Black Hat: $600+ in Taxis, 115° Heat, Too Much AI… and a Hell of a Poker Game!

By Michael Hiskey

Black Hat is enormous, overwhelming and filled with more competing events, parties, presentations and vendor experiences than anyone could possibly fit into a single week. That’s exactly why the CxO Security Forum approach was different.

 

Our goal at Black Hat was to create a smaller, more personal experience where cybersecurity executives could step away from the noise, put the sales pitches aside and simply spend time with peers. Whether around the poker table, or over a drink between hands, the value came from the people in the room and the quality of the discussions.

 

We are grateful to LogicGate, Sun Security, and Rival Security for supporting the CxO Security Forum Black Hat Executive Poker Invitational and helping make five tables of cybersecurity leaders, a few hours of poker, and a lot of great conversation one of the highlights of Black Hat 2026.

My First Black Hat — The Good, the Hype, the Hacker Ethos, and Everything In Between

 

I was almost embarrassed to admit that this was my first Black Hat ever.  Everybody assumes I’ve probably been to a bunch of them, so more than a few people were surprised when I said it was my first. Interestingly, I also met quite a few other first-timers, so apparently I wasn’t alone.

 

Black Hat is different.  It’s huge.

 

And, I understand why people compare it to the RSA Conference. In many ways, it has become another massive cybersecurity industry gathering—with enormous exhibit halls, endless side events, packed hotel suites, executive dinners, parties, networking receptions and enough competing agendas to make your head spin.

 

At times, I didn’t see as much of the hacker ethos that is supposed to be the root, the core, the inner nerd of the Black Hat community.  But it was still there around the edges.  Guy Fawkes masks. More black T-shirts. More people in shorts. More of that unmistakable “security people being security people” vibe.

 

Although, to be fair, it was 115 degrees in the shade in Las Vegas this week, so the shorts were probably less about hacker culture and more about basic survival.

Comments

I welcome your input on this article… please do that via the summary LinkedIn post on this same topic

Too Much of Everything

 

There were way too many side events.

 

Lots of them were very good. The problem was that there were simply too many of them—and they were spread all over Las Vegas.

 

I spent more than $600 on Ubers during the trip.  That tells you something.

 

Mandalay Bay was sold out and wildly overpriced, and while there were rooms available at neighboring properties, the quality of some of those accommodations has apparently declined over the years. The Luxor isn’t what it used to be, and the Excalibur is… well, the Excalibur.

 

I personally like Vegas.  I know it’s fashionable to beat up on Las Vegas. People complain about the smoke, the gambling, the noise and the general Vegas-ness of it all. But I embrace it. I actually think one trip to Vegas a year is probably good for almost everybody.

 

That said, there were simply too many things happening too far away from Mandalay Bay.

 

I understand that some events have to be somewhere else. If you’re going to drive Ferraris, for example, you probably need a little more room than you can find in the Mandalay Bay parking lot.

 

And don’t get me wrong: everybody should drive a Ferrari at least once in their lives.

 

But a lot of the executives at end-user organizations I know aren’t particularly interested in elaborate boondoggles. They want useful conversations, meaningful connections and access to people who understand the problems they are actually dealing with.  That’s an important distinction.

 

The Community: Real Relationships vs. FOMO

 

Of course, one of the best parts of any major cybersecurity conference is reconnecting with old friends and meeting people you’ve known for years but somehow never actually met in person.  I’m not going to harp on that too much, though.

 

There are already plenty of sappy LinkedIn posts about how incredible the cybersecurity community is, how “we’re all family,” and how everyone loves everyone.  There are a lot of really good people in cybersecurity. We’re colleagues. We share common challenges. We help each other.

 

But I also think some of those posts are really about creating FOMO—or trying a little too hard to demonstrate just how amazing someone’s relationships are within the industry.  If you want to talk about genuine relationships, however, there were some great examples at Black Hat.

 

One of my favorites was the “Midnight in the War Room” movie premiere.

 

Midnight in the War Room

 

The premiere was a who’s-who of the cybersecurity industry, and I was particularly pleased to see so many CxO Security Forum community members both featured in the film and attending the premiere.

 

There were perhaps a thousand people gathered to watch it.

 

Interestingly, many of the people who appeared on screen had only seen their own portions of the movie. Most hadn’t seen the final production, and several people I spoke with beforehand had no idea how much of their face-to-camera interview actually made it into the finished film.  That made watching the premiere even more interesting.

