The 30-second version: the room is not sentimental about the big conferences. The recurring view is that the largest events have drifted toward sales while the value moved to smaller, more specific ones, and that the single best way to get to any of them is to submit a talk, because a speaker slot converts a personal expense into a business case. The most useful material here is not about which conference to pick. It is about how people afford to go, how they handle their own exposure once there, and one thing nobody schedules for.
Three ground rules for this page: no individual attendee is named, every claim links to the recap it came from, and opinions are labeled as opinions rather than promoted to facts.
On this page
Where this comes from
Cloud Security Office Hours is a free, open Zoom that runs every Friday. Practitioners drop in, someone asks a question, the room works through it, and every session gets a published recap. Conferences come up constantly: roughly fifty recaps carry a Conferences tag. Almost all of those are somebody mentioning they will be at an event. This page draws on the five where the subject was actually worked through, including a post-Black Hat debrief recorded days after the show floor closed.
This is not a survey and not a ranking. It is what people said to peers rather than to a camera. CSOH has no affiliation with any conference named here and takes no money from any of them, which is worth stating on a page where most published comparisons are written by someone selling a booth or a ticket.
Are the big ones still worth it?
The blunt assessment came in the December 5, 2025 session, and it was about RSA. Attendees described a shift where both vendors and buyers are increasingly skipping the event, which is a more serious signal than either one alone: a conference can survive buyers drifting away as long as sponsors keep paying, and it can survive sponsors leaving if the audience still shows. Both at once is a different problem. The word used was relevance.
The same session reported AWS re:Invent drawing only a few attendees from this group, and noted that re:Inforce, the security-specific event, was being folded into re:Invent the following year. Consolidating a security conference into a general cloud conference is the kind of decision that reads as efficiency from inside and as demotion from outside.
The August 7, 2026 session is the freshest data point, recorded days after Black Hat. Attendees who went reported a show floor slower than previous years, and made a prediction worth recording as a prediction: several companies that came out of stealth with expensive booths may not be around next year. That is a read on the funding cycle as much as on the conference.
Where the value went, according to the December session, is smaller and more specific: fwd:cloudsec and KubeCon were both named as producing more meaningful conversations than the large general events. Nobody argued the big conferences are worthless. The argument is that what they are good for has narrowed.
Black Hat, DEF CON, and what each is for
The April 3, 2026 session drew the clearest distinction. DEF CON was described as more inclusive and less corporate; Black Hat as offering more industry-relevant content but at a higher cost. That is not a ranking, it is a statement that they answer different questions, and the practical consequence is that "which conference should I go to" is the wrong question until you know whether you are buying content, access, or community.
The August 7, 2026 session supplied a worked example of the content problem. OpenAI presented at Black Hat on its response to model containment breaches, and an attendee who watched it came away unconvinced: the talk read as marketing in tone, and, more damningly for a security audience, offered no recommendations for preventing a recurrence. An incident response talk that does not tell you how to avoid the incident is a case study in why people stop paying for the show floor.
There is a third thing conferences are for, and it does not appear on any agenda. In the July 10, 2026 session, weeks ahead of the event, members were organising a CSOH breakfast at Black Hat and setting up a dedicated Signal group to coordinate meetups across Black Hat and DEF CON. For people who already have a community online, the conference is largely the excuse to be in one city at once, which is a different value proposition from either the talks or the show floor and is priced identically.
The same April session recorded a criticism that belongs here rather than being quietly dropped: an attendee noted the absence of a Black affinity group at an event that had Latino and LGBTQ groups, and was told the reason was a lack of space. It is reported as it was raised, one person's account of one event, but a community page about which conferences are worth attending should not silently omit who felt welcome at them.
How people actually get to go
This is the most useful thing in the archive on this subject, and it is almost never written down. The April 3, 2026 session worked through how attendees actually fund conference travel, and the answer was consistent: submit a talk.
The reasoning offered was that being selected as a speaker makes it far easier to justify attendance to an employer, because it reframes the trip as business development rather than personal networking. That is a budgeting argument, not an ego one, and it is the reason the advice generalises. One attendee described getting her employer to fund conference attendance precisely this way, across several events.
It also explains something about the conferences themselves. If speaking is the main route to a funded ticket, then who gets accepted to speak partly determines who is in the room, which is a quieter feedback loop than any diversity statement.
Speaking when you do not feel qualified
The April 3, 2026 session spent real time on this, prompted by a member preparing a talk and another worrying aloud about whether he should submit one at all. His stated concerns were a language barrier and not enough experience.
The room's response was unanimous in a way it rarely is. Speakers do not need to be polished or senior: passion and genuine expertise in the thing you are talking about matter more than formal credentials. On the language worry specifically, attendees were direct that an accent does not affect how a talk is received in this industry, and that experience level is not the filter he imagined it to be.
There was also a quieter kindness in that session worth preserving, because it is the opposite of how conference advice is usually written. Alongside the encouragement, the group told him plainly that he did not have to speak if he was not comfortable, and pointed at other routes to building a reputation. The advice was not "push through it". It was "you are qualified, and also this is optional".
