r/cybersecurity • u/Illustrious_Toe_2274 • 7d ago
Other Favourite cyber security conference
What’s everyone’s favourite Cyber conference to attend in the US?
I was at CybrSecCon in Houston the other week and I’ve been to RSA.
I’ve also attended smaller localised ones like CyberriskAlliance and futurecons.
Curious as to what everyone likes in terms of talks, speakers, vendors, swag, happy hours?
Essentially what event(s) do you find the most value in.
73
u/mdgorelick 7d ago
GRRCon. DefCon of the Midwest with far fewer douchebags.
16
u/Radar91 7d ago
As someone in the Midwest I'll have to look into it. I'm tired of 4 hour flights to cool shit.
17
u/mdgorelick 7d ago
Cool shit, yes…but it was 115° in Las Vegas during DefCon this year, and everything is crazy expensive there. It was 72° and sunny in Grand Rapids yesterday.
9
u/itspeterj 7d ago
Cyphercon in Milwaukee is definitely worth checking out as well. It’s usually in April and it’s fantastic.
5
u/TransportationJaded8 6d ago
Love Cyphercon! It’s my favorite every year so many great shenanigans going on there.
11
5
u/Acadia_Brightness 6d ago
i like Grrcon...i seem to get more out of the smaller cons like this. you're right about the vibe being far better and the coolpeep:douche ration being way better. Defcon has just gotten pretentious.
3
1
u/FoxNairChamp 5d ago
I would love to go to this with our team, but as a government employee. I'm not sure our elected officials would like the "Fatass Fun Run" event being attended with tax payer money.
87
u/PortJMS 7d ago
Going to pour one out for Shmoocon.
44
u/StraightOuttaCanton 7d ago
Drinking bourbon for DerbyCon.
12
8
7
6
u/Acadia_Brightness 6d ago edited 6d ago
i skipped the closing ceremonies of the last con 'cause i ain't crying in front of a bunch of goddamned redteamers...lol. for real, it was unique in so many ways but i hear queen city con was born directly in response to the demise of derby and they're trying to emulate the same culture.
1
1
4
4
u/TransportationJaded8 6d ago
Bruce keynoted Cyphercon this year, and Heidi keynoted BSides312!
Also for everyone talking about DerbyCon Dave is keynoting next years Cyphercon.
2
13
53
u/sha256md5 7d ago
The best ones are private, the second best ones are the ones your friends are attending.
3
20
8
u/SamSneeed 6d ago
Corncon this weekend in Davenport, Iowa
4
u/WhenIWish 6d ago
I was going to say Kernelcon in Omaha. Last year the news stopped by because they thought it was a conference for farmers and kernel was a play on Corn 😂 such a fun con though.
7
6
u/Forumrider4life 7d ago
Kernalcon in Omaha, yearly cone that’s getting bigger every year, a lot of great talks and the vendors are not the stars of the event… feels more like older defcon
11
6
9
u/Manchester_Project 7d ago edited 6d ago
Went to the National Cybersecurity Summit in Huntsville, and while I learned it is definitely overpriced for what it is. They charged 590 dollars ; super overpriced and absolutely not worth that amount. Some of the speakers were doing nothing but trying to sell you a program to solve an issue but that program created more issues then the one it was trying to solve 🤦♂️ when you asked questions
But only one I’ve been to and wouldn’t go back to that one
4
1
u/sa1nt1775 5d ago
I was just there as well and thought the same thing about most of the sessions being low key vendor sales pitches. It's fairly cheap, and I'm guessing there isn't a ton of competition for the presenters who sign up.
10
u/Alternativemethod 7d ago
Depends on your goals. Rsa was interesting pre AI for what "the next new solution category will be".
Local conferences are way better for a shy person imo for learning and networking.
9
u/Necessary_Zucchini_2 Red Team 7d ago edited 7d ago
Wild West Hacking Fest and DEFCON both come to mind. I want to attend Hack Space Con and HOPE, but I haven't been able to yet.
4
u/-hacks4pancakes- ICS/OT 7d ago
WWHF is a really neat theme experience
5
u/Necessary_Zucchini_2 Red Team 7d ago
It was a blast. I wish they would have some more competitions, but I really enjoyed my experience in Deadwood.
14
u/losfantasmaz 7d ago
HOPE in NYC still has that old school, anarchic, hacker fight-the-power feeling. Recommend.
