Conference Description
Key Takeaways
- Annual conference dedicated exclusively to defensive cybersecurity practitioners and blue team professionals
- Four-day programme featuring technical talks, hands-on trainings, Capture the Flag competitions, and specialised villages
- Designed for security analysts, incident responders, SOC staff, security engineers, and CISOs across enterprise, government, and critical infrastructure sectors
- Addresses skills gaps in threat detection, incident response, and security operations
- Continuing Professional Education credits available for eligible sessions
Introduction
Blue Team Con is an annual information security conference focused exclusively on cybersecurity defenders—the professionals responsible for protecting organisations from increasingly sophisticated cyber threats. Held in Chicago, the event brings together security analysts, incident responders, and security operations centre staff for four days of technical education, hands-on training, and professional networking. As organisations face mounting pressure from ransomware, supply chain attacks, and advanced persistent threats, events dedicated to defensive security have become essential forums for practitioners seeking to sharpen their skills and share operational knowledge.
About Blue Team Con
Blue Team Con positions itself as a community-driven gathering rather than a vendor-dominated trade show. The conference attracts over 850 attendees annually and emphasises education, collaboration, and relationship-building among defensive security professionals. The organisers have cultivated an environment intended to be inclusive and welcoming, recognising that effective cybersecurity defence requires diverse perspectives and open knowledge sharing.
The event takes place at Swissôtel Chicago and spans four days of programming. Participants can earn Continuing Professional Education credits for attending talks and completing training sessions, supporting the certification maintenance requirements common among security professionals holding credentials such as CISSP, CISM, or GIAC certifications.
Defensive Security Topics and Training Formats
The conference programme centres on the practical realities of organisational defence. Core subject areas include incident response methodologies, threat detection techniques, security operations workflows, and blue team tactics. Unlike conferences that blend offensive and defensive content, Blue Team Con maintains a deliberate focus on protection, detection, and response—the daily concerns of security operations teams.
Programming formats extend beyond traditional presentations. Hands-on labs provide opportunities to work directly with defensive tools and techniques in controlled environments. Capture the Flag competitions allow participants to test their skills against realistic scenarios. Specialised villages offer deep dives into specific defensive disciplines, enabling attendees to explore particular areas of interest with subject matter experts and peers facing similar operational challenges.
The Growing Importance of Defensive Security Expertise
The cybersecurity industry has historically allocated significant attention and resources to offensive security research, penetration testing, and red team operations. While these disciplines remain valuable, organisations increasingly recognise that defensive capabilities determine whether attacks succeed or fail in practice. Security operations centres must process vast quantities of telemetry, distinguish genuine threats from false positives, and coordinate rapid response when incidents occur.
This operational reality has created persistent demand for skilled defenders. Many organisations struggle to recruit and retain qualified SOC analysts and incident responders, while existing staff face burnout from alert fatigue and the relentless pace of threat evolution. Conferences focused specifically on defensive security provide practitioners with opportunities to learn from peers, discover emerging techniques, and reconnect with the broader purpose of their work.
Who Should Attend
Blue Team Con serves a broad spectrum of defensive security professionals. Security analysts and SOC staff will find technical content directly applicable to their daily responsibilities. Incident responders can explore advanced techniques and compare approaches with practitioners from other organisations. Security engineers responsible for building and maintaining defensive infrastructure will encounter relevant tools and architectural discussions.
The conference also attracts CISOs and security leaders seeking to understand the operational challenges their teams face and identify training opportunities. IT professionals transitioning into security roles may find the event valuable for building foundational knowledge and professional connections. Attendees represent diverse sectors including enterprise, government, education, and critical infrastructure, reflecting the universal need for effective cyber defence.
Vendor and Sponsor Participation
The conference includes participation from security vendors and service providers. Sponsors supporting the event include organisations such as Picus, OffSec, Gravwell, Acalvio Technologies, Greynoise, Flare, ThreatLocker, and Black Hills InfoSec, among others. This vendor presence provides attendees with exposure to defensive security products and services, though the conference maintains its educational and community-building focus as the primary draw.