 

Hats off to the Semperis crew—or perhaps I should say Semperis Studios—for pouring so much time, energy and heart into the project.

 

Their entire Black Hat presence revolved around the film. The booth was packed, the team was everywhere, and they had some pretty cool swag and activities surrounding the premiere.

 

I was fortunate enough to receive VIP access, which turned out to be a fantastic opportunity to see so many familiar faces in one place.  I also somehow wound up sitting next to Jen Easterly and Chris Inglis—two people who appear prominently in the film.

 

That was an interesting situation.  They were sitting there watching themselves on a giant screen, which was probably even stranger for them than it was for me.

 

I hope the great work that Tim Brown, Chase Cunningham, Richard Stiennon and Krista Arndt contributed reflects as well on the broader cybersecurity community as their commentary did.  And a special mention for Chase: his commentary produced the first really good, hard laugh of the movie. It was exactly the bit of energy the film needed in what is, understandably, a pretty serious documentary.

 

As the Black Hat CEO said in the introduction, the movie highlights the hard work, pressure and enormous mental load that CISOs and other cybersecurity executives carry every day.  That part felt very real.

 

The Show Floor: Bigger, Louder and More Theatrical

 

The show floor is massive.  And “massive” doesn’t really capture it.

 

The atmosphere is almost carnival-like. Vendors went all out with enormous exhibits, elaborate displays, games, entertainment, giveaways and anything else they could think of to get someone’s attention.  It seemed like every vendor had at least a 20×20 booth, and many went considerably bigger.

 

Illumio, as usual, had its centrally located in-booth interviews featuring big names and interesting conversations. I also ran into John Kindervag, who apparently did some stand-up comedy later that night. I can’t wait to hear how that went.

 

A few other standouts caught my attention:

  • Adaptive Security had fighting BattleBots and a group of young team members actively working the floor and bringing people over to see them.
  • Zero Networks did something I thought was particularly smart: they had actual customer CISOs at their booth, sitting at the counter and having one-on-one conversations with prospects. That’s a dramatically different experience than putting another salesperson behind a table.
  • Rapid7 had robots, autonomous AI playing chess and a pretty impressive “Player Not Pawn” takeover of the Mexican restaurant in the convention center.
  • Dropzone AI created a diner-themed experience that was kitschy, fun and constantly feeding people, with energetic BDRs like Teri engaging attendees.
  • Abnormal Security and Anomali both had large, engaging exhibits outside the Business Hall itself, which was a smart way to engage people who didn’t have a full Black Hat conference pass.

There was plenty of noise.  But there were also plenty of legitimate conversations happening underneath all of it.

 

Suite Life

 

I heard about at least a dozen different suites and private gatherings.  And, honestly, I understand why they exist.  Community members regularly tell me that, under the right circumstances, one-on-one time with a solution provider’s C-suite executives can actually be productive.

 

The key phrase there is “under the right circumstances.”

 

One of the more interesting examples was what Karl Mattson did with his VC and #StartUpLife founders.

 

When these gatherings are thoughtfully curated and focused on actual business challenges rather than sales pitches, they can be valuable.  When they’re simply elaborate lead-generation machines, well… we all know what happens next.

 

Hospitality

 

There were too many hospitality events to mention.

  • GuidePoint was seemingly everywhere and had what looked like one of the most consistently busy and centrally located setups, right off the casino between the hotel rooms and convention hall.
  • Arcova and friends were at the House of Blues.
  • AWS hosted an evening gathering that was extremely well attended, with the Vegas Golden Knights DrumBots drumming conference-goers into the lounge.
  • WWT essentially took over S-Bar at Mandalay Bay. Kate and Madison had a constant stream of senior executives, along with panels and interviews throughout the evening.

I was particularly pleased to have the opportunity to hear from and shake hands with Acting CISA Director Nick Anderson there.  Those kinds of moments are ultimately what make conferences like this worthwhile.

 

CxO Security Forum Black Hat Executive Poker Invitational

 

And then there was the poker game.

 

Our executive poker tournament was phenomenal.

 

I don’t want to brag, but I’m going to brag a little.  A lot of participants told me that our tournament was better than some of the much bigger, splashier vendor-sponsored poker events with large cash prizes and no buy-in.  And I understand why.

