built throughORANGEBOX·see what it ships·$1 →
Still-life of a sealed manila envelope on dark slate with a thin cyan ribbon of light crossing the frame.

AtomEons / Learn / Cyber / Conferences

Where the field meets

Twelve conferences worth knowing about.

Cybersecurity is a small enough field that going to two or three conferences a year puts you in the conversation. Below: what each major recurring conference is, when it runs, what tier it represents, and how a student or junior pro can actually get there.

01

DEF CON

August · Las Vegas (Caesars Forum + Flamingo)

The hacker conference

The defining cyber conference since 1993. ~30,000 attendees. Talks + villages (Lockpick Village, Car Hacking Village, Aerospace Village, AI Village, ICS Village, etc.) + CTF + workshops. Aggressively practitioner-oriented. Cash-only at the door (~$460 in 2025), no badges in advance — operational-security tradition. Many free-to-watch recordings on YouTube weeks after.

Student / junior pro: Student discount if you're enrolled (limited badges). Many groups offer scholarships — Hak4Kidz, Ladies of London Hacking, DC101 fund underrepresented attendees.

02

Black Hat USA

August · Las Vegas (Mandalay Bay) · the week before DEF CON

The corporate/enterprise conference

Founded by Jeff Moss (also DEF CON founder). $2,500+ for Briefings access. Higher production value, more enterprise audience, more government attendees. Briefings selection committee is extremely rigorous — a Black Hat USA talk is a major credential. Trainings ($3,000-$7,000) sell out months early.

Student / junior pro: Press + academic discounts exist. Most students attend DEF CON instead.

03

RSA Conference

April/May · San Francisco (Moscone Center)

The vendor + executive conference

Largest cybersecurity conference by attendance (~40,000+). $2,500+ for full conference pass. Heavily vendor-oriented — the expo floor is the largest cyber-business surface anywhere. Less hacker-culture, more CISO + government. Innovation Sandbox Top-10 startups list is consequential industry signal.

Student / junior pro: Student rate exists but you'll feel out of place — DEF CON is the better entry-point.

04

BSides (anywhere)

Year-round · 100+ cities globally

The free + local conference

Community-run, mostly-free or low-cost cybersecurity events in 100+ cities. Las Vegas BSides runs concurrent with Black Hat/DEF CON. BSides DC, BSides NYC, BSides SF, BSides Charm (Baltimore), BSides Chicago, BSides Atlanta — every major US city has one. International equivalents in Europe, Australia, Asia. The single best free entry point to the field. Find your nearest at securitybsides.com.

Student / junior pro: Most BSides have student rates of $0-$20. Often the easiest first conference.

05

ShmooCon

January · Washington DC

The mid-Atlantic federal-adjacent

1,500-person conference run by The Shmoo Group. Highly competitive ticket sale — sells out in seconds. Federal-employee-heavy attendee mix. Talks frequently feature original research. Free recordings published after.

Student / junior pro: Student rate exists. Tickets are the harder problem than money.

06

Chaos Communication Congress (CCC)

December · Hamburg, Germany

The European hacker conference

Annual gathering of Chaos Computer Club, the German hacker community. Runs over Christmas week. ~17,000 attendees. Strong civil-liberties + cryptography + privacy emphasis. Streams free worldwide. Many of the best public talks on government surveillance + activist technology come from CCC.

Student / junior pro: Ticket pricing typically €120-€140 — the conference itself is one of the most accessible. Apply early.

07

Kaspersky Security Analyst Summit (SAS)

Variable · usually spring · varying global locations

The threat-intelligence conference

Invite-only or sponsor-purchase for ~500-700 attendees. The premier threat-intelligence + advanced-persistent-threat research conference. Major nation-state actor attribution research often debuts here. Significantly affected by 2022+ Western researcher boycotts after Kaspersky's Russia-government ties became politically untenable.

Student / junior pro: Not student-accessible. Mentioned for completeness.

