Black Hat USA has never suffered from a shortage of technology.
Walk the show floor in Las Vegas and you'll find thousands of security professionals surrounded by new platforms, new capabilities, new approaches, and increasingly, new promises about what artificial intelligence can do.
But some of the most valuable conversations at Black Hat USA 2026 weren't about what organizations should buy next.
They were about what organizations already have.
Throughout the week, Steel Patriot Partners met with cybersecurity leaders, technology partners, practitioners, and business leaders to discuss what's changing across security, compliance, cloud, and IT strategy. We also sat down with Studio C60 / ITSPmagazine for a series of conversations about what we were seeing and hearing.
Several themes kept resurfacing:
Organizations don't necessarily need more technology. They need more value from the technology they've already purchased.
AI is creating legitimate new security concerns, particularly around non-human identities, but the answer isn't automatically another AI security product.
Security leaders are becoming more selective about who they trust for guidance.
Compliance and cybersecurity investments make more sense when the business objective comes first.
And perhaps most importantly:
The question isn't always "What should we buy?" Increasingly, it's "Who can help us figure out what we actually need?"
Key Takeaways
- The security market is moving from "more tools" toward "better outcomes."
- Many organizations already own capabilities capable of addressing emerging risks but have not configured or operationalized them effectively.
- Non-human identities emerged as one of the most significant AI-related security concerns heard by SPP at Black Hat.
- AI and automation have increased the volume of information reaching security leaders without increasing the time available to evaluate it.
- Tool rationalization and configuration can create significant ROI without introducing another platform.
- Trusted advisors, partners, VARs, and existing relationships are becoming increasingly important as buyers attempt to cut through vendor and AI-generated noise.
- Compliance should begin with the business destination, entering a market, winning a customer, satisfying a partner, reducing risk, not with selecting a framework.
- Security and compliance recommendations should be evaluated as business decisions first and technical decisions second.
- Being technology- and assessor-agnostic can be valuable because sometimes the right recommendation is not to buy or pursue something new.
Theme #1: The Capability May Already Be in Your Stack
One of the clearest observations coming out of Black Hat was that security leaders are beginning to question whether the answer to every new problem needs to be another product.
Michael Parisi, Chief Growth Officer at Steel Patriot Partners, discussed this directly during his Black Hat recap with Marco Ciappelli of ITSPmagazine.
One of the biggest AI-related concerns Michael heard throughout the event involved non-human identities, service accounts, machine identities, automation, APIs, and increasingly AI agents, operating with credentials and permissions inside enterprise environments.
Organizations recognize the potential risk.
But there's another side to the problem.
Many security teams may already own technology capable of providing some of the discovery, governance, identity, or security capabilities they need. They simply may not realize those capabilities exist, or may not have configured them appropriately.
That leads to a much better question than:
"What new product should we buy?"
Ask:
"Can something we already own solve this problem?"
Before adding another platform, organizations should understand:
- What capabilities exist across the current stack?
- Which features are actually enabled?
- Where are tools overlapping?
- Are products configured for today's business requirements?
- Have new capabilities been added since the product was originally purchased?
- Are teams getting the value they expected from the investment?
In other words:
The capability may already be there. The configuration may not be.
Theme #2: The ROI Is Often in the Configuration
That theme carried directly into another Black Hat conversation between Michael and Sean Martin of ITSPmagazine.
Security organizations have accumulated enormous technology stacks over the past several years.
The buying cycle was understandable.
-
A new problem emerged.
-
A new platform addressed it.
-
Another requirement appeared.
-
Another tool was purchased.
-
Cloud expanded.
-
Compliance expanded.
-
Attack surfaces expanded.
-
And eventually, the stack expanded with them.
But purchasing technology and extracting value from technology are two very different things.
Michael described the issue as a form of deferred maintenance applied to the security stack: organizations purchased technology enthusiastically but eventually ran out of the time and resources required to fully configure, maintain, and optimize what they owned.
That creates an enormous opportunity for security leaders.
Not necessarily to buy. To rationalize.
Michael shared an example involving approximately $750,000 in annual licensing costs where an independent review identified roughly $250,000 in potential savings. The opportunity didn't require ripping out the entire environment or introducing another platform. It came from taking an independent look at existing spend and capability.
That's an important lesson heading into the next budget cycle.
Before asking for another technology investment, organizations should evaluate:
Utilization. Configuration. Overlap. Licensing. Architecture. Consumption. Operational ownership.
Three products producing substantially the same business outcome may not need to remain three products.
And the platform that survives doesn't necessarily need to win every analyst comparison.
