Abhijith B R moderated a panel with Ken Kato, Vivek Ramachandran, and Jonathan Baker at RSAC 2025 to review the biggest breaches of 2024 and discuss strategies for strengthening incident response, containment, and defense against sophisticated adversaries. RSA Conference 2025
Our founder, Abhijith B R, moderated this panel at RSA Conference 2025 in San Francisco on 30 April 2025, bringing together three practitioners who each look at sophisticated adversaries from a different angle.
Jonathan Baker co-founded and led MITRE Engenuity's Center for Threat-Informed Defense, the research hub behind much of the community's work on ATT&CK-driven defense. Vivek Ramachandran, founder and CEO of SquareX and a long-time offensive security researcher, brought the browser- and endpoint-attack perspective. Ken Kato, Chief Security Officer at Kindo and a former White House Presidential Innovation Fellow, added the view from defending critical government and enterprise systems. Together with Abhijith, they walked through the biggest breaches of 2024 and what they tell us about where defenses keep falling short.
The conversation centered on a hard truth: even with advanced tooling, no organization is immune. The panel reviewed the year's most significant incidents, the recurring gaps that let them succeed, and concrete strategies for strengthening incident response, containment, and resilience against ransomware and state-sponsored threat actors.
The session ran on the RSAC Sandbox stage at Adversary Village, the community Abhijith founded and was also hosting at RSAC 2025, with a full program of talks, live demos, gamified table-top exercises, adversary and ransomware simulators, guided breach simulation, and hands-on activities.
Cyber attacks ranging from sophisticated ransomware to state-sponsored breaches have targeted critical infrastructure and major organizations, driving escalation in security efforts. Despite advanced tools, no organization is immune to adversaries. This panel will review the key breaches of 2024, discuss ongoing issues, and strategies for improving incident response, containment, and defense. RSAC 2025 session abstract




BreachSimRange runs red teaming, threat-led breach and adversary simulation that mirror how modern threat actors operate, so you find the gaps before they do.
Talk to us about Consulting