The Conference Circuit: Are We Getting Lost in Our Own Industry?
I’m heading to DEF CON in a few days. Every year I go through the same ritual: pack the badge-grabbing gear, mentally prepare for the crowds, and ask myself the same question I’ve been asking for years: is this still worth it?
The cybersecurity conference circuit has become a massive, multibillion-dollar ecosystem. RSA Conference draws upwards of 40,000 attendees annually to San Francisco’s Moscone Center. Black Hat fills the Las Vegas Convention Center with practitioners, researchers, vendors, and everyone in between. DEF CON, which started as a scrappy gathering of hackers in a hotel room, now pulls tens of thousands of people to the Las Vegas Strip every summer.
These are impressive numbers. They’re also, depending on who you ask, part of the problem.
When Bigger Isn’t Better
There’s an irony baked into the growth of the major security conferences. The whole point of gathering is connection: sharing knowledge, learning from peers, staying sharp in a field that moves faster than almost any other. But when you’re navigating a conference floor the size of an aircraft hangar, weaving through a sea of branded tote bags and competing booth pitches, genuine connection gets harder, not easier.
RSA has, in many ways, become a trade show first and a security conference second. The expo floor is a masterclass in enterprise marketing: massive booth structures, swag so abundant it fills checked luggage on the flight home, and a vendor-to-practitioner ratio that sometimes feels inverted. That’s not a knock on RSA entirely; there are genuinely excellent talks and meaningful conversations to be had there. But you have to work to find them beneath the noise.
Black Hat sits in an interesting middle ground. The Briefings track still delivers some of the most technically rigorous research you’ll find anywhere, and the Business Hall has grown into its own RSA-esque spectacle. The conference has managed to preserve a research credibility that keeps serious practitioners coming back, but it too has grown in ways that can feel overwhelming to navigate.
And DEF CON, my destination this week, is not immune. The “family reunion of the hacker community” has scaled dramatically. Villages have proliferated (which is genuinely great, more on that in a moment), but the badge lines, the crush of bodies in the Caesars Forum, and the sheer density of everything happening simultaneously can leave you feeling like you missed the conference you actually came to attend.
The Lobbycon Phenomenon
Here’s the thing that keeps experienced practitioners coming back to the big shows despite all of the above: Lobbycon.
If you’ve been in this industry long enough, you know exactly what I mean. It’s the conversations that happen in hallways, hotel lobbies, bars at 2am, and impromptu gatherings outside the official program. It’s running into the researcher you’ve been meaning to talk to for two years. It’s an unplanned conversation with a former colleague that turns into a two-hour deep dive on something you’ve both been wrestling with independently.
The talks are often the excuse to gather, not the reason. The real currency of the big conferences is the density of high-caliber people in one place at one time, and the informal access that creates.
That’s real and it has genuine value. But I’d also push back on it a little: if Lobbycon is the main reason you’re there, you’re paying thousands of dollars in registration, flights, and hotels for the privilege of hanging out in a lobby. There’s got to be a more efficient way to do this.
The BSides Ecosystem: A Different Animal
While the flagship conferences have been scaling up, the BSides movement has been quietly doing something different. Started in 2009 when talks rejected from RSA were organized into their own event, BSides conferences have multiplied into hundreds of regional events worldwide: BSides Las Vegas, BSides London, BSides Charm, BSides SATX, and countless others.
BSides events tend to be smaller, cheaper (often free), and significantly more technical. The speaker selection skews toward practitioners doing real work rather than polished vendor presentations. The audience is engaged and knowledgeable. There’s less swag, less noise, and more signal.
For people early in their careers or making a transition into security, BSides events can be transformative. The accessibility is unmatched; you can walk up to a speaker after their talk and have a real conversation. The community atmosphere is genuine. And the technical content often punches well above the weight of conferences that cost ten times as much to attend.
But there’s a ceiling, and I think it’s worth acknowledging. For journeyman and senior practitioners, people who’ve been in the trenches for a decade or more, who have deep specializations, who are looking for peers at their level rather than foundational education, BSides can sometimes feel like it’s not quite calibrated to where they are. That’s not criticism; it’s a feature. BSides is doing exactly what it’s supposed to do.
The question is: what’s the equivalent for the experienced end of the spectrum?
Where Are the Senior Practitioners Actually Going?
This is the conversation I keep having with colleagues, and I don’t think there’s one clean answer yet. But a few patterns have emerged.
Smaller, curated invite-only events have proliferated quietly. These don’t show up with big marketing budgets or flashy websites because they don’t need to. Attendance is limited, topics are specific, and the assumption is that everyone in the room is already operating at a high level. If you’re not already in those networks, getting there is mostly a function of time, reputation, and relationships, which is either a feature or a bug depending on your perspective.
The village model at DEF CON is worth highlighting here as a genuine bright spot within the chaos of a large conference. The ICS Village, the Adversarial ML Village, the AppSec Village, the Policy Village: these function almost as mini-conferences within the larger event, with focused content and communities that actually talk to each other. They’re one of the better innovations in how large conferences have tried to solve the problem of scale.
Industry working groups and ISACs (Information Sharing and Analysis Centers) have become an underappreciated venue for senior-level knowledge exchange. The collaboration that happens in sector-specific security communities is often more directly applicable, and more candid, than anything you’ll find at a public conference.
Practitioner-focused events like SANS summits, certain USENIX tracks, and purpose-built gatherings around specific disciplines (red teaming, threat intelligence, ICS/OT security) tend to draw a more experienced, more focused crowd precisely because they’re not trying to be everything to everyone.
A Conference Worth Attending Is One with a Clear Purpose
I think the honest conclusion I keep arriving at is this: the era of the single conference that serves everyone is over, if it ever really existed. The industry has fragmented and specialized in ways that the big shows simply can’t keep up with.
That doesn’t mean RSA, Black Hat, or DEF CON have no value. They clearly do. But the value proposition is different depending on who you are and what you’re looking for.
- If you’re early in your career, the big conferences offer exposure and the BSides circuit offers depth.
- If you’re mid-career, BSides and specialized events offer the best return on your time investment.
- If you’re a senior practitioner, the ROI calculation increasingly favors smaller, curated gatherings, and being selective about which of the major conferences you invest in and why.
As for me, I’m still going to DEF CON. I’m looking forward to a few specific villages, a handful of talks I’ve already flagged, and honestly, yeah, the Lobbycon conversations that will happen in some hotel bar on Saturday night.
But I’m going in with clear expectations. And I think that’s the move: go with a purpose, find your people within the crowd, and don’t try to attend everything. The conference isn’t the point. The community is.
See you in Vegas.
Have a take on where the best knowledge exchange in security is happening right now? I’d genuinely love to hear it.
By: Adam John

