Compliance & Risk

GRRCon 2026: A Conversation with Richard Maloley II

Richard Maloley II

GRRCon 2026: A Conversation with Richard Maloley II
GRRCon 2026: A Conversation with Richard Maloley II

GRRCon celebrated its 15th year in 2026, and Digital Elevation's Richard Maloley II attended for the sixth time. We sat down with him afterward to find out what he brought back for mid-market IT and security teams in West Michigan.

Richard is a security consultant at Digital Elevation and helps run #misec, a Michigan-based professional community for cybersecurity practitioners. His personal notes and session photos from GRRCon 2026 are public at github.com/maloleyr/grrcon-2026. The responses below are his own, lightly edited for the format. One follow-up question (marked added) was asked after the original set.

Warm-up and context

Was this your first GRRCon? If not, how did this year compare to past ones?

This was my sixth GRRCon, and the conference celebrated its 15th year, quite the milestone. Compared to prior years, it felt more like what a hacker conference is supposed to feel like.

What was different this year? (added follow-up)

The combination of talks and the crowd. More of the talks had real substance rather than mythical or marketing content. One talk was about literally hacking, physically and logically, a water-cooled bed accessory so it works in a more free and human-focused way ("My Bed Tried To Freeze Me at 3AM. I Rooted it.", Adam Schaal). Even the vendor conversations were more focused on reality than hype. One vendor's product brief was all "AI, AI, AI", and when I asked for the reality, no AI was in use at all. At least they were honest in words.

What did you go in hoping to get out of it?

For me a hacker conference has three purposes: networking, learn something new, get excited.

  • Networking. I'm there as a member of my company, as a member of a non-profit group, and as myself. I'm looking for current customers to chat with, future customers to court, vendors to sponsor my non-profit, and a growing group of peers who can help me learn and grow.
  • Learn something new. There has to be at least one thing I learn, otherwise it's hard to justify the time and expense. In "So You Want To Be a Forensicator," I learned something new about the history of forensics (Locard's Exchange Principle).
  • Get excited. When you constantly live in the cybersecurity space, it's easy to lose excitement because of all the harm we see. Being around other excited people helps stir my own.

I got out of it what I wanted: personally, professionally, and for the community I want to help build and foster.

How would you describe GRRCon to someone in West Michigan who's never been?

GRRCon is the place to be if you want to work in the cybersecurity industry in West Michigan. It's a two-day event where you can level up skills, meet new employers, and make friends who will help you along the way. Everyone is welcome, from the hacker in cargo shorts to the CISO in a suit and tie.

Talks and sessions

Which talk or session stuck with you most, and why?

The two keynotes. The first, by three presenters, rightly called out the anti-human nature of some technology and the venture capital world. It was a call to remember the human, to build community, and for product organizations to remember the SMB and "mom and pop" shops. That is a space where Springthrough and Digital Elevation can do a lot more work. The second keynote was about free and open APIs that governments and academia in other nations expose, leaking PII and other critical data. Calling that out, and disclosing another data exposure live on stage for the first time, is a critical act of caring for people that these systems and organizations apparently don't care for.

Did anything surprise you or change how you think about a threat or a defense?

Nothing changed my view of the current state of cybersecurity. What shifted slightly is where I think AI and LLMs are going: smaller, leaner models focused on specific roles and task types. I expected that direction, but the vibe at the conference was that we're getting there quickly.

Was there a talk you disagreed with, or one you think got something wrong?

For once, every session I attended got things right, in my opinion. I rated Timothy Scheid's "Your Security Isn't Failing, It's Regressing" a "meh" only because it could be summarized as making change management and testing an ongoing process. A friend pushed back: how do you automatically test for a failure when your EDR vendor ships a bad update? That has stuck with me. It takes more than change management. It takes proactive thought and action whenever vendors push updates, which in some organizations makes vendor management an entire job role or team.

Did you do any of the hands-on activities?

No. My focus is on sessions and peer networking. It's not a cheap conference, so I want as much as possible out of the content itself. The Malört tasting board was a fun prop to check out.

Trends and the threat landscape

What themes kept coming up across sessions?

AI, unsurprisingly. Three themes stood out:

  1. Modern agentic AI and LLMs are really good and getting better. They can work together, often without the human operators knowing, and we need tighter regulation and security around them.
  2. Practitioners need to learn and lean in on using AI and LLM technology.
  3. AI and LLM creators need to make their products safer for humans by default (a recurring point from J. Wolfgang Goerlich). For example, don't let the AI cause a human to fall in love with it.

