Surviving Black Hat: AI Hype, Vendor Noise & Making the Conference Count with Gina Yacone
In this special edition of the No Trust Podcast, recorded live in Las Vegas during Black Hat, Jaye Tillson and John Spiegel sat down with Gina Yacone for a conversation about surviving Hacker Summer Camp (aka Black Hat/Def Con), cutting through the growing noise around AI, evaluating a new generation of cybersecurity startups, and getting real value from one of the industry's biggest weeks.
PODCAST
John Spiegel
8/20/20267 min read


In this special edition of the No Trust Podcast, recorded live in Las Vegas during Black Hat, Jaye Tillson and John Spiegel sat down with Gina Yacone for a conversation about surviving Hacker Summer Camp, cutting through the growing noise around AI, evaluating a new generation of cybersecurity startups, and getting real value from one of the industry's biggest weeks.
Gina has been attending Hacker Summer Camp since 2017, after moving into cybersecurity from an earlier career in legal. Over that time, she has watched the week grow into a sprawling collection of conferences, communities, vendor events, meetings, parties and networking opportunities.
And while Black Hat remains at the center of it, the week has become about much more than a single conference.
For security professionals trying to navigate it all, the challenge is increasingly simple to describe and difficult to execute:
How do you separate the things that matter from all the noise?
Hacker Summer Camp Is Bigger Than Black Hat
Black Hat may be the anchor, but Gina sees the broader Hacker Summer Camp ecosystem as one of the things that makes the week special.
DEF CON, BSides Las Vegas, the Diana Initiative, community events, CISO gatherings and other specialized conferences bring together practitioners from across cybersecurity. Importantly, they also create different entry points depending on experience, interests and budget.
That matters because not everyone attending the week has a large corporate travel budget or an expo booth behind them.
Some people are security leaders looking for new technologies. Others are practitioners trying to sharpen their skills. Students may be attending their first major security event. Others simply want to find their community.
Put all of those groups together and tens of thousands of security professionals descend on Las Vegas for a week of learning, networking and, inevitably, a little chaos.
The opportunity is enormous.
So is the potential for burnout.
You Can't Do Everything — So Don't Try
One of Gina's biggest lessons from attending Black Hat over the years is that over-scheduling doesn't work.
It is easy to look at a calendar before arriving in Las Vegas and believe back-to-back meetings are possible.
Then reality intervenes.
A meeting at Mandalay Bay might be followed by one at the Four Seasons and another at the W. What looks manageable on a calendar can turn into a race through hotels, casinos, conference corridors and 110-degree heat.
And that ignores one of the most valuable parts of Black Hat: the people you weren't expecting to meet.
As Gina explained, the week can feel like a reunion. Walk a few steps and you run into somebody you know. Those hallway conversations matter, and scheduling every minute of the day removes the space for them to happen.
Her approach now is deliberately different.
Build travel time into the calendar. Leave gaps. Research events before arriving. Understand which talks, villages, meetings and parties actually matter to you.
Most importantly, accept that you cannot do everything.
Surviving Vegas Requires a Strategy Too
There is another side to surviving Black Hat that has nothing to do with cybersecurity.
Food.
Water.
Sleep.
Heat.
And comfortable shoes probably don't hurt either.
During the conversation, Gina described how difficult something as basic as getting a proper meal can become during Black Hat. Restaurants around the conference can be booked or bought out for vendor events, while lines at the remaining options become increasingly long.
Add packed meeting schedules and it becomes surprisingly easy to discover at 3 p.m. that breakfast was the last time you ate.
The physical environment adds to the problem. Outside, Las Vegas is brutally hot. Inside, conference spaces can feel freezing. Then there are late dinners, parties, early starts and, for international visitors, jet lag.
Trying to stretch that schedule across the entirety of Hacker Summer Camp can quickly catch up with you.
The lesson is straightforward: pace yourself.
A conference that lasts most of a week should be treated like one.
The Black Hat Show Floor Has Become a Gauntlet
The physical scale of Black Hat isn't the only thing that has changed.
The show floor has become louder, more crowded and increasingly difficult to navigate.
Vendor presentations spill into hallways. Large booths compete for attention. Celebrity appearances can stop crowds in their tracks. Restaurants become extensions of vendor marketing programs.
And the traditional distinction between the huge established cybersecurity companies and small startups is becoming harder to see.
Some young companies now arrive with enormous funding rounds and equally enormous booths.
That creates an interesting problem for buyers.
A spectacular booth can tell you a company has money.
It doesn't necessarily tell you what problem its technology solves.
Everybody Does AI. But What Does That Actually Mean?
Unsurprisingly, AI dominated much of Gina's time on the Black Hat floor.
More specifically: agentic AI.
Gina is bullish on the potential of agentic security and the broader impact AI will have on cybersecurity. But that doesn't mean accepting every AI claim at face value.
Quite the opposite.
Walk through the expo and seemingly every company has AI terminology attached to its product. The difficulty is understanding what those terms actually mean from one vendor to another.
What does the product do?
What problem does it solve?
How is it different?
How mature is the technology?
And what is actually on the roadmap versus what exists today?
Those questions become even more important as AI-assisted coding allows companies — including businesses that might never have considered themselves software companies — to build their own applications.
