Closing Remarks

Reed Loden

BSidesSF 2026 · Day 2 · AMC Theatre 13

Overview

Reed Loden's "Closing Remarks" for BSides San Francisco 2026 served as a comprehensive retrospective, encapsulating the monumental efforts and record-breaking successes of one of the cybersecurity community's most anticipated events. Far from a traditional technical talk dissecting vulnerabilities or new exploits, this session provided an invaluable look behind the curtain at the intricate operational security, logistical challenges, and community spirit required to host a conference of this magnitude. Loden, a long-standing contributor to BSides SF, meticulously detailed the event's achievements, from unprecedented attendance figures and a wealth of content to the impressive volunteer dedication and the technical prowess demonstrated in managing its complex infrastructure.

Watch on YouTube

Key moments

  1. 0:00 Welcome and record-breaking conference statistics
  2. 2:00 Program facts and CTF competition results
  3. 4:50 Exploring the nine diverse BSides villages
  4. 5:40 Successful charity fundraising from t-shirt sales
  5. 6:00 Internet infrastructure and network usage statistics
  6. 7:00 Real-time network issue resolution and firmware update
  7. 7:40 Gratitude for financial sponsors supporting the event
  8. 8:15 Appreciation for the 235 dedicated event volunteers

Closing Remarks

Speakers: Reed Loden

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=M4iVn1Rwzdk

Overview

Reed Loden's "Closing Remarks" for BSides San Francisco 2026 served as a comprehensive retrospective, encapsulating the monumental efforts and record-breaking successes of one of the cybersecurity community's most anticipated events. Far from a traditional technical talk dissecting vulnerabilities or new exploits, this session provided an invaluable look behind the curtain at the intricate operational security, logistical challenges, and community spirit required to host a conference of this magnitude. Loden, a long-standing contributor to BSides SF, meticulously detailed the event's achievements, from unprecedented attendance figures and a wealth of content to the impressive volunteer dedication and the technical prowess demonstrated in managing its complex infrastructure.

The talk highlighted BSides SF 2026 as a landmark year, setting new benchmarks in participant engagement, content diversity, and operational scale. It underscored the conference's commitment to its core ethos of community participation and knowledge sharing, while also revealing the technical and human challenges inherent in orchestrating such an ambitious gathering. For attendees, it offered a moment of collective celebration and appreciation, while for the broader cybersecurity community, it provided a compelling case study in large-scale event management within a highly technical domain.

Background

▶ Watch: Welcome and record-breaking conference statistics (0:00)

BSides conferences, born from the desire for more community-driven, accessible, and inclusive security events, have grown exponentially since their inception. BSides San Francisco stands as one of the largest and most influential iterations globally, embodying the foundational "by the community, for the community" principle. Its background is rooted in providing a platform for diverse voices, fostering collaboration, and democratizing cybersecurity knowledge outside the often-prohibitive costs and corporate structures of larger, commercial conferences. This ethos attracts a wide array of participants, from seasoned professionals to aspiring students, eager to learn, share, and network.

The problem that BSides SF addresses is multifaceted: the need for high-quality, relevant security content that is financially accessible; the cultivation of new talent through opportunities like first-time speaking slots and Capture the Flag (CTF) competitions; and the creation of a vibrant, inclusive space where everyone feels empowered to participate. Reed Loden's personal journey with BSides SF, starting in 2015 by managing the Call for Papers (CFP) process, exemplifies the volunteer-driven nature of the organization. His deep involvement provides him with a unique perspective to articulate the scale of effort and the community's collective achievement. Running an event of this scale in San Francisco, as Loden noted, presents unique financial challenges, making the reliance on volunteers and generous sponsors even more critical to maintaining low ticket costs and upholding the BSides mission.

