Peter Laakkonen has been walking the Black Hat floor for twenty years. This year he walked it wearing a Noir Dove badge instead of a vendor one, and that shift changed what he was looking for. Black Hat USA 2026 drew roughly 23,000 attendees across 460 exhibitors, up 15% from the prior year (Black Hat, August 2026). The growth was not the story. What the money was doing was. Several companies Peter had never heard of before walking past their booths had some of the largest, most expensive setups on the floor. One had fewer than 30 people and was still under $1M in revenue. Funded conviction dressed as market traction is common at this show. It is remarkably easy to mistake for product-market fit if you are watching from the wrong angle.

Summary
- Black Hat USA 2026 drew 23,000 attendees across 460 exhibitors, a 15% increase from 2025, with booth spend patterns that had no reliable correlation with company revenue or pipeline (Black Hat, August 2026).
- Pi Security, a San Francisco company with fewer than 30 employees and under $1M in revenue, built one of the floor’s most expensive booths after coming out of stealth days before the show, illustrating a structural shift in how capital arrives in the cybersecurity market (Peter Laakkonen, Noir Dove field observation, August 2026).
- The highest-attended session was OpenAI’s security engineers walking through a frontier model sandbox escape, confirming that agentic AI behavior has replaced CTEM as the dominant technical category, a shift that compressed inside six months between RSAC and Black Hat (Peter Laakkonen, Noir Dove field observation, August 2026).
- Cybersecurity founders at $1M to $10M in real revenue are being out-spent on visibility by companies with less traction, and the instinct to match that spend addresses the symptom while leaving the underlying commercial system problem untouched.
TLDR
At Black Hat USA 2026, money bought attention and rarely bought clarity. Several heavily funded companies with limited revenue ran the floor’s most elaborate booths, while vendors who actually cut through 460 exhibitors all saying the same thing about AI did so by saying something specific, not something louder. For cybersecurity founders at $1M to $10M in revenue, the floor made visible what is likely already limiting them: a commercial system that does not travel without the founder in the room.
A San Francisco Company Built an Igloo at Black Hat and Nobody Knew What They Did
Pi Security came out of stealth the week before the show. Fewer than 30 people. Still under $1M in revenue. Their booth looked like a creative take on the North Pole: snow sleds, an igloo, a snowman, no obvious connection to cybersecurity anywhere in the design. It was memorable. Whether it generated pipeline is a separate question, and that distinction is exactly where cybersecurity GTM breaks down for most founders between $1M and $10M.
Pi Security was not alone. Exaforce, past 100 employees, put up an equally prominent setup that almost no one on the floor recognized. One team threw a different party every night, opening bottles that retail around $1,500 and buying advertising space on the Sphere, the giant globe behind the MGM. Most people who saw that ad from the Strip almost certainly had no idea what the company did.
CrowdStrike did not have a booth this year, the first time Peter can remember. Their own annual event lands at the same resort a few weeks later. Their advertising still covered large stretches of casino resort walls and ran through the weekend after Thursday’s close. Saturday night on the Strip belongs to gamblers from LA, not security buyers.
The traditional read on a large Black Hat booth was straightforward: presence signals revenue and staying power. That signal has broken down. Capital is now arriving before recognition, not after it. For founders with real revenue and real customers, that shift rewrites the competitive context. The company with a fraction of your traction can now buy more floor attention than you, and spending to match them is the wrong response to the wrong diagnosis.

The Booths Were Theater. The Sessions Were the Signal.
Four hundred and sixty exhibitors, most of them saying some version of the same thing about AI and security. The real read on where the market is heading came from the sessions, and 2026 had a clear one.
The highest-attended panel was a breaking-news presentation from OpenAI’s security engineers walking through a frontier model sandbox escape. Rogue agentic AI behavior and how to contain it. That was the topic no one wanted to miss. A second thread ran across several other sessions: how security teams defend in an era where frontier models can discover vulnerabilities and generate working exploits almost instantly, with close to zero skill required from whoever launches the attack. Fighting AI-driven attacks increasingly means running AI-driven defense. That idea showed up in booth conversations as often as it did in keynotes.
OT and critical infrastructure security received serious attention, framed around a genuinely hard convergence: geopolitical tension, AI-accelerated attack tooling, and infrastructure still running on decades-old systems, all at once. Multiple sessions pushed past endless vulnerability lists toward business risk. Fewer people were talking about patching everything. More were asking which exposures actually threaten revenue and how to build software that does not create the exposure in the first place.
One category stood out by its absence. CTEM was everywhere on the RSAC floor in the first half of 2026. At Black Hat it barely appeared. The vendors pushing exposure management had mostly moved past the framework, pitching autonomous and agentic remediation instead. A category that dominated the market conversation in March had been superseded by a new framing by August. That compression rate matters for any founder building positioning in this space.