The development cycle is accelerating.
Security has to keep pace.
Traditional security controls still have an important role, but Gina believes organizations also need to understand the risks created by increasingly dynamic applications and runtime attacks. New security technologies can complement existing controls, but buyers first have to determine which capabilities are real and which are primarily marketing.
That may be one of the hardest jobs on the Black Hat floor.
Pretty Booth. Cool Name. What Problem Are You Solving?
One of the recurring frustrations in the conversation was remarkably basic.
Sometimes it is difficult to tell what a company actually does.
Gina described walking past impressive booths with creative themes and eye-catching designs, only to have no immediate idea what problem the vendor solves.
Is it third-party risk?
An AI SOC?
Security awareness?
GRC?
Application security?
Something else entirely?
The branding may be memorable, but the problem statement isn't always obvious.
That creates an environment where attendees sometimes have to engage with a vendor simply to understand what category the company belongs in.
And once that badge gets scanned, the vendor has a lead.
For security leaders arriving at Black Hat with specific problems to solve, that is hardly efficient.
The alternative is to approach the show floor much more deliberately: identify the problems you care about, curate the companies you want to meet, and use the rest of the floor to discover what you might have missed.
Cybersecurity Buyers May Need to Start Thinking Like VCs
AI isn't only changing security technology.
It is changing the companies building it.
Startups can develop products faster, raise capital earlier and arrive on the Black Hat floor far sooner than might have been possible in the past.
That presents security leaders with a new type of risk.
The technology may be promising, but will the company still exist in 12 months?
Will it be acquired?
Can it scale to support an enterprise?
Has it reached product-market fit?
How much of what you are seeing is a mature product — and how much is still essentially an idea?
One response is to avoid younger vendors entirely.
Gina argues that approach creates its own problem. The risk an organization is trying to address doesn't disappear simply because a CISO is uncomfortable betting on a startup.
Instead, buyers may need to become more sophisticated about evaluating the company behind the product.
Who are the founders?
Who invested in them?
Has the leadership team successfully built companies before?
Can the technology scale?
What does the underlying technology stack look like?
Are customers actually using it?
In other words, cybersecurity leaders increasingly need to think a little like venture capitalists.
And rather than making one enormous bet, the better strategy may sometimes be a series of smaller ones.
Find Someone Who Can Cut Through the Noise
Of course, not every CISO has the time to become a venture capitalist while simultaneously running a security program.
That is where trusted advisors and technology partners can play an increasingly important role.
Gina described the work her organization does evaluating emerging companies and engaging with founders to understand not only what their technology promises, but whether the business and product can realistically support enterprise customers.
That kind of curation becomes valuable in a market where a search for "agentic AI security" can return a rapidly expanding list of companies making remarkably similar claims.
The objective isn't simply to know who exists.
It is to understand who can actually solve the problem.
If You're Starting Your Career, Take Notes
The conversation eventually turned from technology buyers to people beginning their cybersecurity careers.
If Gina were starting again today, much of her approach would remain surprisingly traditional.
Go to talks.
Listen.
Take notes.
Ask questions.
Talk to speakers.
Have hallway conversations.
Then go home and research the things you didn't understand.
Gina believes people may have lost some of the art of simply taking notes and using them as the starting point for deeper learning.
AI absolutely belongs in that learning now. Anyone entering cybersecurity needs some understanding of AI and how it is changing the industry.
But AI should not become the entirety of somebody's cybersecurity education.
Network security still matters.
Cloud security still matters.
Endpoint security, vulnerability management, asset management and the traditional security domains still matter.
The industry will continue to need practitioners with expertise across all of them.
The better career strategy is therefore not to chase whatever happens to be the biggest trend on the Black Hat floor.
Find the part of cybersecurity that genuinely interests you and build from there.
Conferences Still Matter
That also means giving practitioners opportunities to get outside their normal working environment.
Online training, certifications and learning management systems have their place.
But they don't completely replace being in a room with other people solving similar problems.
Gina believes leaders should give employees space to attend conferences — whether that's Black Hat, RSA, a local security event or something else entirely.
Why?
Because conferences help people build perspective.
They expose practitioners to ideas outside their immediate organization. They create opportunities to challenge assumptions, compare approaches and build professional networks.
Perhaps most importantly in today's market, they help people learn how to differentiate signal from noise.
And there is plenty of noise.
The Bigger Picture
Black Hat has always been intense.
But this year's conversation with Gina highlighted how several forces are colliding at once.
The conference is bigger and more commercial. Startups are moving faster. Venture capital is placing enormous bets. AI terminology is everywhere. Product development cycles are shrinking. Security teams are being asked to evaluate technologies that may not have existed a year ago.
That makes preparation more important, not less.
Come to Black Hat with a purpose.
Know which problems you want to solve.
Leave enough room in the calendar for unexpected conversations.
Ask vendors what their technology actually does.
Look beyond the booth and evaluate the company behind the product.
Learn AI, but don't abandon the cybersecurity fundamentals that got us here.
And remember that sometimes the most valuable thing you bring home from Las Vegas isn't a piece of swag, a product demo or another badge scan.
It's perspective.
Because in an industry moving this quickly, the ability to separate what matters from what is simply froth may be one of the most useful security skills of all.
