State of Security Vendors: CYBR.SEC.CON 2026

Full report in text follows….


Key Takeaways

You might be forgiven if you thought that CYBR.SEC.CON was an AI conference: just over 50% of booths mentioned AI or agents. Despite its size at 3000 attendees and 173 exhibitors, CYBR.SEC.CON is still a regional conference. What does that mean? Exhibitors are tilted more towards “All-in-one” solutions (MDR, Consulting, Platforms, VARs) and away from management (compliance, TPRM) and development (HW/SW enablement, AI safety) support solutions.

With CYBR.SEC.CON in Houston, OT is a big discipline. In addition to having its own track (OT.SEC.CON), there were ten OT exhibitors (matching RSAC’s ten, but with only two overlapping).

Exhibitors tend to have smaller, more muted displays, as well. Fewer claims of being “first”, “best”, or “only”, (only 4 of those), with the only truly bold statement being Dragos’s “Safeguarding Civilization,” which still remains the best tagline in cybersecurity.

Notable and Niche Keywords
● AI (61 booths)
● Agent/agentic (21)
● Enterprise (7)
● Exposure (4)
● Platform (20)
● Risk (13)
● SOC/SecOps/Sec Ops (10)
● Zero Trust (4)

Entirely lost

37 booths (1 in 5) have “No Clue” messaging, that doesn’t reveal to a passerby in a moment what space the exhibitor is in. These come in four categories:
Big brands, vague messaging. Companies like Cisco (“Innovating for a new era of security”) who often have too many products to want to define themselves narrowly.
Beautiful design. You don’t see many of these at a smaller exhibit hall (even Wiz’s booth, usually the epitome of “all design, no messaging”, was focused on delivering a message here). There were only four themed booths, even counting Bloom bringing flower pots to decorate their kiosk), and only Auguria’s hit the combination of “beautifully eye-catching” and “doesn’t easily tell you what we do.”
Vague or misleading messaging. Over-engineered slogans (think GE’s “We bring good things to life”) which might be great at the end of a commercial, but tell a passerby nothing about the company. Alternately, some just toss out buzzwords that take you in the wrong direction.
No messaging. Too many booths had no words at all on display. If you’re a startup, you can often at least put something up on your kiosk; take advantage of the opportunity.

Methodology

This report is built based on observations made, in person, looking at each of the 173 exhibitor booths on the CYBR.SEC.CON 2026 show floor. This took about 5 hours, with each booth being observed, while major visible taglines, branding, and important keywords recorded via dictation on an iPhone directly into a spreadsheet. That spreadsheet had been prepopulated with the exhibitor list.

Each booth was quickly assessed in real-time to answer very specific questions:
● Did I understand what the company did, based on the booth alone?
● Was the booth strongly themed?
● Was the company messaging overly bold (“we’re the first!”) or overly aggressive (“CISOs don’t know anything!”)?
● How did the company handle the Oxford comma?

The taglines were checked against my existing dataset from previous conferences, the vendors websites, or conversations with the booth staff, so that I could categorize what the vendor actually did (not just “AI”).

What I didn’t collect? The taglines from all the non-exhibitors. There weren’t as many alternate venues for vendors as you see at global conferences.

Consuming Booths
Conference booths serve very different purposes, with vastly different observers, and these purposes are sometimes in conflict. In vaguely priority order (from the buyer perspective) these are:

  1. Provide an educational experience for a practitioner to learn more about a security problem, a vendor’s approach to it, and gain familiarity with the product.
  2. Enhance or establish brand awareness to security decision makers.
  3. Demonstrate to VCs the viability and velocity of a company in anticipation of its next round.
  4. Collect badge scans, as a (poor) proxy for leads.

But this report is not a product or CISO view of the security market. Rather, it’s a marketing perspective: how do event marketers implicitly see the cybersecurity landscape, and their role in it? What do they think that security buyers are looking for and buying?

There’s a further nuance to this view. Event marketers often have a very perverse incentive. Common marketing practices drive to maximize the number of touches that a company has with security practitioners, whether or not a practitioner is in market now, or will ever be. This drive is motivated partly by the battle over revenue attribution, and partly over the lead generation model of maximizing leads of any quality, and filtering via fairly cold outreach to those leads. As a result, exhibition floors often have a Halloween feel to them, with attendees trading their contact information in exchange for some piece of marketing shwag.

As a result, so many booths seem to be nothing more than beautiful bait, luring in the unsuspecting attendees until they can be hooked into coughing up their personal details. At the other end of the spectrum, some booths are simply a product sheet, listing every feature in a company’s product. Any demographic analysis covering both ends of that spectrum will have some infelicities.

Finding Booths
CYBR.SEC.CON had one of the easiest layouts to navigate, with booths having both a number (hundreds was the left-to-right index, and the tens/one place was the down-to-up index) and a street name (all walking paths had a giant overhead street name with a Houston-relevant name (NASA Parkway, H Town Hwy)). This gave booths both an algorithmically-parseable and a human-friendly address.

Unlike most conferences, the startup kiosks didn’t face internally into a startup area; instead, a small lounge with chairs was surrounded by outward-facing small booths.

Booth Overview


The Continued Dominance of AI and Agents
Only 50% of booths mentioned AI or agents–a factoid that surprised everyone I mentioned it to. Some of that was highly concentrated, though: every Data security company but one either mentioned AI or agents (or had no visible messaging). Meanwhile, all but two of the all-in-one/VAR/consulting exhibitors completely skipped out on AI messaging.

Hidden Words
While larger conferences have a plethora of 20’x20’ (or larger) booths open to all sides, only 6 booths at CYBR.SEC.CON were that large. The vast majority were 10’x10’ booths, with a score of 10’x20’ booths, as well as the few dozen innovation kiosks. These all have a clear “front” and “back”, and exhibitors generally used portable stand-up displays or some form of printed booth backdrop (with a few, like Huntress and 7AI, having a fully built-out booth).

