Navigation
AboutExperienceBlogResourcesMerchContact

inquiries@ctijen.com

← Back to blog
August 2, 2026

Bring a Belt: Everything I Know About Speaking at Cybercons

Real talk on CFPs, slide decks, stage nerves, and yes, why you should always pack a belt. A culmination of advice from a panel celebrating two years of Simply Cyber's Public Speaking Group I did back in April.

This past April, I got to be part of something really special: a 4-person panel, alongside Reanna Schultz, Chris Honda, and ZeroSignal (yes, that's the whole handle, no last name needed, and that's exactly how they like it), and moderated by Chris Young, celebrating the 2-Year Anniversary of Simply Cyber's all-volunteer Public Speaking Group. You can find Reanna, Chris Honda, and Chris Young on my People to Follow page. In two years, that group has helped double digits worth of new and seasoned cybersecurity professionals land their first conference talk, with a handful going on to land multiple, major cybercon speaking slots. (New to Simply Cyber? Here's what it is and how to join their Discord.)

I put together a lot of notes for that panel and figured, why let them live and die in a Discord voice channel? Here's everything I know about actually getting booked to speak at a cybersecurity conference, from finding the right CFP to remembering to pack a belt.

Finding (and Choosing) Your Opportunities

BSides is the move. Find one near you and apply. BSides are wonderful, local conferences where the barrier to entry can be lower than your larger cons. You may even know some folks on the CFP review board! BSides conferences help you get to know real people in the field and in your own community.

If you're in a specific niche, look for specialty cons built around it. DEATHCon is fantastic if you're into detection engineering and threat hunting, and Intellic0n is a great one, too. Don't be afraid to ask an AI assistant to help you scout niche cons in your area, just make sure you verify any con AI tells you about actually exists before trying to sign up.

Don't sleep on general, location-based cons either. GrrCon (Grand Rapids, if the name didn't give it away) and CypherCon in Milwaukee are both fantastic ways to get to know your local security community. I'm biased as a Midwest girl, but these two are fantastic and I highly recommend them!

How People Actually Find You

Funny story here. I once applied to two CFPs in a short window, one of which I'd actually been approached to apply to. I basically threw that one away as a defense mechanism, figuring I wouldn't get it anyway, so why bother really selling myself. The other CFP, where I was just another applicant with no inside track, I went all in and wrote what I still think is a genuinely good submission.

I actually apologized to the organizer of the first CFP, telling him it wasn't my best work. He told me the reason he'd approached me in the first place was my social media, specifically the educational content I'd been putting out. That's what put me over the edge for him.

Moral of the story: the CFP you don't think matters is sometimes the one someone's already decided they want you for. Put in the effort anyway.

Picking a Topic

My approach is embarrassingly simple: I think about what I'm actually working on at work right now, and then I make it open-source and vendor-agnostic with my Legal team's blessing. It's wild how much you think you're just doing business as usual, when really, your workflows and solutions could unblock someone who doesn't have access to the tools you use or hasn't thought about the problem the way you have.

Between "Accepted" and Actually Presenting

This part is a lot. If it's a brand-new talk, you're writing the whole thing from scratch. For me, that usually takes about a month of writing it all down, then going back through and iterating, iterating, iterating.

One thing that genuinely helps and may seem silly: pick a slide deck theme that makes you excited to work on it. For one talk, I went spooky, graffiti and tattoo graphics for a presentation on using AI to help analyze intel collection. If the deck is fun to build, you'll enjoy building it!

Some areas I feel as though a genuine, in-the-moment presentation of yourself is a fabulous idea. With con talks however, I run my presentations into the ground before I give them. I want to feel so comfortable that if something goes wrong (and it will, it did at Intellic0n, my slides got completely messed up), I can just roll with it. Which leads to my biggest tip: send your presentation as a PDF if you can. Try to get a run-through with the actual con equipment if possible, and if you can't, ask how it'll work and watch how the keynote and earlier speakers handle it.