A trusted solution that meets the organization's requirements and is properly configured, maintained, and operated may deliver more value than a technically superior product that isn't.
Theme #3: AI Created More Capability and More Noise
AI was unavoidable at Black Hat.
But compared with some earlier cybersecurity events, Michael observed a change in the conversation.
The AI hype had begun to mature.
Rather than simply asking who has AI, organizations were becoming more focused on which business and security problems AI actually needs to solve.
That's progress.
But AI has also introduced another problem.
Noise.
Security leaders were already inundated with vendor outreach, technology options, threat intelligence, alerts, vulnerabilities, analyst research, and product claims.
Generative AI made producing outreach and marketing content dramatically easier.
It did not give CISOs more hours in the day to evaluate it.
Michael's observation from Black Hat was that buyers are responding by narrowing the circle.
They're going back to people they already know.
-
Trusted partners.
-
Existing relationships.
-
VARs that understand their environment.
-
Practitioners whose advice they trust.
Rather than asking another unfamiliar vendor for another demo, they're increasingly asking:
Who do you work with?
Who can I buy through?
Who understands my environment?
Who can tell me whether this actually makes sense for us?
That shift matters.
In an industry with more information than anyone can realistically process, trust becomes a filtering mechanism.
Theme #4: Trusted Advice Is Becoming More Valuable Than Another Pitch
Trust became one of the most consistent themes across SPP's Black Hat conversations.
Jason Ford, CEO and Co-Founder of Steel Patriot Partners, and Michael discussed it during their Brand Spotlight conversation with Marco Ciappelli.
The philosophy behind Steel Patriot Partners is captured in a phrase the team uses frequently:
Business owners first. Engineers second. Security and compliance people third.
That order is intentional.
Cybersecurity conversations frequently begin with the framework.
-
FedRAMP
-
CMMC
-
SOC 2
-
ISO 27001
-
CJIS
Or they begin with the product.
-
SIEM
-
CNAPP
-
IAM
-
GRC
-
EDR
But the better conversation starts earlier.
What is the business trying to accomplish?
Jason and Michael described the importance of understanding where an organization actually stands before prescribing where it should go. Sometimes organizations discover they're considerably less mature than they believed.
Other times, the opposite happens.
They discover they're much closer to their desired outcome than they thought.
That discovery can completely change the investment decision. And it reinforces why independent advice matters.
If every conversation begins with a predetermined product, framework, assessment, or service, the recommendation can easily become the destination.
It shouldn't be.
Theme #5: The Destination Isn't the Certification
This point became even clearer in Michael's conversation with Sean Martin about SPP's Find Your Path approach.
Organizations rarely wake up and decide:
"Our business objective is to obtain a certificate."
There is usually something underneath it.
-
A company wants to enter the federal market.
-
A software provider wants to sell into state government.
-
A customer requires proof of security before signing a contract.
-
A partner needs evidence before integrating systems.
-
Leadership wants to reduce enterprise risk.
-
A board wants greater confidence in the organization's security posture.
The certification or framework is a means to that outcome.
Not the outcome itself.
As the ITSPmagazine conversation summarized it, "What a company is trying to reach is rarely a certificate." The secure and compliant environment should ultimately enable whatever the organization is trying to accomplish as a business.
That changes how compliance strategy should work.
Instead of:
Framework → Requirements → Technology → Cost → Business justification
Start with:
Business objective → Required capabilities → Applicable requirements → Current-state gaps → Appropriate investment
The framework follows the objective.
Five Different Organizations May Need Five Different Paths
During the conversation, Michael outlined several situations organizations commonly find themselves navigating:
-
Growth has stalled and a new market represents the next opportunity.
-
Money has already been committed to a strategy recommended by someone else, but leadership wants independent validation.
-
The direction is already established and the organization needs specialized expertise to execute it.
-
Leadership needs help selecting the right partners, technologies, or assessors.
-
The organization needs ongoing operational support rather than another finite consulting project.
Those aren't the same problem.
So they shouldn't automatically produce the same engagement.
This is one reason SPP created Find Your Path: to help organizations determine where they actually are before deciding what they need next.
And sometimes the answer is:
You don't need what you thought you needed.
Michael described that as one of the more satisfying outcomes of these conversations—helping an organization determine that it may not need to pursue the investment it initially assumed was necessary.
That's what technology-agnostic and assessor-agnostic advice should enable.
Theme #6: Cybersecurity Strategy Is Becoming Business Strategy
Across all of the conversations, one larger theme emerged.
The separation between cybersecurity strategy and business strategy is becoming increasingly difficult to justify.
