Skip to content

BSides Houston Takeaway: The Next Generation Has Got This

BSides Houston offered a powerful reminder that the next generation has the brains, passion and enthusiasm to tackle cybersecurity's biggest challenges.

There are days when I look at the state of the world and wonder whether we have a fighting chance to preserve civilization. Cyberattacks against critical infrastructure, artificial intelligence advancing faster than our ability to secure it, geopolitical instability, and a seemingly endless supply of people determined to tear things down.

But there are also plenty of people determined to build things up, protect what matters and leave the world better than they found it.

And after spending a day at BSides Houston, I came away feeling a hell of a lot more confident that the next generation has the brains and passion to give us a fighting chance.

The event took place at the Houston Food Bank, itself an impressive example of community coming together for the common good. Inside that building, another community had gathered around a different mission: sharing knowledge, building skills and getting the next generation ready to tackle the cybersecurity challenges of the next 20 years.

Small rooms, big enthusiasm

BSides Houston was a sharp change of pace after two action-packed days of CYBR.SEC.CON. 2026 with my colleagues at CYBR.SEC.Community.

Our conference was a tremendous success, and I'm still riding the high of everything we accomplished. But for those of us working it, those two days were intense. By the time we wrapped up, my brain had been pounded into a fine powder.

A satisfying stupor after a hard job well done, but a stupor nonetheless.

Then came BSides Houston.

Unlike the much larger BSides gatherings in Las Vegas and San Francisco, this was stripped back to the basics with a couple of rooms: one for talks and another for everything else, including meals, sponsor tables and the conversations that make these gatherings worthwhile.

It felt like a small gathering of old friends and young people eager to learn from them. Which, of course, it was.

The bigger BSides events have that same sense of community. But the small size of BSides Houston brought it into sharper focus for me.

You could see the connections happening. Experienced security practitioners sharing what they had learned. Younger attendees absorbing every bit of knowledge they could get their hands on. People gathering around tables, asking questions and finding common ground.

The people were the attraction.

And one presentation, in particular, reminded me why that matters so much.

Related:

The Kids Would Be Alright -- If Cybersecurity Would Stop Failing Them
Fergus Hay argues that cybersecurity isn’t facing a talent shortage: it’s failing to recognize that the next generation of hackers is already here, hiding in plain sight inside gaming culture.
Every 3-Year-Old Is a Hacker: Jayson Street on Curiosity, Community, and Hacker Culture
Jayson Street explains why hacking starts with curiosity, why community matters, and how hacker culture extends beyond computers.

We tricked rocks into thinking. How cool is that?

The presentation was called "The Power of Abstraction: Tricking Sand into Doing Math," delivered by Ragul Balaji, VS.

I'll confess right up front that much of it went straight over my bald head.

Part of that was the subject matter. Balaji took the audience deep into the inner workings of computers, starting with NAND gates and building his way up through multiplexers, flip-flops, registers and arithmetic logic units.

He walked through how those components can be assembled into a functioning CPU, complete with an instruction set and the ability to execute programs.

And he wasn't simply describing the theory. He had actually built this stuff.

Balaji designed RISC-style instruction set architectures, implemented them on field-programmable gate arrays, built memory-mapped input/output and a simple text-mode GPU, and created emulators and an assembler for his machines.

He even developed a RISC-V translator to get a C compiler running on his custom architecture.

Then he turned the discussion toward cybersecurity, showing how the abstractions that make modern computing possible can also conceal assumptions that attackers exploit. Using a deliberately vulnerable C program, he traced a buffer overflow through the compiler and down into machine instructions, registers and stack memory.

Balaji moved through his detailed, step-by-step slides with a huge smile on his face, certain in his conviction that this was the absolute coolest thing he had ever been involved with. And he wanted everyone else to delight in it.

His enthusiasm was infectious. He was hungry, eager to share what he knew and certain that his findings would contribute to a better future.

One line from his presentation abstract captures that spirit perfectly:

"We somehow tricked rocks into thinking. I wanted to understand how, so I built one myself."

He wanted to understand something, so he built it. Not because somebody told him to. Not because it was a requirement for a certification or a box to check on a performance review. He did it because he was fascinated by the technology and wanted to understand it at a deeper level.

Judging by the faces in the room, he wasn't alone.

The next generation is already stepping up

As Balaji worked through his presentation, I found myself watching the audience almost as much as I watched him.

People were genuinely fascinated by the topic and level of technical detail. They were following along, absorbing the information and engaging with the ideas.

It was the kind of moment that takes a jaded middle-ager like me and injects me with renewed hope that there may actually be a future worth living in.

Here was a gathering of people who weren't simply interested in getting a job in cybersecurity. They wanted to understand how technology works, how it breaks and how they might make it better.

Our industry spends an enormous amount of time talking about the cybersecurity workforce shortage. We debate which skills are missing, which certifications matter and how artificial intelligence will reshape the jobs of tomorrow.

Those are important conversations. But sometimes we get so wrapped up in workforce statistics, technology investments and the latest existential threat that we lose sight of the people who will ultimately determine where this industry goes.

The people who are curious enough to take things apart. Who refuse to accept that something is too complicated to understand. Who spend countless hours building something simply because they want to know whether they can.

The people who light up when they discover something new and can't wait to tell everyone about it.

Those are the people who will tackle the cybersecurity challenges of the next 20 years.

They'll be the ones figuring out how to defend systems we haven't even invented yet. They'll discover vulnerabilities in technologies that today's security leaders are only beginning to understand.

But first, they need places where their curiosity can flourish. They need experienced practitioners willing to share what they know and opportunities to experiment, ask questions, make mistakes and learn from them.

That's what I saw at BSides Houston.

I can't wait for the next one.

Latest