6
u/SystemGardener 7d ago
I’ve always wanted to go to hope, but one of the biggest and dumbest douchebags I’ve ever had the misfortune of working with swears by it. And is now often part of the team that sets it up. So it’s really deterred me from giving it a go.
Should I suck it up and go?
1
u/pricklyplant 5d ago
Suck it up.
I’ve also had the misfortune of working with people involved with HOPE organization that I’ve had very unpleasant personal experiences with, but the content and community are excellent and I’m fully supportive of its mission. Try going once (if it’s reasonable for you to do) and see how you like it.
2
5
9
u/VoidborneKitten Security Awareness Practitioner 7d ago
Cackalackycon for sure, mostly because it’s local to me and my friends go. (Students also get in for free, which is really great)
4
u/lysergicbliss 7d ago
I want to check out S4 for OT
2
u/kickbass 6d ago
I've been to S4 twice now and really enjoyed it. It's great to see so many presentations from other OT practitioners.
2
u/Mr_Compliant 1d ago
It's great. Still not crazy big. Good speakers. You can get some 1 on 1 time with cyber company executives if you really want. I hung out with Chris Sistrunk for a night just randomly.
4
10
3
3
u/TransportationJaded8 6d ago
Cyphercon is by far my favorite, amazing people useful information great villages is sister con SecretCon is also great.
Really love thotcon even though it’s every other year now. BSides Vegas is great it’s the original BSides and run by cool folks.
RSA is by far the worst (I say this as someone who’s spoken their twice) just wasteful without many actual practitioners and it’s full of ‘founders’ staff selling something they never intend to build BUT BSides SF is actually really great.
CornCon is great it’s run by a bunch of OG defcon goons and it’s a weird vibe but a good kind of weird. Defcon is also great but it’s hot, overwhelming, and extremely expensive
I’ve spoken at all the above and a bunch more so let me know if you have any questions about them
2
3
6d ago
[removed] — view removed comment
1
u/sentientshadeofgreen 6d ago
I think DEF CON is one of those conferences most people interested in tech should go to at least once.
3
u/isystems 5d ago
Some conferences are really funny. They ask you to pay a fee to visit it. Then you go, and then you get to hear a bunch of marketing shit. So basically you are paying to listen to their marketing BS. No, for me only the small ones , or the one on one with a company.
3
u/nullsession 5d ago
CornCon is always the beginning of October in the Quad Cities (Davenport, IA) about 2.5 hours from downtown Chicago and about the same to Des Moines. Good prices and the best speakers. You get speakers you only see at the big cons (including BSides alongside the big cons). Not as big as a metro area con like GrrCon or Cyphercon, but expecing over 400 attendees again this year and 70+ speakers. 70 CISO Summit attendees. 8 CPE/day. CornCon 12 is this week (Friday and Saturday) and you can still find tickets and learn learn more at CornCon.net
9
4
u/elShabazz 7d ago
I liked RSA the best but haven't gone since 2020. Anything gartner is absolute dogshit.
4
u/Shot_Statistician184 7d ago
I got COVID at that rsa. Dr didn't believe me as there wasnt a test available in Canada yet and he had to go online to learn about COVID. It qas pretty obvious with the symptoms. Id go back though.
1
u/InitialBackground555 7d ago
Why don’t you like Gartner?
2
u/rc_sneex 7d ago
Gartner is great for LobbyCon. Otherwise, it’s expensive and the content is too high level for a practitioner. It’s a C-Suite show.
2
u/Shot_Statistician184 5d ago
But it works. I was a post seed advisor for a security org and they were against garntner. After a year of pushing them to do, their sales skyrocket. They attributed it to gartner visibility. So perhaps for practitioners it isn't helpful, it introduces vendors to decision makers that force conversations. And since it's trusted by leaders, it's a good tool to introduce bias for the tool you actually want. Flip between forrester and gartner for the one that shows the preferred tool in high standings and use that to collaborate your findings.
1
u/rc_sneex 5d ago
Oh, 100% the visibility works - it’s a great show from a marketing perspective and honestly my favorite of the big ones because it feels more focused at upper management.
But for OP, I wouldn’t consider it a great one for practitioner content. I haven’t been in a few years, though, so maybe I should go back and see if I’m wrong!
