Conference Season Is Here. Pick Like It Matters.
September 23, 2026 · 6 min read
Canada's security conference scene is better than it gets credit for. Most people still pick the wrong one.
GoSec opens in Montreal today. CanSecWest starts in Vancouver next week. SecTor takes over the Metro Toronto Convention Centre on October 6. Hackfest fills the Québec City Convention Centre at the end of the month, and BSides Ottawa closes things out in November.
That's five serious security events in about eight weeks. Your training budget covers one. Maybe.
So everybody asks the same thing: which one's the best?
Wrong question.
I've spent 26 years in this industry and I've run a conference since 2011. The best event is the one that fits the job you need done this year. Most people pick based on which vendor handed them a free pass, then come home with a bag of stress balls and nothing they can use on Monday.
The big room
SecTor is the heavyweight. It started in Toronto in 2007, it runs under the Black Hat banner now, and it pulled 5,000 unique attendees in 2024. This year it's October 6 to 8, with an Executive Summit and an AI x Cloud Security Summit on day one, then two days of briefings and a business hall.
If you need to see a lot of vendors in one place, go. If you're a CISO who wants to benchmark against peers from the banks and telcos, go. The research tracks are good and they've always been good.
Just know what you're walking into. A big show owned by a big events company is built around the business hall, because the business hall pays for the room. Nothing sinister about that. It just means the useful conversations happen in the hallway, not at the booth.
GoSec plays in a similar lane at a smaller scale. It's been running for over 20 years, expects 1,500+ people, and leans toward leadership and trends: AI, ransomware, cloud, data protection. Good fit if your job is budget and strategy and you'd rather not fight 5,000 people for coffee.
The deep end
Canada punches way above its weight on hardcore technical events. A lot of people in our own industry have no idea.
NorthSec in Montreal is where I send people who tell me they want to get better, not just get informed. The talks are solid. The CTF is the point: close to 100 teams of eight, 48 hours, in person. You'll learn more that weekend than in a year of webinars. The 2027 dates are already up, May 10 to 16 at Bonsecours Market.
REcon is also in Montreal and has been since 2005. Reverse engineering and exploitation, single track, 600 tickets total. If you don't know what a decompiler is, skip it. If you do, it might be the best three days you spend all year.
CanSecWest in Vancouver is the old guard of offensive research. Pwn2Own was born there in 2007. That contest has since moved to Berlin, which tells you something about where the money in exploit research went. CanSecWest still runs, September 30 to October 1 this year. Still small. Still technical.
Hackfest in Québec City is the one people outside Quebec sleep on. It started as Hackfest Reloaded in 2009 with 175 people in a hotel basement. Hit 1,600 in 2019. Passed that in 2025. Their CTFs are ridiculous in the best way: a physical escape room, real industrial equipment, an actual vehicle, a wind turbine. This year's edition runs October 29 to November 1.
The local ones
My bias, up front: I founded AtlSecCon. Weigh the next part accordingly.
Most Canadian organizations aren't banks. They're municipalities, school boards, clinics, law firms, manufacturers, and the MSPs who look after all of them. Those people don't fly to Toronto. There's no travel budget. There's one IT person and a board that just started asking questions.
Regional events are where those people actually show up. BSides chapters run in Ottawa, Toronto, St. John's and other cities. Volunteer-run, cheap to attend, full of first-time speakers who'll tell you exactly what broke at their shop. BSides Ottawa is November 19 and 20 this year.
AtlSecCon had 1,750 people and 64 speakers in Halifax this April, up from 1,200 in 2023. That's close to 50% growth in three years, and more than GoSec is expecting this week. Only SecTor is clearly bigger. It started as a regional show. At that size, it's outgrown the label.
Every talk is 45 minutes. No panels. That was deliberate. Panels are where good speakers go to agree with each other for an hour. We'd rather hand one person the room and make them say something.
The keynote isn't why you go to a regional show. You go because the person sitting beside you works 20 minutes from your office.
When you get hit at 2 a.m. on a Saturday, that's who you call. Across 600+ incident response engagements, the pattern holds: the organizations that recover fastest already knew who to phone.
You don't build that at a 5,000-person show.
How I'd actually pick
Figure out what you need this year. Then pick the event that serves it.
Want hands-on skill? NorthSec or Hackfest, or REcon if you're already deep. Put your junior people in a CTF and watch what happens to them.
Evaluating tools or benchmarking your program? SecTor or GoSec. Book your vendor meetings before you arrive so the business hall works for you instead of the other way around.
Need people you can call in a crisis? Go local, whatever's in your region, and go back next year. One visit doesn't build a network. Three does.
Whatever you pick, skip the session you could watch on YouTube later. Go to the hallway. Buy someone a coffee. Ask them what their worst week looked like.
That's the conference.
Bottom line
Some of the most technical events in North America run in Montreal and Québec City. The biggest one in the country runs in Toronto, and one of the biggest runs in Halifax. The regional shows keep smaller organizations in the room when nobody else will.
Supply was never the issue. People treat conferences like a perk when they should treat them like a plan.
Pick one on purpose. Go with a goal. Come home with names, not swag. AtlSecCon 2027 runs April 8 and 9 at the Halifax Convention Centre. Yes, that's a plug. I did warn you.
Next Step
Ready to strengthen your organization's resilience?
A 30-minute discovery call to discuss your cybersecurity posture, incident readiness, and whether advisory support is the right fit.