Key Findings

▶ Watch: Exploring the nine diverse BSides villages (4:50)

The "Closing Remarks" unveiled a series of impressive metrics and operational successes, effectively serving as the key findings for BSides SF 2026:

  • Record-Breaking Participation: The conference saw close to 3,000 participants, a significant increase of nearly 500 attendees from the previous year's 2,500. This represented a new attendance record, underscoring the growing appeal and relevance of BSides SF within the cybersecurity landscape.
  • Unprecedented Content Volume: A record 92 talks were delivered, comprising two keynotes, 86 traditional talks, and four panels. Additionally, 11 interactive sessions were hosted, including two podcasts, eight workshops, three Birds of a Feather (BoF) sessions, and four "Roast My Pitch" events. This diverse program offered a wide spectrum of learning and engagement opportunities.
  • Massive Call for Papers Engagement: The program team reviewed an astounding 602 talk submissions, an all-time high for BSides SF. This volume speaks to the conference's reputation as a premier platform for sharing cybersecurity research and insights. Notably, 18 individuals presented for the first time, reinforcing the conference's commitment to nurturing new talent.
  • Highly Engaged Capture the Flag (CTF) Competition: The CTF attracted 3,300 registered users and over 2,200 teams. More than 400 teams participated on-site, and over 600 teams successfully solved at least one puzzle. The competition culminated in a three-way tie for first place, ultimately decided by submission time, with Vera Labs, TJ CSC, and Squid Proxy Lovers taking the top spots. This high level of engagement highlights the CTF's success in providing practical, hands-on learning.
  • Diverse Village Offerings: Nine distinct villages were featured, including Adversary AI, Bug Bounty, Career, Cloud, Crypto and Privacy, IoT, Lock Pick, and Script Kitty. These specialized hubs provided focused learning and interaction opportunities, reflecting the broad interests within the security community.
  • Significant Charity Contributions: Through event t-shirt sales, over $4,000 was raised for three charities: Bard Theatre, EFF (Electronic Frontier Foundation), and Diana Initiative, demonstrating the community's philanthropic spirit.
  • Robust Network Infrastructure Performance: The conference's internet infrastructure, powered by a 1 Gigabit Google Fiber link, handled approximately 2 terabytes of downloaded data and 750 gigabytes of uploaded data. Over 1,800 total clients connected via 58 Aruba access points (donated by HPE), supporting 2.4, 5, and 6 GHz bands. A notable 35% of clients utilized PEAP, the most secure Wi-Fi offering, with the remaining 65% on WPA3, indicating a strong emphasis on network security.
  • Agile Incident Response for Network Stability: A critical operational finding was the real-time identification and resolution of connectivity issues for newer devices utilizing 6 GHz radios. The NOC team swiftly pushed a firmware update, addressing the problem live during the event and significantly improving network performance. This proactive incident response highlighted the team's expertise and dedication.
  • Massive Volunteer Effort: The event was supported by 235 different volunteers, who collectively covered over 400 shifts and contributed 1,901 human hours. This immense dedication is the backbone of BSides SF's success, with 16 volunteers receiving "Tiny Tony Awards" for exceptional service.

These findings collectively paint a picture of BSides SF 2026 as an exceptionally well-executed, community-driven conference that successfully scaled its operations and content offerings while maintaining its core values.

Technical Deep Dive

▶ Watch: Internet infrastructure and network usage statistics (6:00)

While "Closing Remarks" is not a traditional technical deep dive into a specific vulnerability or system architecture, it offered significant insights into the operational technical challenges and solutions deployed for a large-scale cybersecurity conference. The most prominent technical aspects revolved around the conference's network infrastructure and the real-time incident response capabilities of its NOC (Network Operations Center) team.

The backbone of BSides SF 2026's connectivity was a robust 1 Gigabit internet link provided by Google Fiber. This high-bandwidth connection is crucial for supporting thousands of attendees, presenters, and staff simultaneously, who are actively downloading slides, streaming content, and engaging in various online activities. Over the course of the event, this link facilitated approximately 2 terabytes of downloaded data and 750 gigabytes of uploaded data, demonstrating the heavy usage and the necessity of such a resilient backbone.

The wireless network infrastructure was equally critical. HPE Aruba generously donated 58 access points, strategically deployed throughout the venue. These access points were configured to support all three common Wi-Fi frequency bands: 2.4 GHz, 5 GHz, and the cutting-edge 6 GHz band. The inclusion of 6 GHz support was forward-thinking, aiming to leverage the increased bandwidth and reduced interference offered by Wi-Fi 6E (802.11ax) for compatible devices.