08

Insomni'hack

March · Lausanne, Switzerland

The European hacker + CTF

Swiss conference combining briefings with one of the most respected CTFs in Europe. ~1,000-1,500 attendees. Strong European red-team + reverse-engineering presence. CTF qualifications open globally.

Student / junior pro: Workshops accessible to skilled students. CTF is free to register.

09

Hack-in-the-Box (HITB)

Variable · Amsterdam, Phuket, Dubai (separate events)

The Asian + European technical conference

Founded in Malaysia, now multi-region. Strong reverse-engineering + exploit-development content. Technical depth-over-breadth. Multiple events per year across regions.

Student / junior pro: Student rates exist. Recordings often free post-conference.

10

NULLCON

March/September · Goa, India + Berlin

The South Asian hacker conference

Founded in Goa in 2010, now also runs Berlin. Strong original-research presence — especially mobile security, ICS, automotive. India's largest cyber conference.

Student / junior pro: Affordable for the region. International attendees pay more but still well below US conference rates.

11

FIRST Conference

June · varies (Washington DC, Toronto, etc.)

The incident-response conference

Forum of Incident Response and Security Teams. ~600 attendees, by member-organization affiliation. The premier global IR + CSIRT operations conference. Members include national CERTs, major Fortune 500 SOCs, military cyber units.

Student / junior pro: Membership-gated. Apply via your employer's CSIRT if any.

12

OWASP Global AppSec

April + October · varying global cities

The web AppSec conference

OWASP Foundation's twice-yearly flagship conference. Lisbon, San Francisco, Dublin, Tel Aviv have hosted. ~600-1,000 attendees. The web-AppSec community gathering — strong DAST/SAST/threat-modeling/SDLC content. Pairs with regional OWASP chapter events that run year-round and are usually free.

Student / junior pro: Student rates exist. Local OWASP chapter events are universally free.

How to actually get there.

  1. 01

    Start with BSides in your nearest city. They're $0-$20, run on Saturdays, and the talks are surprisingly technical. Pair with your local OWASP chapter meetup (also usually free) for regular community contact.

  2. 02

    If you can get to one major event, DEF CON is the right one for a junior cyber pro. The villages are the actual education: pick three (Recon, Car Hacking, AI Village, Aerospace, ICS, Lockpicking) and spend a full day in each.

  3. 03

    Black Hat USA Briefings are a credential, not an education. If your employer pays, go for the badge. If you're paying yourself, save for DEF CON.

  4. 04

    Submit a talk to a BSides as soon as you have something to present. The barrier is lower than you think, and a BSides talk on your résumé matters for senior interviews.

  5. 05

    Watch DEF CON / Black Hat / CCC / OWASP talks on YouTube. Every year publishes the recordings. Three hours a week of conference talks = de facto graduate-level coursework.

LAB · ATOMEONS · MARCO ISLAND FLÆONS RESEARCH · 12 PAPERS · CC-BY 4.0ORANGEBOX v1.0.0-beta · TURBO-OPTIMIZE CLAUDE · SHIPPED 2026-05-30B00KMAKR v3.2.0 · AI PUBLISHING COCKPIT · MAC + WINDOWSFREE LAUNCH WEEK · ENDS JUNE 6 · §4A NO-SAAS LOCKFOUNDER'S VIEW · NEXT BROADCAST IN ...CITE THE WORK · FORWARD THE LINK · NO ALGORITHMLAB · ATOMEONS · MARCO ISLAND FLÆONS RESEARCH · 12 PAPERS · CC-BY 4.0ORANGEBOX v1.0.0-beta · TURBO-OPTIMIZE CLAUDE · SHIPPED 2026-05-30B00KMAKR v3.2.0 · AI PUBLISHING COCKPIT · MAC + WINDOWSFREE LAUNCH WEEK · ENDS JUNE 6 · §4A NO-SAAS LOCKFOUNDER'S VIEW · NEXT BROADCAST IN ...CITE THE WORK · FORWARD THE LINK · NO ALGORITHM