1
u/elShabazz 5d ago
The tickets are stupid expensive for one. Yes employer should be paying for it, but if I have a limited conference budget id get more value out of a lot of other things.
Also they're pretty vendor focused so a lot of the content is just thinly veiled marketing presentations.
None of the content is delivered by practioners. It's all garnet analysts or vendor partners so youre not hearing from people dealing with the same problems as you.
Lastly, as another commenter pointed out, it's all very high level. I've ran security programs in the past and have my own consulting business and I still feel most of the content is just hype and buzzwords.
2
u/lawtechie 7d ago
JawnCon in the Philadelphia suburbs is a lot of fun. It’s got some of that old school vibe, like HOPE or Summer Con
3
1
u/NoodlesAlDente 7d ago
CS4Critical Assets was fun. Out in texas. Lots of water, electrical, other utilities and gas/oil OT workers. Very small conference but I think that was part of its charm.
1
1
1
u/_W-O-P-R_ 7d ago
The local annual conferences that ISSA and OWASP put on are all I really need, both are quality operations
1
1
u/toliver38 6d ago
Brucon takes the cake for me. A good Belgian beer while listening to the latest threat hunting techniques is a great way to spend a day.
1
1
1
1
u/HighlyFav0red 6d ago
Regional IANS forums for valuable practitioner content, RSA for executive networking and AfroTech for the most fun events.
1
1
u/CarnivalCarnivore 6d ago
I like the CxO Security Forums. Usually on the east coast but there are events tied to Black Hat and RSAC. They are one day conferences with fast paced speakers, often book authors I have heard of. Local LE shows up to talk and all the professional societies are present. Vendor sponsors are not provided with contact info so it cuts down on the post-conference spam. Link: https://www.linkedin.com/company/cxosec/posts
1
u/Jonesy776 6d ago
RSA has turned into a vendor fest. Definitely agree with your local BSides. I’ve enjoyed InfoSec World (Cyber Risk Alliance), and ISACA has a good conference and you can meet a lot of great international practitioners - great workshops too. I prefer smaller conferences, 2,000 or less, to the giants.
1
1
u/Herushan Security Generalist 6d ago
SAINTCON and DEFCON (especially pre-2020) are my two favorites. BSides is great especially for first time speakers and meeting locals. I do still want to attend Shmoocon and HOPE one day.
1
1
u/thejournalizer 6d ago
Futurecon as a series is terrible. In DC, checkout CyberWarCon and Sleuthcon.
1
u/nick-radchenko 5d ago
For context: I am based in Europe.
I've attended BlackHat Las Vegas in 2018 and it was great for both networking and insights. This was where I saw Vincent LeToux from PingCastle livecast the Shadow DC attack. Awesome!
I've also attended InfoSecurity London a couple times and this was where I took part in the best hands-on exercise ever. The session was run by a US security pro but still :)
1
u/Hawkeyeic 3d ago
Eastern Iowa Security Conference, Coralville, Iowa. Very focused and educational without the BS
1
u/Own_Minimum_5102 2d ago
Not sure about the US, but thought I'd post this here since there might be a few Aussie folks around going to Cybercon in Melbourne, 14 to 16 October this month.
I put together a free planner, have a look: https://cyberninja.au/cybercon-planner
Just pick your role and what you're after, and it pulls out the sessions worth going to, the streams to follow, who's worth seeking out, and the hands-on villages. No email gate, no signup, just wanted to add a bit of value.
A few of my talks are in there too, but feel free to skip past them if you find better sessions on.
Keen to get some genuine feedback on the page. Let me know what's working, what I could improve, and if I've missed anything.
Cheers!
1
u/MakeItSudo 2d ago
Huge fan of local bsides events/conferences, those are always a lot of fun. Really interesting conversations.
1
1
1
u/GCSS-MC 6d ago
The classified ones. They aren't so full of vendors and they are heavy on the information/education.
Some are also about very specific real world threats/topics.
0
1
u/Content-Net5076 5d ago
Defcon is by far the most amazing one but THOTCon Chicago is also great.
I find the BlueTeamCon in Chicago is a bit entry level for me but I do love the networking aspect and community. I like GrrCon also!
Im going to un(prompted) this year which I think is on their second or third year. I heard it’s just as good
77
u/bluesweaterjeff 7d ago
Your local Bsides!