Many of these displays and backdrops seem to have been conceived on a monitor, without considering the effect of having a human in front of them working the booth. Eighteen–10% of the exhibitors–had key words occluded by humans, while there was empty space above the humans’ heads.

The Oxford Comma
7 out of 13 booths correctly used the Oxford comma in their displays. Increasingly, exhibitors seem to be shifting away from sentence-based lists, and just displaying keywords or phrases outside of sentences entirely, therefore obviating this argument entirely.

Booth Behaviors


More respectful staff
. At larger conferences, booth staff are aggressive in their badge-scanning desires, and even conversation starters feel like ploys to just get a scan. Booth staff at CYBR.SEC.CON had more genuine interactions, commenting on my shoes without immediately pivoting to a pitch, or making eye contact, not seeing interest, and turning away.

Unstaffed booths. With most booths minimally staffed, especially in the innovator area, you’d occasionally find an empty booth. Usually, this was triggered by the one staffer either having a speaking slot, or needing a bio break, but a few booths appeared to have had exhibitor staff tear down their booth early–something noticed and commented on by attendees and conference staff alike.

Category Breakdown

You might look at that chart above and notice that it doesn’t seem to match up to normal industry breakdowns. The guiding principle for this categorization is based on the environment that the solution targets.

AI (6)
This is predominantly for AI governance and observability solutions, with a tiny dose of AI safety companies. If a vendor is using AI to do anything that isn’t “govern other AI use,” they’ll appear in a different (and relevant) category. This category includes the former SaaS security vendors, who have generally pivoted to be AI security. Smaller conference effect: fewer exhibitors in software or governance spaces.
AI Governance: 5
AI Safety: 1

All In One (25)
The All-in-One category is for vendors that are basically “outsource a big chunk of your security to us”, either as a managed service (generally, an MDR), as a comprehensive platform, or by providing consulting services. Consulting services is included here because this is more about delivering your own security rather than your own product. Smaller conference effect: more exhibitors.
Managed Service: 7
Comprehensive Platform: 8
Consulting: 10

Applications (9)
Applications now covers only traditional AppSec services. AppSec itself is already a fairly wide category, including software supply chain, application testing, and runtime security. Penetration Testing vendors whose messaging aims at the SDLC land here; others land in Governance. This grouping is not further broken down. Smaller conference effect: fewer exhibitors in software or governance spaces.


Cloud (8)
Traditional CSPM/CNAPP vendors fall into this category, as well as cloud configuration and management tools. Cloud security seems to be fairly robust against AI marketing (they’re all using AI, and discussing AI, but generally still are clearly targeting “secure the cloud.” This grouping is not further broken down.

Data (11)
From DSPM to DLP, with sides of encryption and backup/recovery, data security solutions are often found across varied environments, but with a clear focus on data as it lives in or passes through those environments. Data security vendors often have a hard challenge differentiating themselves from Application Security focused vendors. Tools focusing on protecting data from AI get included here. This grouping is not further broken down.

Enablement (12)
Scattered across the show floor you’ll find Hardware and Software vendors to incorporate into your own products. You’ll also find a handful of Workforce Development vendors, either helping you find staff, or training your existing staff. Smaller conference effect: fewer exhibitors in software or governance spaces.
Software: 11
Hardware: 1
Workforce Development: 10

Governance (19)
Governance includes not only the traditional Compliance Management and Third Party Risk Management spaces, but has also been expanded to include Continuous Threat & Exposure Management (CTEM), Unified Threat Intelligence, and Offensive Security as well. All of these are knowledge disciplines, enabling a buyer to understand their risk profile. Smaller conference effect: fewer exhibitors in software or governance spaces.
CTEM: 8
GRC: 0
Asset: 2
TPRM: 0
Offensive Security/Threat Intelligence: 9


Humans (19)
Core to any environment are the endpoints, but EDRs alone are ineffective enough that we have an entire Human Risk Management space. HRM includes both technical controls like email filtering as well as security awareness training.
Endpoint Security: 8
Human: 11

Identity (22)
The long-running challenges of Identity have exploded with the rise of agents using humans’ identities. Spanning IAM, IGA, MFA, ITDR, as well as non-human identities, this space continues to grow, since the “I” in “AI” certainly doesn’t stand for Identity. This category is not further broken down.

Networks (10)
A triple space, Networks includes traditional NDR, as well as SASE, ZTNA, and Web Security. Web application firewalls, bot management, and fraud management tend to end up here as part of the Web Security space. This category is not further broken down.

OT (10)
There are a small handful of exhibitors focused directly on the OT, ICS (or CPS), and IoT worlds. This category is not further broken down. Regional conference effect: more exhibitors in a space relevant to the region.

Operations (22)
Whether you’re providing a data pipeline, a SIEM, Security Operations/Automation, or Detection Engineering And Threat Hunting, Operations comes in third with the most exhibitors. The AI SOC is probably the hottest “let AI take over a security job” space.
Detection Engineering & Threat Hunting: 2
SIEM: 7
Security Operations and Automation: 13

About Us
Duha is a boutique consultancy that provides a spark of genius at the intersection of cybersecurity, leadership, product, and messaging, led by legendary CISO Andy Ellis. Duha advises CISOs, CMOs, CROs, and other executives on improving themselves and their teams. Interested in engaging Andy for a workshop on Cultivating CISOs for your SDRs and field marketers, a conversation about your messaging, or with a leadership keynote for your next event? Contact andy@duha.co.

Posted in

Andy Ellis

CEO. A visionary technology and business executive with deep expertise in security, managing risk, and leading an inclusive culture.