Qualys Brought a Cricket Player. Manage Engine Pressed T-Shirts. Both Worked Better Than the Igloo.
The vendors who cut through were not the biggest spenders. Qualys had their CEO interview a cricket player and commentator at their booth. An odd choice in a country where cricket barely registers, but it created a specific, unexpected reason to engage. People stopped. People asked questions. Manage Engine ran their standard 20×20 setup with a T-shirt press, doing exactly what they always do. Torq put up an inflatable so large Peter still cannot explain the internal decision that led to it.
None of these approaches share a playbook. What they share is a reason to stop that is more specific than “we do AI security.” Qualys generated conversation. Manage Engine generated familiarity. Torq generated curiosity. Each of those outcomes requires something concrete at the center of the commercial narrative, not a category claim.
The economics on the floor were visible. Money bought attention. It did not buy clarity. A company could spend $500,000 on a booth and leave with no one knowing what the company actually did. Pi Security’s igloo was memorable. The question is whether anyone remembered what Pi Security does, and those are two different outcomes with very different revenue implications.
The founders who stood out for the right reasons said something specific enough that the comparison to every other AI-security vendor became unfavorable on first contact. That specificity requires a commercial foundation: a diagnosed ICP, a tested narrative, a consistent message across every function that touches the buyer. You cannot buy that foundation at Black Hat, and no booth budget produces it.

What Cybersecurity Founders Between $1M and $10M Should Do with This
Peter stopped at the booth of a company that had come out of stealth and closed a Series A right before the show. He talked to their VP of Sales. A handful of paying customers, still under $1M in revenue, one of the fanciest setups on the floor. That is the uncomfortable part for founders sitting at $1M to $10M with real traction: you are being out-shouted by companies with less, and the instinct is to match the spend. Bigger booth. Louder party. More ad dollars.
That instinct treats a positioning problem as a budget problem. Those are different problems with different fixes.
If your sales team cannot close a deal without you in the room, that is a commercial system problem. If marketing is targeting practitioners while sales pitches security leaders, you have an ICP definition that was never formally agreed between the two functions. If pipeline fills but stalls in legal and procurement, your multi-stakeholder narrative is missing a layer for every buyer who is not the CISO. Gartner found that 70% of sales and marketing teams operate without a shared definition of their ideal customer (Gartner, B2B Buying Survey, 2024). At Black Hat 2026, that number was visible on the floor in both directions: in the booths that generated conversation and in the ones that generated impressions with no follow-through.
The question worth sitting with before writing the check for next year’s booth is not “how big should the booth be.” The question is whether the commercial system underneath the story is strong enough to compound when you put money behind it. If the story does not travel without you in the room, it will not travel with a larger booth either.

FAQs
Why did CTEM disappear from Black Hat 2026 after dominating RSAC earlier in the year? The category compressed faster than most vendors anticipated. By August, vendors pushing exposure management had already reframed their pitch around autonomous and agentic remediation, treating CTEM as a baseline assumption rather than a differentiating claim. Categories in cybersecurity collapse into assumed functionality quickly once the first wave of funded players establishes the vocabulary. The competitive conversation moved to what happens after exposures are identified, not whether to identify them.
How should a cybersecurity founder think about Black Hat presence if they are at $3M to $8M ARR? Presence is a commercial decision, not a visibility decision. Founders who extracted real value from this floor had specific anchors: named prospect meetings, channel partner conversations, or a speaking slot that established a point of view. A booth without those anchors produces impressions. Whether impressions convert into pipeline depends entirely on whether the commercial motion behind the booth can handle the attention. For a company at $3M to $8M, the return on a $200,000 booth is determined before the show, not at it.
What does it mean practically that capital is now arriving before recognition in cybersecurity? It means the booth-size heuristic has broken down as a buyer signal. A large presence used to indicate a company worth investigating. That is no longer reliable. For buyers, more screening is required before a conversation. For founders at $1M to $10M with real revenue, it means their competitive context now includes companies that are well-funded but pre-revenue, and distinguishing themselves requires a narrative specific enough that the comparison becomes unfavorable to the funded-but-unproven competitor on first contact.
If the commercial system is the real constraint, where does a cybersecurity founder start? Start with the diagnosis, not the fix. The most common error is treating a symptom as a root cause. CISOs going quiet after the first call is a symptom. Marketing generating MQLs that sales does not recognize as buyers is a symptom. The founder still closing most deals personally is a symptom. Each of those symptoms can point to a different structural cause, and the right fix depends on which cause is actually producing the symptom. Spending on a larger booth, a new campaign, or a new rep before that root cause is identified accelerates activity in the wrong direction.
Sources Referenced
- Black Hat USA 2026, Official Attendance and Exhibitor Data, August 2026 (23,000 attendees, 460 exhibitors, 15% year-over-year attendance growth)
- Peter Laakkonen, Cybersecurity Advisor, Noir Dove, Field Observation Notes from Black Hat USA 2026, August 2026 (Pi Security booth, Exaforce, party and Sphere spend, CrowdStrike wall advertising, Qualys cricket interview, Manage Engine setup, Torq inflatable, OpenAI frontier model sandbox escape session, CTEM absence)
- Gartner, B2B Buying Survey, 2024 (70% of sales and marketing teams operate without a shared ideal customer definition)
Talk to Noir Dove
If your pipeline is inconsistent and your commercial narrative does not hold without you in the room, the Black Hat floor made visible what is likely already costing you deals. Check our cybersecurity solution.
The diagnostic starts with what is structurally limiting your story, not with what you should spend next year.