The same session included a member workshopping an actual talk proposal in front of the group, on treating people as game pieces in security and the risk of single-dimensional thinking about roles. That is what the pipeline into speaking looks like in practice: an idea tested on peers before it ever reaches a review committee.
Your own operational security
The March 6, 2026 session covered the part of conference attendance that security people are oddly bad at applying to themselves. The practical advice given was to be careful what personal information you share at events, to know you can ask not to be recorded, and to weigh the risk against the benefit before speaking publicly rather than assuming either.
The concrete reason came from an attendee with a public profile in security, who described receiving targeted phishing attempts as a consequence of that visibility. Being known is a real attack surface, and the trade is worth making with open eyes rather than by accident.
Two fears got a more skeptical hearing. One attendee raised concerns about presenting at all, because recordings could be misused by AI, and the group generally did not share the worry. Another shared a self-deprecating story about arriving at DEF CON braced for something far more hostile than what he found, offered as an example of how the folklore around that event outruns the reality for newcomers.
That combination is the honest position: the ambient dread about hacker conferences is mostly overblown, and the specific, boring risk of being a recognisable name is real.
The thing nobody schedules for
The most operationally useful observation on this page is one sentence from the August 7, 2026 session: the group noted a possible pattern of supply chain attacks landing during major security conferences, when the people who would notice are away.
It is offered as a pattern the room had observed rather than as a measured finding, and it should be read that way. But the logic does not need statistics to be worth acting on. Conference weeks concentrate exactly the people who triage alerts, approve emergency changes, and recognise that something looks wrong, and they concentrate them in a different timezone with poor wifi and a full schedule. Whether or not attackers are deliberately timing to it, the defensive gap is real and entirely predictable from a calendar.
Nobody in the session proposed a fix, which is itself telling. The obvious ones (coverage rotas that account for conference season, a named owner who is not travelling, elevated alerting thresholds that week) are unglamorous enough that they tend not to get planned until after the first bad August.
Where the room disagrees
These are live disagreements, not strawmen. None of them were settled.
Is a quiet show floor a dying conference or a maturing one?
The August 7, 2026 and December 5, 2025 sessions both report the same symptoms, thinner floors and departing buyers, without settling what they mean. One reading is decline. The other is that the trade-show model is separating from the conference, and a security event whose sponsors are pulling back may simply be reverting to the thing practitioners said they wanted. Nobody in either session made that second argument explicitly, and it is offered here as the obvious counterpoint that did not come up.
Does presenting expose you?
The March 6, 2026 session split cleanly. One attendee's concern about recordings being misused by AI was largely dismissed by the room. In the same conversation, another attendee's account of targeted phishing that followed his public profile was accepted without argument. Both cannot be simply right: the group was skeptical of a speculative future harm and matter-of-fact about a demonstrated present one, which is defensible, but it does mean "is speaking risky" got answered two different ways within one session.
Is the value in the talks or the hallway?
Never stated as a disagreement, but the sessions pull in opposite directions. The April 3, 2026 session treats speaking and networking as the point, and the August 7 session judges a conference largely on the quality of a specific talk. If the hallway is the product, a weak keynote hardly matters; if the content is the product, it matters a great deal. Which one you believe should determine which conference you buy a ticket to, and the archive does not answer it.
FAQ
Is this an official position of Cloud Security Office Hours?
No. It is a synthesis of what attendees said on the live Friday call across five sessions. CSOH has no affiliation with any conference named here and takes no money from any of them. Where attendees disagreed, both sides are reported rather than reconciled, and opinions are labeled as opinions.
Why are no individual attendees named?
The Friday session is open to anyone, but it is a conversation, not a publication. People think out loud, change their minds, and talk about their employers informally. Attributing opinions to named individuals would change what people are willing to say. Guest speakers who presented publicly are named, because presenting is a public act.
How were these sessions selected?
They are the recaps between December 2025 and August 2026 in which conferences were actually discussed rather than mentioned in passing. Around fifty recaps carry a Conferences tag, but nearly all of those are one person saying they will be at an event; only five worked the subject properly. Every claim on this page links to the recap it came from.
Why is my favourite conference not here?
Because nobody discussed it at length on a Friday. This page reports one community's conversations, not a survey of the field, so absence means no coverage rather than a negative judgement. The conferences directory is the broader list.
Can I join the Friday session?
Yes. It runs every Friday, it is free, there is no pitch, and there is no requirement to speak. Details are on the sessions page, and every past session has a published recap.
Where next
The best way to use this page is to disagree with it in real time. The room is small enough that your question gets answered and open enough that nobody minds if you have never touched the topic before.
- Friday Zoom sessions - every Friday, free, no pitch. This page exists because people show up.
- All the session digests - the same treatment applied to AI security, careers, vulnerability management, supply chain, and regulation.
- All meeting recaps - the full archive, including the five sessions cited here.
- Conferences directory - the broader list, including the events nobody happened to discuss on a Friday.
- Present at CSOH - lower stakes than a CFP, and a reasonable place to try a talk on a friendly room first.
- Community and Signal chat - where the meetups at Black Hat and DEF CON actually get organised.