Conference Description
Key Takeaways
- International cybersecurity conference using the Open Space format for participant-driven agenda creation
- Topics span secure software lifecycle, penetration testing, red teaming, cloud security, compliance and risk management
- Designed for professionals at all experience levels, from students to CISOs
- Emphasis on breaking down industry gatekeeping and fostering inclusive knowledge sharing
- In-person event held at SeminarZentrum Rückersbach, Germany
A Community-Driven Approach to Cybersecurity Learning
The Open Security Conference, known as osco, is an international cybersecurity event that takes a distinctly different approach to professional gatherings in the security field. Rather than following the conventional conference model of pre-scheduled presentations and expert panels, osco employs the Open Space format, allowing attendees to collectively shape the agenda onsite. This participant-driven methodology reflects a broader movement within the cybersecurity community to make knowledge sharing more accessible and less hierarchical.
The conference addresses a persistent challenge in the security industry: the barriers that often prevent professionals from engaging meaningfully with their peers and advancing their expertise. Traditional conferences can inadvertently reinforce gatekeeping through exclusive speaker lineups and rigid programming. Osco positions itself as an alternative by creating space for serendipitous conversations and hands-on collaboration, regardless of an attendee’s seniority or formal credentials.
Technical Focus Areas
While the agenda remains flexible by design, osco centres on several core cybersecurity disciplines. The secure software lifecycle features prominently, reflecting the industry’s ongoing shift toward integrating security practices throughout development rather than treating them as an afterthought. Penetration testing and red teaming sessions provide opportunities for practitioners to share offensive security techniques and defensive countermeasures.
Network and cloud infrastructure security discussions address the operational realities facing organisations as they manage increasingly distributed environments. Continuous compliance has emerged as a significant topic area, acknowledging the regulatory pressures that security teams navigate alongside their technical responsibilities. Risk management and threat mitigation round out the technical programme, connecting tactical security work to broader organisational strategy.
Notably, usability and accessibility in security receives dedicated attention. This focus recognises that security controls only prove effective when users can actually work with them, a consideration that often receives insufficient attention in purely technical forums.
The Open Space Format in Practice
The Open Space methodology that underpins osco originated in organisational development contexts and has found application in technology communities seeking more dynamic knowledge exchange. Participants propose session topics at the start of the event, then self-organise into discussion groups based on genuine interest rather than predetermined tracks. This structure encourages practitioners to bring real-world challenges they are actively working through, rather than polished presentations of solved problems.
The format suits cybersecurity particularly well given the field’s rapid evolution. Threat landscapes shift faster than traditional conference planning cycles can accommodate, making participant-driven agendas more responsive to current concerns.
Who Benefits from Attending
Osco welcomes a broad cross-section of the cybersecurity community. Security engineers and consultants can exchange practical techniques with peers facing similar operational challenges. Developers gain exposure to security considerations that affect their daily work. CISOs and security leaders find value in understanding emerging threats and community perspectives outside their immediate organisational context.
The conference explicitly welcomes students and those newer to the field, recognising that cybersecurity’s talent shortage requires more accessible pathways into the profession. Professionals from adjacent disciplines including IT operations, compliance and risk management also find relevant content, reflecting the increasingly cross-functional nature of security work.
Building Professional Networks Beyond Formal Sessions
Beyond technical content, osco emphasises relationship building within the security community. The in-person format at SeminarZentrum Rückersbach in Germany creates conditions for the informal exchanges that often prove most valuable at professional gatherings. For practitioners who work in isolation within their organisations or operate as independent consultants, such networking opportunities provide essential connection to the broader professional community.

