
Reflections After Black Hat USA and DEF CON 2026
A couple of days ago, while still in Las Vegas, I wrote about returning to DEF CON after many years away and what it was like seeing a community I had known in its earlier days become what it is today.
That article was largely about looking backward.
Now that Black Hat and DEF CON are behind me, I’ve found myself thinking much more about what I saw looking forward.
And interestingly, my biggest takeaway isn’t a new security product, vulnerability, attack technique, or even AI.
It’s the importance of community and collaboration at precisely the moment our technology is becoming less dependent on humans.
That may sound contradictory. But after this week, I don’t think it is.
Black Hat Shows You the Industry
Black Hat is always an interesting snapshot of where enterprise cybersecurity is heading.
Walk the floor, attend sessions, and talk with enough people and certain themes become impossible to miss.
This year, unsurprisingly, AI was everywhere…
- AI-powered security operations.
- Agentic workflows.
- Automated detection and response.
- AI governance.
- Model security.
- AI-assisted offensive security.
- Agents operating tools.
- Agents communicating with other systems.
- Agents increasingly capable of taking actions instead of simply recommending them.
Some of what we’re seeing is genuinely transformative. Some of it is probably inevitable marketing enthusiasm… familiar technologies repackaged, rebranded, and proudly stamped with the latest industry badge: “Now with AI.”
That’s normal whenever the industry goes through a major technology shift. But underneath the marketing is something very real…
The speed at which both attackers and defenders can operate is about to change dramatically.
And I think we’re still working through what that actually means.
We’re Moving Toward Machine-Speed Security
For most of cybersecurity’s history, technology amplified human capability…
- A scanner helped a human find vulnerabilities.
- A SIEM helped a human analyze events.
- An EDR platform helped a human investigate endpoints.
- Automation helped humans perform repetitive tasks faster.
Agentic systems introduce a slightly different proposition. We’re beginning to give technology the ability not only to analyze information, but to reason across it, select tools, make decisions, and potentially take action.
Attackers will have access to these capabilities too…
- Reconnaissance can accelerate.
- Social engineering can scale.
- Attack paths can be analyzed dynamically.
- Malware and scripts can be modified rapidly.
- Vulnerabilities can potentially be evaluated and exploited faster.
Defenders will counter with their own automation and agents. Which means we may be approaching a cybersecurity environment where portions of an attack and portions of the defense happen at speeds where humans simply cannot remain directly in the loop for every decision.
That’s fascinating, but it’s also a little terrifying. Because the question stops being simply, “What can AI do?” The more important question becomes, “What are we willing to allow AI to do on our behalf?”
The Governance Question May Be Bigger Than the Technology Question
I’ve spent a lot of time thinking about AI governance recently, and Vegas reinforced something for me. Organizations are understandably excited about capability…
- Can an agent investigate this?
- Can it remediate that?
- Can it query these systems?
- Can it automatically respond?
Those are important questions. But security leaders need to ask another set of questions at exactly the same time –>
- What information can the agent access?
- What credentials does it possess?
- What systems can it modify?
- What actions require human approval?
- What happens when its reasoning is wrong?
- Can another agent manipulate it?
- Can an attacker influence its context?
- What is logged?
- Who is accountable for the decision?
- And, how quickly can we stop it?
We spent decades building least privilege for humans. We’re going to need to become equally serious about least privilege for machines acting on behalf of humans. That may become one of the defining security architecture challenges of the agentic era.
Then You Walk Into DEF CON…
This is one of the reasons I enjoy experiencing Black Hat and DEF CON together.
Black Hat makes you think about the industry. DEF CON makes you think about the people underneath it. The atmosphere and experience changes…
- Someone is taking apart hardware.
- Someone is attacking a protocol.
- Someone is experimenting with radio.
- Someone is picking a lock.
- Someone built something wonderfully unnecessary simply to prove it could be done.
And everywhere, people are talking, sharing, teaching, arguing, comparing notes, and showing someone else what they discovered.
I wrote recently about my own history with that culture, so I won’t retell that story here. But walking through DEF CON after spending several days thinking about AI and automation created an interesting contrast. We’re building technology capable of doing more and more without us.