Client connectivity statistics revealed interesting trends and a strong emphasis on security. Out of over 1,800 total clients connected to the network, a significant 35% opted for PEAP (Protected Extensible Authentication Protocol). PEAP, often used in enterprise environments, provides robust authentication and encryption by creating a TLS tunnel to protect the inner authentication method (typically MSCHAPv2). This indicates a substantial portion of attendees prioritizing secure network access. The remaining 65% of clients connected via WPA3 (Wi-Fi Protected Access 3), the latest and most secure Wi-Fi security standard, offering enhanced encryption and protection against brute-force attacks compared to its WPA2 predecessor. This commitment to deploying and encouraging the use of advanced security protocols for attendee connectivity sets a high standard for conference network security.

A key technical challenge and a testament to the NOC team's capabilities arose early in the event. Newer devices equipped with 6 GHz radios experienced unexpected difficulty in establishing stable internet connections and obtaining a strong signal. This issue, likely related to nascent 6 GHz implementations or specific firmware configurations on either the access points or client devices, presented a real-world operational hurdle. The NOC team swiftly identified the problem through active monitoring and user reports. In a remarkable display of agile incident response, they pushed out a firmware update to the Aruba access points during the night. Loden noted, "doing it live, testing things live," highlighting the real-time, high-stakes nature of the fix. This update successfully resolved most of the connectivity issues, dramatically improving the network experience for 6 GHz clients on the second day. This incident underscores the importance of having a skilled and responsive network operations team capable of diagnosing and remediating complex technical issues under pressure.

Beyond the core network, the Capture the Flag (CTF) competition served as a major technical engagement. While the talk did not delve into the specifics of the challenges, the scale of participation—3,300 registered users and over 2,200 teams—indicates a significant technical infrastructure dedicated to hosting and managing the competition. CTFs typically involve a wide range of cybersecurity disciplines, including reverse engineering, web exploitation, binary exploitation, forensics, cryptography, and more, requiring a robust and secure platform to deliver the challenges and track scores.

Finally, the various Villages like Adversary AI, Cloud, Crypto and Privacy, and IoT represented specialized technical domains within the conference. While the "Closing Remarks" didn't detail their individual content, their existence signifies the breadth of technical topics explored at BSides SF, providing attendees with focused areas for deep dives into emerging and critical cybersecurity fields. The inclusion of new villages further indicates the conference's responsiveness to evolving technical landscapes.

Demo / Proof of Concept

▶ Watch: Real-time network issue resolution and firmware update (7:00)

This "Closing Remarks" session was a retrospective summary of the BSides San Francisco 2026 conference and, as such, did not include a live demonstration or proof of concept of a technical exploit, tool, or solution. Instead, the entire successful execution of the conference itself, with its record-breaking attendance, diverse content, and robust infrastructure, served as a "proof of concept" for large-scale, community-driven event management in the cybersecurity domain. The agility of the NOC team in resolving the 6 GHz Wi-Fi connectivity issue in real-time could be considered an operational "demo" of effective incident response under pressure.

Defensive Implications

▶ Watch: Appreciation for the 235 dedicated event volunteers (8:15)

While Reed Loden's talk was about conference logistics rather than a direct security vulnerability, several crucial defensive implications can be extracted from the operational successes and challenges highlighted:

  1. Prioritizing Secure Network Infrastructure: The deployment of PEAP and WPA3 on the conference network demonstrates a strong commitment to attendee security. For any organization or event planner, this highlights the necessity of offering and encouraging the use of modern, robust encryption and authentication protocols. Defenders should ensure their corporate and public networks are configured with the strongest available security standards, moving beyond outdated protocols like WPA2-PSK where possible, and educating users on the benefits of secure connection methods like PEAP.
  2. Agile Incident Response and Operational Resilience: The swift identification and resolution of the 6 GHz Wi-Fi connectivity issues by the NOC team is a prime example of effective incident response in a live, high-pressure environment. This underscores the critical importance of:
  • Proactive Monitoring: Having systems in place to detect anomalies and performance degradation in real-time.
  • Skilled Personnel: A competent team capable of diagnosing complex technical problems quickly.
  • Preparedness for the Unexpected: Recognizing that even with meticulous planning, unforeseen technical challenges can arise, especially with new technologies (like early 6 GHz implementations).
  • Rapid Remediation: The ability to push out fixes (e.g., firmware updates) efficiently and with minimal disruption.

