Article
August 10, 2026
By Scott Radcliffe
I walked into Black Hat this year with a simple observation that kept getting reinforced the more I saw and heard: this isn’t your father’s Black Hat anymore.
There was a time when Black Hat was the hacker conference, the kind of place where attendees would famously hijack hotel WiFi and billing systems just to prove they could. It was edgy, even a bit gleefully irreverent. That energy hasn’t disappeared entirely, but it has definitely evolved.
I asked a number of people at the conference, from CISOs to others in communications, if they felt the following sentiment seemed true to them. That RSA has become its own thing; DefCon has become the old Black Hat and Black Hat has become the old RSA. As if to reinforce the point, a CEO of a mid-sized security company told me at his company’s large and well-staffed Black Hat booth he doesn’t even reserve booth space at RSA anymore because his customers, CISOs, system admins, directors of security and so on, are no longer there. They are, however, at Black Hat. Though many have great feelings of nostalgia for the old Black Hat, it is now undeniably a security conference for business and research. Still technically focused, but with a fundamentally different vibe and evolving focus.
The scale of the transformation became impossible to ignore when I saw there was an entire healthcare track at this year’s conference. To me, it tells you everything about how the conference has matured and professionalized. What was once a place where the hacker subculture would convene is now a sprawling conference center addressing security challenges across entire industries. With that growth comes responsibility, but also opportunity.
The Tone in the Security Community Has Shifted Ever so Slightly and It’s Turning Optimistic
In terms of substance, the tone of talks, general discourse and even solutions and products offered on the floor shifted a bit in the months since RSA, particularly around AI security.
At RSA, which many may remember occurred just before the limited release of Anthropic’s Mythos model, people were overwhelmingly sounding the alarm about AI’s offensive cyber capabilities. That discussion certainly didn’t disappear, but it’s no longer dominating the discourse around security or even security in AI. The most common question asked at the conference was generally, “How do we secure the AI models running in our own environments?” Axios’s Sam Sabin covered this very effectively in her overview of the conference as well. But even that generally was solutions-focused and underscored the shift. What I saw and heard at Black Hat was something slightly more optimistic: tangible solutions and exciting innovations for defenders.
This isn’t just a tonal shift; it reflects real progress. The best minds in security are now effectively chipping away at a very real and present problem presented by the quickly growing and evolving threat environment that has only accelerated thanks in large part to AI. The message we heard a few months ago was “defenders won’t be able to catch up for a couple of years” and has now begun to turn to “here’s what we’ve come up with to map and mitigate your vulnerabilities.”
Innovation at Scale: From Companies Large and Particularly Small
As you may expect, though some of this progress came from established companies in the space, the most exciting developments came from startups. A CISO I spoke with underscored this point in how he approaches building his environment. He said he leaves “the large muscle movements” like endpoint detection and response (EDR) to the big companies and relies on startups and smaller firms for innovation. His reasoning seemed pretty sound to me as I worked my way through the conference hall, sat through some talks and attended some events.
The runway for innovation is wide and long, especially today. You’ve got sustained growth in the security market overall, a universally recognized threat environment that’s expanding everywhere that touches the internet and now the ability to rapidly develop and deploy new tools using AI. This has all established a dynamic where smaller, nimble companies can move fast enough to actually solve critical problems, often in incremental but important ways.
I watched this play out across multiple startup competitions. The winners weren’t necessarily the ones with the most complex solutions. They were the companies that could clearly and efficiently articulate the problem they were solving and how they were solving it.
At these competitions it was obvious that a clear and simple solution set resonated with the intended audience. It was also evident that a focused and concise story told about those products won out as well. In a space defined by technical complexity, nuance and countless interdependencies, clear storytelling wins.
Yes, the technical details matter. Yes, the nuance is critical. But people, decision-makers, investors and security teams, respond to a clear, well-told story about what you’re trying to accomplish. The most successful startups at Black Hat weren’t necessarily the most technically sophisticated. They were the ones who could translate their innovation into a human narrative.
Don’t Forget the Fundamentals—And That’s Where Communications Lives
Even as AI turbocharges everything, security experts seemed united on one point they seem eager to tell everyone who will listen: get the fundamentals of security right. An often-forgotten element of that common piece of advice is that executing the fundamentals of cybersecurity isn’t purely a technical problem.
Consider what’s emerging as a real AI security risk: credential theft. Certainly not a new concept for security, but it impacts threats that result in everything from the compromise of a business email account to the unauthorized use of internal models from individuals outside your organization. Threats like this and the business use of unsanctioned AI models aren’t firewall problems. They’re employee behavior and awareness problems. They’re exactly the kind of issues where communications can directly contribute to security outcomes.
Making sure your organization is following security policies, engaging employees on best practices and maintaining data governance, these aren’t just IT concerns anymore. They’re enterprise-wide challenges that require a coordinated communications and engagement campaign.
Black Hat itself this year felt like a conference, and a conference serving an industry, finding an important stage in its evolution in response to genuine disruption. There’s real optimism about what’s possible when you combine human expertise with AI tools, when you focus on innovation in the margins where smaller companies thrive and when you remember that beneath all the sophistication, security success still depends on clear thinking and clear communication.
Scott Radcliffe is FleishmanHillard’s global director of cybersecurity, leading the firm’s Cybersecurity Center of Excellence and advising clients on rising cyber risks. He recently rejoined FH from Apple, where he led cybersecurity communications and previously served as the agency’s senior global data privacy and security expert.
See what else is happening
You might also like
-
Expertise
When Food Safety Crises Test Trust: A Guide for Communicators
July 24, 2026
-
Expertise
We Went to Cannes Lions: Where the Industry Is Trending
July 1, 2026
-
Expertise
Healthcare’s Moment Has Arrived. The Question Now Is: Will Your Organization Move Fast Enough?
July 1, 2026
-
Expertise
The Visible CEO: How Leadership Can Serve as a Strategic Asset
July 1, 2026
-
Expertise
How to Win the GLP-1 Food Industry Wake-Up Call
June 30, 2026
-
Expertise
Cannes Lions Exposed an Industry’s Transition of Power: Takeaways From Winning Work
June 26, 2026
-
Expertise
Lessons From Cannes: Don’t Let Speed Fail Storytelling
June 25, 2026
-
Expertise
Get Bold Work Out Into the World: How to Seize the Chaos Advantage
June 25, 2026
-
Expertise
The Action Gap: Leaders Know Bold Work Wins. They’re Just Not Moving Fast Enough.
June 23, 2026