# Propuesta RSAC 2027 v2.0

**Fecha:** 18 de septiembre de 2026

**Estado:** borrador competitivo para revisión y reescritura final del autor. No debe enviarse sin comprobar nuevamente el formulario y sus límites.

## Decisión narrativa

La propuesta abre con un acierto de RSAC —enforcement de GDPR— y no con una crítica. Luego muestra que los aciertos pueden tener diferente valor informativo. RSAC queda tratado como interlocutor y caso de uso, no como blanco.

La experiencia profesional se presenta correctamente como motivación observada en años recientes. No se la convierte en evidencia retrospectiva ni se inventan casos de clientes.

## Session title — 66/75 caracteres

`When Cyber Predictions Are Right—and Still Wrong for Your Strategy`

## Abstract público — 387/400 caracteres

RSAC forecasts correctly anticipated consequential shifts such as GDPR enforcement—but not every hit is equally useful. We audited 120 explicit predictions from 36 conference sessions and found headline accuracy matched a trivial baseline. Through contrasting cases, attendees learn a five-field test for deciding which conference signals deserve investigation, budget, or policy action.

## Session detail privado — 2.457/2.500 caracteres

In recent years, repeated conversations with CISOs showed me how ideas heard at major cybersecurity conferences could become inputs to corporate strategy. I did not preserve those conversations as a dataset, so they motivate this research rather than support its empirical claims. The concern was that authority and confirmation bias could turn a memorable claim into a decision without testing its precision, evidence, or failure conditions.

This session begins with a success. In December 2018, the RSAC Advisory Board predicted that 2019 would focus heavily on GDPR enforcement and major regulatory actions. In January 2019, the CNIL fined Google EUR50 million. RSAC had identified a consequential shift. But what made that forecast useful—and would any prediction mentioning privacy deserve equal credit?

I built a frame of 189 sessions from Black Hat USA, Chaos Communication Congress, and Virus Bulletin. From 138 sessions with qualifying material, I extracted 120 explicit predictions from 36 sessions. Before searching for outcomes, each claim received a frozen population, outcome, horizon, indicator, thresholds, and evidence rule. RSAC is not in that denominator because its historical archive could not be reconstructed comparably; RSAC cases are labeled contrasts.

Among 89 resolvable predictions, 54 met their thresholds: 60.7%. Yet "label every prediction fulfilled" also scores 60.7%, and 31 claims remain indeterminate. Accuracy alone demonstrates neither calibration nor forecasting skill.

Contrasting cases expose why. RSAC anticipated the 2016 ransomware wave, but the same evidence did not establish its claim about ransomed medical devices. A 2018 RSAC forecast that AES-256 would avoid a practical break for one year was correct but had a high base rate. Another correctly identified that NIST would select a hash-based signature, but missed its deadline. Black Hat similarly anticipated AVX-512 hardware but missed its date, while a CCC prediction named the exact date of a referendum already scheduled.

Attendees leave with a five-field test—population, measurable outcome, magnitude, deadline, and resolution source—plus a baseline check. They classify a claim as thematic radar, a hypothesis worth investigating, or a decision-grade forecast, then apply the method to one-week, six-week, and six-month CISO decisions. A new pre-adjudication registry of RSAC's own 2026-2028 forecasts shows how the method works prospectively.

## Submitter comments — 375/400 caracteres

This independent research is public and reproducible. Its limits are explicit: a documentary sample of three venues, clustered observations, 31 indeterminate cases, and one coder. RSAC cases are contrasts, not part of the denominator. A new pre-adjudication registry of RSAC's 2026-2028 forecasts demonstrates prospective use without claiming results before deadlines expire.

## Tres takeaways verificables

1. Attendees can distinguish thematic radar, a research hypothesis, and a decision-grade forecast.
2. Attendees can apply a five-field test: population, measurable outcome, magnitude, deadline, and resolution source.
3. Attendees can compare a forecast with a trivial baseline before it influences budget, policy, or risk acceptance.

## Arco de 50 minutos

| Minutos | Contenido | Función |
|---:|---|---|
| 0–5 | GDPR: un acierto RSAC que sí importó | Abrir sin antagonizar y plantear la pregunta de valor |
| 5–11 | Motivación CISO y límites de la anécdota | Establecer relevancia sin convertir experiencia en datos |
| 11–18 | Corpus y congelación previa a desenlaces | Credibilidad metodológica |
| 18–25 | 54/89, 31 indeterminados y baseline 60,7% | Desarmar la cifra superficial |
| 25–34 | Ransomware, AES-256, NIST/SPHINCS+, AVX-512 y referéndum | Comparar tipos de acierto y fallo |
| 34–41 | Prueba de cinco campos + baseline | Entregar herramienta aplicable |
| 41–45 | Registro RSAC 2026–2028 | Mostrar uso prospectivo y relevancia directa |
| 45–50 | Preguntas | Cierre |

## Por qué esta versión es más competitiva

- Reconoce que RSAC produjo señales correctas antes de explicar sus límites.
- Declara con precisión que RSAC no pertenece al denominador histórico.
- Sustituye “accuracy was wrong” por una promesa ejecutiva: decidir cuándo un acierto sirve para estrategia.
- Añade una extensión prospectiva basada en el informe oficial de RSAC 2026–2028.
- Conserva números, casos y herramienta concreta dentro del detalle privado.

## Revisión humana obligatoria

- Federico debe reescribir expresiones que no usaría oralmente y confirmar que puede pronunciar el texto con naturalidad.
- El formulario oficial debe validar nuevamente límites y caracteres especiales; si no admite el guion largo, reemplazarlo por guion simple.
- No prometer resultados del registro 2026–2028 antes de sus vencimientos.
- Mantener “EUR50 million” si el campo no conserva el símbolo del euro.

## Fuentes del caso de apertura

- RSAC Advisory Board, predicciones 2019: https://www.rsaconference.com/library/blog/2019-and-beyond-the-expanded-rsac-advisory-board-weighs-in-on-whats-next
- CNIL, sanciones emitidas en 2019: https://www.cnil.fr/fr/node/446