Yet the thing that may matter most in cybersecurity is still our ability to learn from one another.
Apparently, I Was a NOOB Again
I also did something at DEF CON this year that I found both amusing and surprisingly valuable.
I spent some time around the NOOB community. There’s a certain irony in attending several early DEF CONs, spending decades working in technology and security, and then voluntarily wandering into the NOOB area. But I loved it. Because if you’ve been doing this long enough, you eventually learn something…
We’re all NOOBs again eventually.
The field is simply too large and moving too quickly for anyone to know everything. There are security disciplines today that barely existed when many of us started…
- Cloud security.
- Container security.
- Modern identity architectures.
- LLM security.
- Prompt injection.
- Model poisoning.
- Agentic systems.
Entire attack surfaces that didn’t exist a few years ago. Experience gives you context and pattern recognition. It teaches you which questions to ask, but it doesn’t give you permission to stop learning.
I actually think one of the most dangerous moments in a technology career is when someone begins believing their experience means they no longer need to be a student.
So yes. After decades in this industry, I spent some time with the NOOBs. And I’ll probably do it again.
I Also Took a Short Trip Backward
At another point I wandered into the retro area.
There sat a Commodore 64 and a TRS-80.
That immediately transported me back to the machines I grew up experimenting with… my VIC-20, Atari 400 and eventually the PCs that followed.
I already wrote about that journey recently, so I won’t subject everyone to another tour through modem speeds, IRQ conflicts and CONFIG.SYS.
But standing in front of those machines during a conference dominated by conversations about artificial intelligence created a remarkable bit of perspective.
Within a single technological lifetime, we’ve gone from… “How much memory can I possibly squeeze out of this machine?” To, “How much autonomy should I give this machine?”
That’s quite a journey. And I think there’s a lesson buried in it.
Technology Changes Faster Than Human Nature
- Attackers still look for weaknesses.
- Defenders still try to anticipate them.
- Researchers still ask uncomfortable questions.
- Hackers still take things apart.
- Engineers still build.
Security teams still occasionally discover that the biggest problem wasn’t the sophisticated attack everyone feared, but the simple configuration nobody noticed. And people still learn from people. That’s why the conversations I had in Vegas mattered as much to me as many of the presentations.
- Someone mentions a problem they’re dealing with.
- Someone else says, “We ran into that.”
- A researcher explains something you hadn’t considered.
- A practitioner tells you what happened when theory met production.
- Someone challenges an assumption you’ve carried for years.
I believe those exchanges matters. AI can aggregate knowledge, but the people give it context. And context is where security decisions become difficult.
The Irony of the Agentic Era
That’s ultimately what I brought home from Vegas. We’re entering an era of extraordinary automation. Our systems will increasingly analyze, recommend, decide, and act. Attackers will automate, and defenders will automate. Agents will interact with agents.
The tempo of cybersecurity will increase. But the more automated our environment becomes, the more valuable I believe human trust, judgment, collaboration, and community will become.
Maybe that’s the irony of the agentic era. The machines will become increasingly capable. And we’ll become increasingly dependent on one another to understand what those machines should, and should not, be allowed to do.
My Biggest Takeaway
Black Hat showed me where the cybersecurity industry is heading. DEF CON reminded me of the culture that helped get us here. And somewhere between the AI demonstrations, technical conversations, villages, NOOBs, researchers, hackers, old computers, new ideas, and an absurd number of steps across Las Vegas, I came away with a surprisingly simple conclusion…
Cybersecurity has never really been a technology problem alone.
- It’s a people problem
- A trust problem
- A communication problem.
- A curiosity problem.
- And increasingly, it’s going to be a governance problem.
The technology will continue changing at an extraordinary pace. And yes, we should embrace that. We should experiment with it. We should absolutely use AI and agentic systems to make defenders faster and more capable.
But we also need to understand what we’re handing over when we delegate authority to machines.
And while we’re figuring that out, we should protect one of the things this industry has always done particularly well…
Share what we learn.
Because whether it happened over a modem decades ago, in a DEF CON village this week, or between security teams defending against tomorrow’s AI-driven attacks… we’ve always been stronger when we learn from each other.
That hasn’t changed. And I don’t believe it ever will.





