Conference Description
Key Takeaways
- ROOTCON 20 marks two decades of the Philippines’ premier hacking and information security conference
- Technical focus spans IoT security, ICS/SCADA systems, AI and LLM vulnerabilities, SDR/RF hacking, and wireless exploitation
- Designed for security researchers, penetration testers, engineers, developers, and technology decision-makers
- Hands-on villages and workshops emphasise practical skill development over theoretical discussion
- Addresses the growing convergence of operational technology security, artificial intelligence risks, and traditional network defence
Introduction
ROOTCON 20 returns to Clark, Philippines, celebrating twenty years as one of Southeast Asia’s longest-running cybersecurity gatherings. The conference brings together hackers, security researchers, and technology professionals for an intensive programme of technical sessions, interactive workshops, and community-driven activities. This year’s event arrives at a moment when organisations face mounting pressure from sophisticated threat actors targeting everything from cloud infrastructure to industrial control systems, making the conference’s emphasis on practical, hands-on security knowledge particularly timely.
About ROOTCON 20
Held at the Royce Hotel & Casino in Clark, ROOTCON maintains its reputation as a technically rigorous event that prioritises direct engagement over passive observation. The conference format includes keynote presentations, technical sessions, and specialised villages where attendees work directly with hardware, software, and wireless systems. Contests and after-hours activities extend the learning environment beyond formal sessions, fostering the collaborative atmosphere that has defined the event since its inception.
The conference philosophy centres on building, breaking, experimenting, and teaching. This approach reflects the broader hacker ethos of understanding systems through direct interaction rather than abstract study. ROOTCON positions itself as a gathering where community contribution takes precedence, welcoming research and discussion on any topic relevant to information security practitioners.
Technical Focus Areas
The programme addresses several interconnected domains within contemporary cybersecurity practice. IoT security and embedded systems feature prominently, reflecting the proliferation of connected devices across consumer, enterprise, and industrial environments. These systems often ship with minimal security controls and receive infrequent updates, creating persistent vulnerabilities that researchers continue to document.
ICS/SCADA security represents another significant thread, addressing the protection of industrial control systems that manage critical infrastructure including power generation, water treatment, and manufacturing processes. The convergence of operational technology with traditional IT networks has expanded the attack surface for these systems considerably.
The inclusion of AI and LLM security acknowledges the rapid deployment of machine learning systems across enterprise environments. Security researchers are increasingly examining how these models can be manipulated through prompt injection, training data poisoning, and adversarial inputs. As organisations integrate large language models into customer-facing applications and internal workflows, understanding their failure modes becomes operationally essential.
SDR and RF hacking sessions explore software-defined radio techniques for analysing and interacting with wireless protocols beyond conventional Wi-Fi. This discipline encompasses everything from automotive key fobs to satellite communications, requiring specialised hardware knowledge alongside signal processing expertise. Related wireless security content addresses the ongoing challenges of securing Wi-Fi networks against evolving attack methodologies.
Biohacking and experimental technology sessions push into less conventional territory, examining the security implications of implantable devices and human-computer interfaces.
Bridging Offensive and Defensive Practice
ROOTCON maintains a deliberate balance between offensive and defensive security perspectives. This dual focus recognises that effective defence requires understanding attacker methodologies, while responsible offensive research depends on awareness of defensive constraints and real-world operational requirements. The conference provides a venue where penetration testers, red team operators, security engineers, and incident responders can exchange knowledge across these traditionally separated disciplines.
Who Should Attend
The conference serves security researchers seeking to present or encounter new vulnerability research, penetration testers looking to expand their technical repertoire, and security engineers responsible for defending enterprise environments. Developers with security responsibilities benefit from exposure to offensive techniques that inform more resilient software design. Students and educators find opportunities to connect with practitioners and observe current industry practice. Technology executives and security decision-makers gain insight into emerging threats and the practical realities of security operations.
Organisations across technology, financial services, critical infrastructure, and academic sectors are represented among typical attendees, reflecting the cross-industry relevance of information security challenges.
Community-Driven Security Education
Twenty years of continuous operation demonstrates ROOTCON’s sustained relevance within the regional security community. The conference has served as a platform for emerging researchers while honouring established contributors to the field. Its longevity reflects an approach that prioritises genuine technical content and community value over commercial considerations, maintaining the event’s credibility among practitioners who remain sceptical of purely vendor-driven security messaging.

