A few years ago, at RSA, one of the organizers said something to me after I asked how RSA (and other conferences in our space) markets to nonprofits. I still haven't shaken it: "Nonprofits aren't the target audience. They can't afford the ticket to attend."
I didn't argue. I couldn't. But how did we know it was true? What made it true for all? (Lumping nonprofits together as if they're all the same is a topic for another time.) Still, that view was in some respects true, and it still is. A Black Hat Briefings pass alone runs somewhere north of $2,000. That's before travel, before the hotel, before the days a small staff has to be away from the mission to justify being in the room, in cities where hotel prices are just as steep.
But it's the other half of that memory that's stuck with me longer. Before I started Sightline, I had lunch with a local nonprofit's CISO. Yes, they had a CISO, which already put them ahead of most of the sector. I asked what he thought of the big conferences. "I like Black Hat, I like RSA," he said. "But they don't know us. They don't know how our business operates. So how can I justify going when no one will see us?"
Hacker Summer Camp (Black Hat, DEF CON, and BSidesLV) all closed up shop in Vegas for another year. And I'm sitting with the same question I had at that lunch table: why, all these years later, are nonprofits, small government agencies, and the organizations serving the most vulnerable among us still standing outside the room?
The math doesn't add up
Here's the part that should stop the industry cold. The nonprofit sector generates somewhere between $1.4 and $1.5 trillion in economic activity every year, roughly 5.2 to 5.6 percent of U.S. GDP. That's not a rounding error. That's a sector the size of a G20 economy and, as I've written before, not one story but thousands of them, each with its own risk profile and none of them interchangeable.
These are organizations holding some of the most sensitive data that exists, often with a staff of five and an IT budget measured in the hundreds, not the millions. And the events where the industry sets its agenda, sells its tools, and decides what "risk" means for the next year largely aren't built with them in the room.
Yes, there are security nonprofits present at these events, and that matters. But a handful of booths and a few scholarship badges is not the same as being seen as a buyer, a peer, or a business sector worth designing for.
This isn't really about the ticket price
I get why "they can't afford it" gets said out loud. It's the easy, defensible answer. But cost is the symptom, not the disease. RSA runs RSAC Gives Back and offers passes through partners like WiCyS and the Global Cyber Alliance. Programs like that exist. They help. They are not the same as the industry understanding nonprofits as a distinct, definable market with its own risk profile, buying cycle, and constraints, which is the thing that CISO at lunch was actually telling me.
You can hand someone a free badge and still not know how their business runs. Access without understanding just gets you a nonprofit standing quietly at the edge of a Business Hall built for a different kind of buyer.
So what would actually change this?
I don't think the fix is another scholarship program, though those are worth keeping. I think it starts with three harder questions, aimed at three different rooms.
To the conference organizers: are you willing to build a track, a pass tier, or even a single day that's designed around how a nonprofit actually operates (e.g., its budget cycle, its board, its volunteer workforce, its mission-first focus) rather than retrofitting a discount onto a program built for enterprise buyers?
To the vendor community: are you willing to see a $1.4 trillion sector as a market instead of a donation line item? Free licenses and CSR budgets are generous. They are not the same as product roadmaps that account for how a nonprofit actually buys, staffs, and sustains security.
To the rest of us in this community: are we willing to keep showing up in these rooms and saying the sector's name out loud, year after year, until it's uncomfortable not to?
Black Hat, DEF CON, and BSidesLV have wrapped for another year, and the broader 2026 conference season is winding toward its close. I'd like the next lunch conversation with a nonprofit CISO to end differently.
What would it take for your organization, or your event, to actually get to know this sector, not just make room for it?