Defenders should invest in these capabilities for their own environments, developing clear incident response plans and regularly testing their teams' ability to react to novel threats.

  1. The Value of Community and Knowledge Sharing: The sheer volume of talks, workshops, and villages (e.g., Adversary AI, Cloud, Crypto and Privacy) at BSides SF underscores the importance of continuous learning and community engagement for defenders. Staying current with emerging threats, techniques, and defensive strategies is paramount. Defenders should actively participate in and contribute to security communities, attend conferences, and leverage platforms that facilitate knowledge exchange to enhance their defensive posture.
  2. Volunteerism as a Force Multiplier: The reliance on 235 volunteers for nearly 2,000 human hours demonstrates the power of community in building and sustaining complex operations. In a defensive context, this translates to the value of internal collaboration, cross-training, and leveraging the diverse skills within a team or even external community resources (e.g., open-source projects, threat intelligence sharing groups). A strong, engaged team, much like the BSides volunteers, can significantly enhance an organization's defensive capabilities.
  3. Benchmarking and Continuous Improvement: The detailed metrics presented—attendance, talk submissions, CTF participation, network usage—provide valuable benchmarks. Defenders can apply this principle by continuously measuring their own security posture, incident response times, and program effectiveness. The commitment to reviewing feedback and striving to "make this better than last year" is a critical mindset for evolving defensive strategies against an ever-changing threat landscape.

In essence, while the talk wasn't about a specific hack, it showcased the operational security best practices, incident response capabilities, and community collaboration that are foundational to a strong defensive posture in the broader cybersecurity ecosystem.

Key Takeaways

  • BSides San Francisco 2026 was a record-breaking success, achieving unprecedented attendance of nearly 3,000 participants and featuring a record 92 talks and 11 interactive sessions.
  • The conference demonstrated a strong commitment to community engagement, evidenced by 602 talk submissions (a record), 18 first-time presenters, and a highly active Capture the Flag (CTF) competition with over 2,200 teams.
  • Operational resilience and agile incident response were critical, as the NOC team successfully identified and resolved unexpected 6 GHz Wi-Fi connectivity issues for newer devices in real-time through a firmware update.
  • The event prioritized secure networking, with 35% of clients utilizing PEAP and 65% connecting via WPA3, showcasing a commitment to modern authentication and encryption standards.
  • The conference's success was overwhelmingly driven by a massive volunteer effort, with 235 individuals contributing 1,901 human hours, underscoring the "by the community, for the community" ethos.
  • BSides SF continues to be a vital platform for knowledge exchange, skill development, and community building within the cybersecurity industry, raising over $4,000 for charities through t-shirt sales and providing diverse learning opportunities through its nine villages.

About the Speaker(s)

Reed Loden is a central figure in the organization of BSides San Francisco, serving as a key member of the event's core staff. His deep and long-standing involvement with the conference dates back to 2015, when he first became involved by managing the critical Call for Papers (CFP) process. This extensive experience has provided him with an intimate understanding of the intricate logistics, volunteer coordination, and community engagement required to run a major cybersecurity conference. As the presenter of the "Closing Remarks," Loden encapsulates the collective efforts and achievements of the BSides SF team, embodying the volunteer-driven spirit that defines the event. His role extends beyond a single task, highlighting his dedication to fostering an accessible and impactful platform for the cybersecurity community.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Closing remarks are closing remarks — this is a conference retrospective, not a talk, and grading it against a research submission would be absurd. Judged as what it actually is — a community event wrap-up — it does its job competently: real numbers, genuine appreciation, a nice operational anecdote about the NOC pushing a firmware fix live for 6 GHz issues. Nothing here that needed to be a video rather than a post-event blog, but it's honest and the speaker has the receipts.

Heather Calloway (CISO) — PASS

This is a conference closing ceremony, not a security talk. There is no threat research, no governance insight, no defender value — it is a thank-you speech with attendance metrics. Outside my lane entirely, and that is not a criticism of Reed Loden or BSides SF.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026