifting from UI-click operators to detection engineers. The assignment: adapt SOC skill profiles and tooling pipelines, or the detection backlog will run dry by 2027.
Third, AI in the SOC is no longer a demo – it’s workflow. Microsoft Security Copilot, Google Security AI, CrowdStrike Charlotte and IBM watsonx Cybersecurity are already visible in production bank SOCs. The operational reality: Tier-1 triage by AI with human override on escalation reduces mean time to resolution by 35–50 %. The assignment: tighten data hygiene and logging schemas, because the AI proxy layer is also an attack surface.
Fourth, vendor consolidation is now a board-level question. 47 tools per DACH group (Gartner Q1/2026), 78 % want to cut that to 25 or fewer. This isn’t an efficiency drive – it’s an operational intervention: fewer tools mean narrower skill spread, clearer data flows and stronger vendor trust per tool. The RSAC vendor hall showed platform consolidators (Palo Alto Networks Cortex, Microsoft Defender, CrowdStrike Falcon) far more visible than point solutions. The assignment: 90-day audit of the tool landscape with a clear list of candidates for retirement.
Fifth, Identity Threat Detection is the surprise gap. Multiple RSAC sessions backed with data that current EDR/XDR stacks only partially cover identity threats (token theft, session hijacking, OAuth phishing). Dedicated ITDR solutions (Authomize, Silverfort, CrowdStrike Identity Protection) occupied every second booth. The assignment: review the identity layer in the SOC stack and run gap analyses with the IAM team.
Migration Timeline: PQC and Detection-as-Code in the DACH CISO Plan
| Phase | PQC Migration | Detection-as-Code |
|---|---|---|
| Q2–Q3 2026 | Crypto inventory, vendor RFIs, PQC roadmap draft | Set up detection repository, begin Sigma migration |
| Q4 2026 | Architecture pilot with hybrid algorithms | Activate CI pipeline with detection validation |
| H1 2027 | TLS migration of critical workloads | Detection-engineer skill build-out in SOC complete |
| H2 2027 | Code-signing and HSM migration | Detection-coverage reporting to executive board |
| 2028+ | Crypto-agility as default in new architectures | Detection engineering in standard CISO reporting |
Sources: NIST FIPS 203/204/205 Final, BSI TR-02102-1 Post-Quantum Recommendations 2026, RSAC 2026 sessions on Detection-as-Code (Splunk, Microsoft, Elastic), proprietary research from two DACH Tier-1 bank CISO interviews, April 2026.
Two DACH CISO Voices from San Francisco
Two CISOs from major German banks shared their takeaways from the conference – verbatim quotes without names for compliance reasons.
“We came with three items on our list and are leaving with five. Identity Threat Detection wasn’t on the agenda – now it’s our top priority for Q3. We can cover the spread from our current budget because we’re saving six figures by consolidating our EDR stack.”
“For us, PQC isn’t 2030 – it’s 2027. Regulators have already flagged missing crypto inventories. What San Francisco clarified is that NIST FIPS 203 will be production-ready, not stuck in research limbo. That unlocks the budget.”
What’s Tipping: Honest Trade-Offs
Three friction points sit inside the five action items. First, vendor consolidation erodes trust: a two-platform stack has less resilience against vendor failures or supply-chain incidents than a point-tool mix. Teams that consolidate must rethink vendor diversity – think multi-region contracts or backup vendors for detection content. Second, Detection-as-Code demands engineering skills in the SOC that aren’t standard today. Expect three to six months of upskilling per analyst. Third, AI in the SOC cuts Tier-1 load but makes Tier-2 more complex: fewer routine triage tickets, more escalation analysis with murky causality.
The honest takeaway from the sessions: nobody has a complete 2026 plan; everyone runs roadmaps with assumptions. Teams that communicate transparently earn more board trust than those that deliver polished answers.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Which crypto components are most urgent in the PQC migration?
TLS termination at external endpoints and code-signing infrastructure sit at the top because their crypto provenance must remain auditable for years. VPN concentrators and HSMs follow, often with longer hardware lifecycles than planned. JWT signing in API gateways and qualified electronic signatures round out the critical list.
Is Detection-as-Code worth it for mid-sized SOCs (5 to 15 analysts)?
Yes – it accelerates onboarding of new detection content and enables versioning. For smaller teams, a single Sigma repo with GitHub Actions validation and manual deployment suffices. Typical build-and-maintain effort is 0.3 to 0.7 FTE in year one, then 0.2 FTE per 100 detection rules thereafter.
How many security tools are a realistic target after consolidation?
Gartner cites 25 as the median target state for DACH large enterprises by 2028. A realistic corridor: 30 to 35 tools for complex landscapes, 15 to 20 for mid-market firms. Below 10 becomes risky: too much vendor concentration and loss of best-of-breed advantages for niche use-cases.
Where does Identity Threat Detection fit into the existing SOC stack?
ITDR sits between IAM and SIEM. It consumes identity events (logins, token issuances, privilege escalations) from AD/Entra ID/Okta and correlates them with SIEM data. Implementation effort for a mid-sized setup: three to six months, with a focus on identity-event schema and token lifecycle analysis.
More from the MBF Media Network
cloudmagazinArchitecture Drives Compliance Costs: How to Cut ThemMyBusinessFutureRisk Shift: Playing It Safe Becomes 2026’s Costliest StrategyDigital ChiefsAI Governance 2026: System‑Level, Not Excel Compliance
Translated from the German original using artificial intelligence. The German version is authoritative.
Further reading
Security Tools at Events: Demo Check Instead of Slides
Security tools at events: scorecard before the hall, dismantle demo theater and only PoC in the shortlist. So stand conversations become purchasing.
IT Security Events 2026/2027: The DACH Calendar
Key IT security conferences and trade fairs in the DACH region from autumn 2026 to spring 2027: dates, locations, focus, and links at a …
it-sa 2026: The Roadmap for Security Decision-Makers
From October 27 to 29, 2026, the Nuremberg Exhibition Center will once again become the most important meeting point for the IT security industry …