What are attackers doing differently this year?

I didn't hear anything new about attackers. A lot of the industry is talking about the fundamentals: know your attack surface, implement firewalls and ACLs, and use phishing-resistant MFA on all services. Agentic tools make it trivial, even more than for a traditional script kiddie, for anyone to vibe-code an attack tool, but the tool still depends on someone missing the fundamentals.

It gets worse when organizations deploy internal AI or agentic tools that take action on unvetted input. I overheard a story about an email to a mailbox that normally receives payment requests. It contained white text on a white background with instructions for the agent, and the AI approved the request and sent the payment. The lesson: a human must make the decision and be accountable. The AI, LLM, or agent should propose the action.

Was there anything you'd call overhyped, or underrated?

No sessions were overhyped this year, and the organizers did a good job there. I skipped the Executive Summit, so I can't speak to the hype aimed at the suits. In one keynote I was glad to hear, directly and frankly, that we should not make purchase decisions based on analyst writeups (think Gartner), a view I've held for some time. From a podcast covering RSA Conference interviews, and from a friend at a major security vendor, my take is that any vendor claiming "AI" is likely running on hype. That friend says openly that their "AI" is largely sophisticated machine learning that falls apart outside a narrow, specific scenario.

A human must make the decision and be accountable.

The AI, LLM, or agent should propose the action. That is the line that keeps the "white-text-on-white-background" attack from draining a bank account.

What it means for businesses

If a West Michigan business owner or IT manager could take only one thing from GRRCon, what should it be?

Who their peers are, and which vendors are local, regional, or larger for services.

Did anything you heard line up with what you're seeing in client environments?

Absolutely. Digital Elevation runs full security assessments against fifty-plus companies a year, across sizes, industries, and maturity levels. I see firsthand that many organizations don't do the fundamentals. Too many buy a product or service that promises a lot, but never do the simple, tedious basics that would negate the need for the expensive purchase.

Are you coming back to change or recommend anything?

I think our services at Digital Elevation and Springthrough already serve SMB clients very well. The only change I see is in how we market to and attract those clients. Our major competitors are going after larger organizations with more budget. We win on value, quality, and flexibility.

What's one thing a small or mid-sized company could do this month?

Run an internal AI and LLM survey. Find out what employees know, what they're using, and how. In particular, find out whether anyone is putting confidential data or PII into an unlicensed AI or LLM. (For a longer treatment, see our practical process for managing employee AI use.)

People, community, and wrap-up

Who did you meet or reconnect with?

I help run and organize the #misec community in Michigan: a professional group, with a non-profit at the top, formed for the benefit of Michigan cybersecurity professionals and anyone who wants to become one. Most of the people I met up with are members who live outside Grand Rapids, so I see them in person once or twice a year. I also had great sidebars with current and former clients. One of our prominent banking customers brought his team, and it was nice to connect outside the work environment. Seeing old customers who still smile when they see me and my team is a joy. I also introduced my junior teammate to new peers, knowing those connections will help him grow.

Why does a local conference like this matter for the security community here?

Because it's needed. Giant conferences like Black Hat and DEF CON are expensive and require lots of travel. Niche conferences, like one in the Caribbean that requires SCUBA certification, add travel and hobby costs that are prohibitive for many. Smaller community events like BSides are great, but they can be harder to get approved as a work expense. GRRCon hits the balance between the big, the esoteric, and the tiny. GRRCon in West Michigan, THOTCON in Chicago, and other regional conferences are necessary so that every cybersecurity professional in a region has a conference to go to.

Would you go again, and would you tell others to go?

Absolutely. I'll go every year and encourage my team and peers to do the same.

One sentence to sum up GRRCon?

It's a work-hard, play-hard conference: wear comfortable shoes, drink lots of water, and go easy on the free beer.

Talks referenced in this interview

  • "My Bed Tried To Freeze Me at 3AM. I Rooted it." by Adam Schaal
  • "So You Want To Be a Forensicator" by Catherine Ullman
  • "Your Security Isn't Failing, It's Regressing" by Timothy Scheid
  • "Your AI is Social Engineering You" by J. Wolfgang Goerlich

If you want to talk about any of this, from AI governance to the fundamentals a security assessment should actually test, reach out to the Digital Elevation team.

Richard Maloley II is a security consultant at Digital Elevation and an organizer with the #misec community in Michigan. Interview conducted and edited by Evan Williams.

Share this post