 

Those events can generate enormous registration numbers because, frankly, people like free money.  But if the primary objective is badge scans and lead generation, everyone in the room knows it.  Our goal was different.

 

We wanted a small, curated group of legitimate cybersecurity executives sitting around tables together, playing poker, talking shop and having a genuinely good time.  And that’s exactly what happened.

 

Five Full Tables of Executives

 

We approved more than 60 people to participate, ultimately welcoming 40 executives to the tables when the cards went into the air around 9:00 p.m.  We had dozens more people asking to participate, and I sincerely apologize to everyone we couldn’t accommodate.

 

But the size restriction was intentional.

 

We are very particular about curating rooms filled with actual end-user CISO and CIO executives. That means sometimes people who want to attend simply can’t.  That’s not a bad problem to have. We played until shortly after midnight and paid out the top five finishers.

 

But, as usual, the money wasn’t really the point.  The conversations were.

 

Your average CISO is pretty good at spotting who knows what they’re talking about and who is making things up. Sitting around those five tables, listening to the conversations, was a perfect demonstration of that.

 

People were talking about what they were seeing at the conference, which technologies were generating legitimate interest, which topics were getting too much hype and which conversations were actually worth their time.  And, of course, there was AI.

 

So much AI.

 

At this point, I’m not sure we can have a cybersecurity conversation without AI somehow being dragged into it.

  • AI in cybersecurity.
  • Cybersecurity for AI.
  • AI-powered cybersecurity.
  • AI-enabled everything.
  • AI agents.
  • AI risks.
  • AI governance.
  • AI, AI, AI.

 

Eventually, someone at the poker table would bring up something interesting and we’d somehow circle back to AI.  

 

Maybe that was the most authentic Black Hat experience of all.

 

So, Was Black Hat Worth It?

 

Absolutely.

 

Would I do it again?  Also absolutely.

 

But I think Black Hat is best approached with realistic expectations.

  • You cannot see everything.
  • You cannot attend every event.
  • You cannot visit every booth.
  • You cannot make every dinner.
  • You cannot have every conversation.
  • And you certainly can’t do all of that without spending a small fortune on transportation.

The sheer scale means you’re inevitably going to miss something.  What matters is knowing what you’re looking for.  

  • If you’re looking for the latest technology, there’s plenty of it.
  • If you’re looking for vendors, there are thousands of them.
  • If you’re looking for networking, you can find it everywhere.
  • If you’re looking for parties, you won’t have any trouble finding one.
  • If you’re looking for thoughtful conversations with people who actually understand the challenges of running cybersecurity programs, those are there too—but you have to be more intentional about finding them.
  • And if you’re looking for remnants of the original hacker ethos, they’re still there.  You just have to look a little harder.

As regular readers of CxO Insights know, I’m pretty critical of vendors in general—and particularly anything that seems designed primarily to turn someone’s contact information into a lifetime supply of unsolicited emails.  But I also recognize good engagement when I see it.

  • There were plenty of genuine conversations at Black Hat.
  • There were people doing interesting things.
  • There were vendors thinking differently about how they engage executives.
  • And there were thousands of cybersecurity professionals who genuinely care about solving some very difficult problems.

For me, that’s the real value.

  • Not the swag.
  • Not the Ferraris.
  • Not the parties.
  • Not the badge scans.

It’s the conversations.

 

And, of course, sometimes it’s sitting around a poker table at midnight with 39 other cybersecurity executives, laughing, talking shop and realizing that—even after everything else Black Hat throws at you—you’ve finally found the part of the conference that feels like it was actually built for you.

 

Special Thanks

 

A few people made my first Black Hat considerably more enjoyable:

  • Dani Woolf, whom I actually met for the first time at the Audice 1st CISO Games Gym. It was great watching Chase kick butt in his military workouts and Cecil walk around like a mayor running for reelection.
  • Trish Crowell, Director of Strategic Partnerships at EC-Council.
  • Kate Brett Goldman, a forever friend of the CxO Security Forum community, who helped me navigate Black Hat as a first-timer.
  • Kate Keuhn and Madison Horne, for letting me crash the WWT functions.

 

And to everyone who joined us at the CxO Security Forum Black Hat Executive Poker Invitational—thank you.

 

You helped make the best part of my first Black Hat one that I’ll be talking about long after the Vegas heat, the Uber receipts and the AI hype have faded.

Comments

I welcome your input on this article… please do that via the summary LinkedIn post on this same topic