July 23, 2026
Black Hat 2026 — A First Timer’s Field Guide
No, I’m not going to Black Hat this year. This is not one of those posts where I manufacture conference FOMO from my couch.

By Dave Bowden
4 min read
A first-timer asked me for a little advice, so I started writing what I intended to be a short response. Somewhere between "disable Bluetooth" and "threat-model the swag bag," my inability to answer anything in three bullets took over.
In my failure to be brief, I wrote an article.
If you are heading to Black Hat for the first time, here is the advice I would give you:
1. Treat every network and identity surface as hostile. Black Hat built its reputation as a hacker conference, and Vegas is not the place to casually trust Wi Fi. Turn off auto-join for networks, disable Bluetooth, NFC, and location sharing, and avoid connecting to public Wi-Fi unless you absolutely have to. If you must connect, use a trusted VPN endpoint and assume everything you do on that network is observable.
Also, remember: identity is your real blast radius. Even with a VPN, session tokens and credentials can still be targeted through phishing infrastructure operating inside or near the event.
Practical tech recommendations for personal protection:
- Use a dedicated travel laptop or a hardened profile with full disk encryption, strong MFA, a personal firewall enabled, and no sensitive source code or production credentials.
- Use a separate browser profile or container for conference activity. Do not remain logged in to corporate or production systems.
- Prefer phishing-resistant MFA such as FIDO2 or passkeys over OTP where possible.
- Log out of sensitive sessions before joining any untrusted network.
- Clear saved Wi-Fi networks, then disable Wi-Fi and Bluetooth in system settings, not just quick toggles.
- Install and verify endpoint protection, and keep OS, browsers, and key applications fully patched before you leave.
- Remove unnecessary SSH keys, cloud credentials, kubeconfigs, and VPN profiles. Use just-in-time access where possible.
- Consider a prepaid or burner phone. If using your primary device, remove corporate apps, disable auto downloads, and lock your SIM with a PIN.
- Avoid public charging stations and use your own wall charger or a trusted power bank.
- Do not plug in random USB devices or scan unknown QR codes.
Know the attack patterns you will actually encounter. Black Hat is one of the few places where you should expect active, opportunistic, and sometimes deliberate targeting.
Common patterns seen every year:
- Rogue Wi Fi networks impersonating hotel or conference SSIDs.
- Fake event invites, after-party links, or "updated schedules" that harvest credentials.
- Malicious QR codes placed over legitimate signage.
- USB drops in hallways, lounges, or swag bags.
- Bluetooth scanning and device enumeration in crowded areas.
- Social engineering through casual conversation about your environment, tooling, or incidents.
Assume anything convenient, free, or urgent deserves scrutiny.
2. Go in with a clear plan, not a packed schedule. The content at Black Hat is deep, and the venue is huge. Before you arrive, use the official agenda and mobile app to identify the few tracks and talks that matter most to you, whether that is AI security, cloud and identity, OT and IoT, or threat intelligence.
Build your schedule around those priorities and avoid sprinting between distant rooms every hour. Aim for one anchor session per half day, then leave a margin for hallway conversations, follow-ups with speakers, and unplanned discoveries.
If you are attending Training, treat it like a high-intensity course: rest, hydrate, take good notes, and think about how you will convert what you learn into internal sessions or improved runbooks.
3. Approach the Business Hall like a reconnaissance mission. The expo floor can either be noise or a force multiplier. Go in with a short list of vendors and categories tied to real problems you are solving, such as AI security, SaaS posture, detection and response, OT visibility, or fraud and payments.
Use quieter time slots for deeper discussions. Ask about deployment models, integration patterns, and reference architectures you can map back to your environment.
Be cautious with swag:
- Treat all hardware (USB devices, cables, chargers, dev boards) as untrusted.
- Do not install vendor software or agents during the conference.
- Evaluate anything you bring home in a controlled environment.
Your goal is not to evaluate everything. It is to identify a few solutions worth a real proof of concept.
4. Invest heavily in relationships, but stay aware. The real long-term value of Black Hat is the people you meet. Before you travel, line up a few intentional meetups.
During the event, prioritize meaningful conversations over volume. Ask what problems people are actually dealing with and share your own lessons learned.
At the same time, be mindful:
- Do not discuss sensitive architecture or incidents in public or semi-public spaces.
- Be cautious with overly probing questions from people you do not know.
- Verify identity before sharing anything non-public.
Follow up within a week with a short note, a concrete takeaway, and a next step. That is how you turn a few days into a durable network.
5. Play the long game: health, safety, and containment. Black Hat is a marathon. The Mandalay Bay layout and Vegas heat will punish you if you treat it like a sprint. Wear comfortable shoes, hydrate frequently, and set aside time for real meals and sleep.
Add a few practical protections:
- Use privacy screen filters to reduce the risk of shoulder surfing.
- Consider RFID blocking sleeves for passports and cards.
- Limit yourself to one credit card and avoid sketchy ATMs.
- Keep devices on you or locked, with short auto lock timers.
Enable tripwires before you go:
- Turn on login alerts for key accounts (Google, Microsoft, AWS, GitHub, etc.).
- Expect and monitor for new device logins or impossible travel events.
- If you have a SOC, let them know you are attending.
When you get home, assume exposure:
- Rotate credentials used during the trip.
- Invalidate active sessions where possible.
- Review OAuth grants and API tokens.
- Run scans, review logs, and consider re imaging high risk devices.
- If you used a travel system, restore it to a known clean state.
Finally, capture the value. Write down your top insights, promising vendors, and two or three concrete improvements you will pursue.
If you do nothing else: Avoid public Wi-Fi without a VPN, do not log in to sensitive systems, do not plug in unknown devices, and assume anything you connect to could be monitored.
For everyone going this year: learn something useful, meet people worth knowing, drink some water, and remember that "free" is not a security classification.
If a stranger hands you a USB device and says, "It's probably fine," congratulations. The conference has become interactive.
Disclaimer: None of this should be interpreted as evidence that I am attending.
Years in cybersecurity have made me old enough to distrust conference Wi-Fi, grumpy enough to avoid Las Vegas in August, and self-aware enough to know that I no longer need 20,000 people, 110-degree heat, and a backpack full of untrusted USB cables to feel professionally fulfilled.
You go. Have fun. Learn something useful. Send me the notes afterward, preferably through a trusted channel.
[SAVE FERRIS]