
Episode #106
When Cybersecurity Becomes Pay to Play
Awards you have to pay to win, events you have to pay to attend and conferences that expect speakers to work for free. When did recognition and expertise in cybersecurity become something you have to buy? Welcome to Razorwire, the podcast where we share our take on the world of cybersecurity with direct, practical advice for professionals and business owners alike. I'm Jim and in this episode I'm joined by security consultant and regular community speaker James Bore and Gary Hibberd, co-founder of Consultants Like Us and the Real Cyber Awards and Conference. Pay to play takes many forms in cybersecurity, from awards that come with entry fees and expensive tickets to events charging vendors thousands for access to decision makers. At the same time, large commercial conferences can expect experienced speakers to give up days of preparation, travel at their own expense and appear on stage in return for little more than exposure. Jim, James and Gary look at where legitimate commercial arrangements end and questionable practices begin. They discuss what gives an award credibility, when paying for access to an event can be worthwhile and why the way cybersecurity treats its speakers could ultimately affect the quality of the events themselves. Three key talking points When recognition comes with a price tag Not every paid award works the same way. From outright offers to buy recognition to free entries followed by expensive ceremony tickets, we look at the different forms pay to play can take and why credibility depends on what happens behind the award. Should cybersecurity speakers be paid? Community events and large commercial conferences operate very differently. We discuss when speaking for free makes sense and why expectations should change when an event is making significant money from exhibitors and attendees. Good speaking takes work A short conference talk can take days of preparation. James and Gary get into the work behind becoming a strong speaker, why experience and preparation matter and what happens when events prioritise sponsored slots over good content. If you're deciding which awards and events deserve your time, or building a reputation as a cybersecurity speaker, this conversation is for you. On what makes an award mean something: "It's lovely to win an award, but you win it based on merit. You don't win it because you paid for it." James Rees Listen to this episode on your favourite podcasting platform: https://razorwire.captivate.fm/listen In this episode, we covered the following topics: The Pay to Play Awards Industry Find out how paid recognition can range from blatant offers to buy an award to less obvious costs that only appear once you've been shortlisted. What Makes an Award Credible? An impressive trophy does not necessarily mean much. We discuss judging, verification and why the process behind an award determines whether the recognition carries any weight. Paying for Access to Decision Makers Vendors can spend significant sums for a seat in the room with CISOs and other senior buyers. Discover why some of these events deliver useful conversations while others fall far short of what was promised. The Real Cost of Speaking for Free Speaking is rarely just the time spent on stage. We get into preparation, travel and accommodation and why the economics look very different for community events and commercial conferences. Community Events vs Commercial Conferences James regularly speaks at community events without charging. Explore why contributing to an event built around the community is different from providing free content to a profitable conference. The Problem With 'Exposure' Exposure can be valuable early in a speaking career, but it has limits. We discuss why established speakers are increasingly willing to turn down events that expect expertise for nothing. Why Conference Content Suffers When experienced speakers walk away and sponsored slots fill the gaps, audiences notice. Find out how decisions about speaker budgets can affect the quality and value of an event. Learning to Become a Better Speaker Public speaking is a skill rather than something that simply happens when someone walks onto a stage. James and Gary discuss preparation, practice and learning the craft. Knowing When to Say No Not every award, event or speaking opportunity deserves your time. We explore why knowing what you want from an opportunity matters before agreeing to take part. Resources Mentioned The Real Cyber Awards and Conference Security BSides Cyber OSPAs Connect with your host James Rees Hello, I am James Rees, the host of the Razorwire podcast. This podcast brings you insights from leading cyber security professionals who dedicate their careers to making a hacker’s life that much more difficult. Our guests bring you experience and expertise from a range of disciplines and from different career stages. We give you various viewpoints for improving your cyber security – from seasoned professionals with years of experience, triumphs and lessons learned under their belt, to those in relatively early stages of their careers offering fresh eyes and new insights. With new episodes every other Wednesday, Razorwire is a podcast for cyber security enthusiasts and professionals providing insights, news and fresh ideas on protecting your organisation from hackers. For more information about us or if you have any questions you would like us to discuss email podcast@razorthorn.com. If you need consultation, visit www.razorthorn.com , We give our clients a personalised, integrated approach to information security, driven by our belief in quality and discretion. LinkedIn: Razorthorn Security YouTube: Razorthorn Security TikTok: Razorwire Podcast Instagram: Razorwire Podcast Twitter: @RazorThornLTD Website: www.razorthorn.com All rights reserved. © Razorthorn Security LTD 2025