Have a point of contact at the con, and don't be afraid to actually use them. Ask about accommodations. Ask if the talk will be recorded or streamed, and if there's anything you can post on LinkedIn beforehand. Basically, try to be the speaker an organizer loves working with: show up on time, participate, and evangelize the con.

Packing for Travel Days

Bring backups of everything, including comfy shoes and a change of clothes. And this is not a joke: bring a belt. You might prefer a blazer for a lav mic, it might be wireless, or you might need it clipped around your waist instead of on your ear, and if that's the case, you need something to clip it to. That extra weight on your waist is no joke. Bring a belt!

Give Something (Tangible or Not) Away

Yes, always. I want my audience to walk away with something useful: the content, the slides themselves, and if I'm presenting on a project or script, that gets open-sourced too. I am 12000% about sharing with the community first.

I'm also not opposed to physical items, but make them useful. If you want business cards, print them on plantable seed paper. Or put something functional on the back: the intelligence lifecycle, the cyber kill chain, or a different threat actor per card with a QR code linking to relevant YARA rules.

My husband hates stickers. I love them! I'm pretty sure most of the cybersecurity community does too, so I'm firmly pro-sticker, but also pro give-them-something-actually-useful for both their own and the planet's benefit.

Q&A, Pacing, and Reading the Room

I always leave time for discussion, unless the whole con is running so far behind that I'm told not to. I like framing that time as a discussion rather than strict Q&A, because the topic people know the most about is themselves. Letting them talk about what they've done tends to spark more questions and solutions than a straight Q&A, and everyone in the room benefits.

If your time window changes, know your key points well enough that you can cut examples on the fly, or stretch with more detail if you've got room to fill. Do a dry run of a condensed version of your talk before you go, so you're not discovering it live.

How Deep Do You Go?

Depends entirely on the audience. At Intellic0n, I can absolutely nerd out on intrusion analysis and get into the specific CVEs Salt Typhoon used on Cisco IOS XE devices. At something like BSides, some people in the room aren't in the field yet, they're just hoping to learn, so I'll talk more generally about threat actors and how to profile one and assess the risk to your org.

Do You Need the Flashy Slides?

I do enjoy a little pizzazz. Maybe not zooming text and flying graphics, but in the right talk, who knows! There's a REALLY great blog post from Lyra Rebane titled "SVG clickjacking" that's a fantastic example of using inline demos to actually illustrate the content. If you can add something that demonstrates your point, and it doesn't require a sacrifice to the demo gods first, add it. Keep people awake. You don't need a ton of it, especially for a more technical audience, but even then, a little automation that types out a SIEM query line by line, or types in a YARA rule as you explain it, goes a long way.

Pacing Your Content

Also depends on the topic. If I'm profiling Handala Hack, I'm packing the talk with details on their campaigns and everything we know about Iran's Ministry of Intelligence and Security. If I'm talking about how to become a CTI analyst, I'll hit some key points and then open it up for questions and comments so I can go deeper where it's actually useful.

Where Do Your Credentials Go?

First. Every time. It could be my imposter syndrome speaking, but I imagine everyone in the room asking "Ok, why should I be listening to you on this topic?" Putting your credentials up front establish who you are, why you're the SME, and then people can decide from there whether they want to stay and listen.

Can You Pitch Something for Sale?

Depends entirely on the con. If you're planning to showcase a tool in your talk, ask the organizer first.

Handling Nerves

I do the opposite of blending in. I wear all my favorite, most distracting clothing and jewelry as armor: loud boots, chains, cheeky t-shirts. That's what makes me feel comfortable, so even if I'm nervous, I still feel good delivering the content.


Huge thanks to Reanna Schultz, Chris Honda, and ZeroSignal for being incredible co-panelists, to Chris Young for moderating and keeping all four of us on track, and to everyone in Simply Cyber's Public Speaking Group for building something that's genuinely helped so many people land their first talk. Go say hi to Reanna, Chris Honda, and Chris Young if you don't already know them. If you've been sitting on a CFP, this is your sign to go hit send! And don't be afraid to reach out to others or myself for feedback and guidance. If you want to check out Simply Cyber for yourself, here's how to join.

← All postsCTIJen