Consider the decisions security leaders are making:
Should we consolidate technology? That's a security decision. It's also an operating-cost decision.
Should we pursue FedRAMP? That's a compliance decision. It's also a market-expansion and revenue decision.
Should we introduce AI into security operations? That's a technology decision. It's also a productivity, workforce, governance, and risk decision.
Should we replace a platform? That's an architecture decision. It's also a capital-allocation decision.
Should we accept a security risk? That's a CISO decision. It's also an enterprise-risk decision.
This is why SPP's "business owners first" philosophy matters.
The business objective should determine the security strategy, not the other way around.
Theme #7: Have an Open Mind
There's another lesson from Black Hat that is easy to overlook.
Come into the conversation willing to discover that your original assumption may be wrong.
Jason emphasized the importance of having an open mind when organizations evaluate their existing strategy.
Maybe the tool you planned to replace is perfectly adequate.
Maybe the product you assumed was necessary duplicates something you already own.
Maybe your compliance program is further along than you thought.
Maybe the architecture needs more remediation than leadership realizes.
Maybe automation can eliminate work that you assumed required additional headcount.
Maybe FedRAMP isn't the right investment for your target market.
Maybe you don't need Steel Patriot Partners at all.
A useful advisor should be willing to say that. Because the objective isn't to justify a predetermined answer.
It's to determine the right path.
What Security Leaders Should Take Away From Black Hat 2026
Black Hat will always be a place to see what's next.
But one of our biggest takeaways this year is that what's next may not always require what's new.
Before adding another platform, look harder at the platforms you already have.
Before reacting to the latest AI security concern with another purchase, determine whether existing identity, cloud, or security tools already provide the necessary capability.
Before renewing an entire stack, evaluate overlap.
Before pursuing a certification, identify the revenue or business objective behind it.
Before accepting vendor advice, understand the incentives behind the recommendation.
And before deciding where your security program needs to go next, establish where you actually are today.
The cybersecurity industry has spent years adding.
-
More tools
-
More telemetry
-
More frameworks
-
More automation
-
More AI
-
More alerts
-
More vendors
The next phase may be less about adding and more about optimizing, integrating, configuring, rationalizing, and trusting the right people to help organizations make sense of what they already have.
Final Thoughts
The conversations at Black Hat USA 2026 reinforced something we believe strongly at Steel Patriot Partners:
Security exists to serve the business.
The technology matters.
Engineering matters.
Compliance matters.
But those things have to support an outcome.
-
Better security
-
Lower risk
-
More efficient operations
-
Access to a new market
-
A customer requirement
-
Faster growth
-
Greater resilience
And increasingly, better returns from investments organizations have already made.
The best question coming out of Black Hat may therefore not be:
"What did we see that we need to buy?"
It may be:
"What did we learn that can help us get more value from what we already have?"
Watch the Black Hat Conversations
Want to hear the conversations directly from the Steel Patriot Partners team?
We've brought together our Black Hat USA 2026 conversations and event coverage so you can hear the full discussions on security strategy, AI, non-human identities, technology optimization, compliance, trusted partnerships, and finding the right path forward.
Watch the Black Hat USA 2026 conversations from Steel Patriot Partners
The page also provides more information about Steel Patriot Partners and our approach to helping organizations design, implement, and operate cybersecurity and compliance programs around measurable business outcomes.
Featured conversations include:
The Budget Is Already Spent. The ROI Is in the Configuration
Michael Parisi discusses security-tool sprawl, changing buying behavior, trusted partners, configuration, consolidation, and finding additional ROI in technology organizations already own.
The Capability Is Already in Your Stack. The Question Is Who You Ask.
Michael recaps Black Hat and discusses AI, non-human identities, existing security capabilities, and why security leaders are increasingly relying on trusted relationships to navigate the noise.
Business Owners First, Engineers Second, Compliance People Third
Jason Ford and Michael Parisi discuss SPP's philosophy, why security and compliance decisions should begin with business outcomes, and the importance of understanding where an organization actually stands before recommending where it should go.
A Secure and Compliant Business Is the Destination. Steel Patriot Partners Maps Five Routes to It.
Michael explores SPP's Find Your Path philosophy and why the destination should be defined by what the business needs to accomplish—not simply the certification or framework it thinks it needs.
Need help navigating the changing IT landscape?
Whether you're evaluating IT strategy or modernizing your compliance program, Steel Patriot Partners helps organizations design, implement, and operate security programs that meet today's requirements while preparing for tomorrow's standards.
Schedule a consultation with our compliance experts to discuss your roadmap.