
By George G. McBride | September 27, 2026
The Call for Submissions for the RSAC 2027 Conference is now open, and the window is short: proposals are due Friday, October 9, 2026, at 11:59 PM PT. If you have been thinking about submitting a talk, now is the time to get it written.
After RSA 2026, where artificial intelligence showed up in nearly every corner of the agenda, I would love to see some non-AI Content!!!! : please consider submitting a talk that is not about AI.
The Key Facts
- Conference: RSAC 2027 Conference, April 5–8, 2027, San Francisco.
- Submission deadline: Friday, October 9, 2026, 11:59 PM PT (for Track Sessions and Learning Labs).
- Formats: Track Sessions are 50 minutes including Q&A (solo, joint presenters, or panel). Learning Labs are two-hour, facilitated, hands-on sessions.
- Speaker notification: January 2027.
- Official Call for Submissions page: rsaconference.com/usa/call-for-submissions
- Submission portal: Submit your session proposal
According to RSAC, more than half of each year’s speakers are new to the conference, and proposals are reviewed by an independent, volunteer Program Committee. First-time submitters have a real chance. The committee is looking for depth and practical experience, not seniority or a sales pitch.
The Case for Non-AI Talks
AI deserves attention, and there will be excellent AI sessions in 2027. But the fundamentals have not gone away. Most of the breaches, outages, and audit findings we see still trace back to identity, configuration, third-party risk, and recovery. Those are the problems practitioners are working on every day, and they need speakers who have done the work.
RSAC’s own published sample track list reflects that breadth. It includes Identity & Access; Cloud & Infrastructure Security; Data Security, Privacy & Data Protection; Governance, Risk & Compliance; Detection & Security Operations; Critical Infrastructure & OT/ICS Security; Cryptography & Post-Quantum; Law; Policy & Government; and Leadership & Workforce Development. (RSAC notes the list is a sampling and may evolve.)
If you need a starting point, here are some topic ideas that would make sense to see on the agenda:
- Identity: What actually happened when you rolled out phishing-resistant MFA, cleaned up service accounts, or retired legacy authentication. Include what broke.
- Cloud and infrastructure security: Misconfiguration lessons, asset inventory that stays current, or segmentation that survived contact with production.
- Privacy and regulation: Turning changing requirements, such as the proposed HIPAA Security Rule updates, into a workable program without waiting for final rules.
- Governance, risk, and compliance: Risk analyses that drive decisions, Board reporting that connects security to business outcomes, and third-party oversight that goes beyond questionnaires.
- Incident response and recovery: Real ransomware recovery timelines, tabletop exercises that exposed gaps, and how clinical or operational teams kept working during an outage.
- OT/ICS and medical devices: Securing systems that cannot be patched on a normal schedule, and coordinating between engineering, clinical, and security teams.
- Human factors: Security culture, burnout in the SOC, building teams, and designing controls people will actually use.
- Fundamentals: Vulnerability management, logging, backups, and encryption. These are unglamorous but decisive, and a talk that shows measurable improvement is valuable to every attendee.
The strongest talks share a real experience, including failures and lessons learned, with enough specific detail that the audience can take something back to their own organization.
A Few Practical Tips
- Complete the session detail. RSAC lists incomplete submissions as the number one reason proposals are not selected. The session detail is the most important part.
- Skip the vendor pitch. Sales pitches are easy to spot, and the Program Committee eliminates them quickly.
- Be specific. Unique, clearly detailed submissions with technical depth stand out from the many similar proposals on popular topics.
- Don’t wait. October 9 is less than two weeks away.
Submit Your Talk
If you have solved a hard identity problem, recovered from an incident, built a compliance program that actually reduces risk, or learned something the hard way about the fundamentals, the community needs to hear it. Please submit a non-AI talk to RSAC 2027. Review the official Call for Submissions, check the sample tracks and FAQ, and submit your proposal before October 9 at 11:59 PM PT.
I hope to see you in San Francisco.
