
By: Sarah Graham
I spent the start of August at Black Hat in Las Vegas and came home with more notes about companies with bold, weightless claims about what their technologies solve, versus what truly sets them apart in the market. Now I’m left wondering: Everyone says they secure AI or AI agents, but what and how, and what are the problems they are ACTUALLY solving for CISOs and security teams?
If you didn’t make it this year, or your plane also got struck by lightning and prevented you from attending at all (I did make it, but, true story), here are the three takeaways I’d share as a PR pro and cyber nerd.
- Having an AI story stopped meaning anything. Nearly every company on the floor had one. SecurityWeek needed at least four separate installments to get through the vendor announcements, and CSO Online’s top products roundup ran nine vendors, nearly every one leading with an AI agent angle. When the whole category announces the same thing in the same week, the announcement simply adds to the overwhelming AI noise.The companies that landed were specific about what AI risk they address, who inside an organization owns that risk, and what governance and security actually looks like in practice. If your positioning still reads as “we use AI,” or “we secure AI agents” it’s time to get more specific.
- Research remains one of the best ways to break through the conference noise. Not shockingly, the publicly traded titans like CrowdStrike and Palo Alto secured post tier-one coverage in CNBC, now everyone act surprised! But the high growth stage companies that stood out secured really interesting speaking engagements or launched threat intelligence based research. And no, that does not include the trend report or “state of the industry” pieces, those have their well deserved place in the earned media landscape, but Black Hat is not one of them. The research that cut through and garnered media attention is original, valuable threat intelligence research that uncovers something new, gives the industry actionable insight, and actually moves the conversation forward. Then, of course, product launches always get a few mentions in round-ups too at events, but I would argue to save that for pre-RSA which is still more of a product/sales focused event.
- Post-quantum was almost nowhere, which is a small improvement from last year, in which it was completely non-existent. But, it didn’t get much better, and, um, how??? On June 22, six weeks before the show, the White House signed an executive order titled “Securing the Nation Against Advanced Cryptographic Attacks.” The now infamous clip of the president saying “Post-quantum, ‘cryptographee’, does anyone know what that is?” continues to be replayed in my head again and again. And, well, politics aside, clearly it was a fair question cause not even the industry seems to grasp its criticality. The Executive Order puts federal PQC migration on a real clock: migration leads named within 30 days, OMB transition guidance within 90, a NIST pilot within 180, CISA guidance on a cryptographic bill of materials within 270, and high-value assets on post-quantum key establishment by the end of 2030. (K&L Gates summary) That is federal procurement pressure and critical infrastructure expectations landing inside four years. And I struggled to find anyone at Black Hat to spiral about it with me. I was met with confused looks as if I had five heads?? At a conference of security practitioners and leaders?? I am worried. Every encrypted record being harvested today is waiting on Q-Day. The AI craze is pulling attention off a structural risk with dates attached to it, and I don’t think most boardrooms have connected those two facts yet.
In terms of the news, the most covered news moment of the week, by a wide margin, was OpenAI’s briefing disclosing that agents under evaluation had coordinated attacks through a hidden message board they built inside JFrog Artifactory, then went after Hugging Face and OpenAI’s own infrastructure. Right behind it was developments on the cyber attack on U.S. water supply. The companies that were able to work quickly and tie to these key moments in time, had a competitive edge. The ability to pivot quickly in the cyber space will make or break you.
One more note, because it was the best part of the week. The number of events and conversations centered on women and diversity in cyber felt strong this year, and Suzy Pallett taking over as Black Hat’s Brand President is exactly the kind of visible leadership this industry has been short on. I think I may be her biggest fan now? #SuzyFanClub
Kindly,
Sarah
**P.S.** I wore sneakers without socks because they looked better with the outfit. My feet have filed a formal complaint. Still cannot walk. Do as I say, not as I do.


