Your cert needs CPEs. Your association writes the CPE rules, then partners with an event company that needs bodies in chairs. Your chapter emails you a free pass and gets a table for it. The association never has to sell your data, because it rarely needs to. You hand it over yourself, at the registration form, on the way in. Nobody broke a rule. Don’t like it? Go take another certification from ISA2™ instead.
And the talks are often bad for a structural reason, not an accidental one. CPE is counted per hour in a seat. A good share of the speakers are paid vendors. Sponsors are graded on badge scans. Follow that all the way down and you find that nobody in the chain gets paid on whether you learned anything.
Then go and look at the event app, and the member portal behind it. Same harvest, same buried opt-out. Privacy is the thing that breaks here, and the remarkable part is that nobody has to break it. You hand it over at the door.
Look at the speaker list, then the association board, then the outlet covering the event. You will often find the same names on all three. That is not a conspiracy. It is a small field with no habit of disclosing anything at the exact point where disclosure would matter.
That’s the part worth being angry about. We’re security people. We built a profession that harvests its own members and calls it community , and then we pay into it.
So what does that make CacheCon
An attempt to run the other version. Not a better-marketed version of the same machine. The machine is the problem. The specific commitments are posted at the trailhead, in public, where you can hold us to them. The short form:
- Nothing scans you. The badge is paper and there is nothing on it to read. That single decision removes the entire economic reason the rest of it exists.
- Sponsors buy a table, not a list. They are told so in writing before they are allowed to pay. If a sponsor wants your email they will have to talk to you like a person and earn it.
- No slot is for sale. Not a keynote, not a track, not a “partner session” with a thin coat of paint on it.
- Nobody speaks as a company. Be fully anonymous, use a handle, or put your own face and bio on it. All three are supported and none is expected. What nobody does here is represent a brand, and you cannot buy a stage that nobody is standing on as one, which turns out to fix the same problem from the other end.
- Nothing is gated. No advanced-only track, no prerequisite, nobody checking your credentials at a door. If a talk goes over your head that is the speaker’s problem to solve, not yours.
- You get your CPEs. Signed certificate at the door, no chasing us for it afterward. People need the hours and sneering about that just sends you off to buy them somewhere worse. We hand them out and then stop thinking about them, because the schedule is not built out of seat time.
None of this is difficult. It is just unprofitable, which is a different problem, and one we would rather have.
What we are not claiming
That we invented this. Plenty of small cons already work like this and have for . That is precisely the evidence that it is possible at the scale where it matters. That everyone at a big conference is acting in bad faith: most of them are decent people inside a structure that pays for something other than your attention. And that we are immune. We will get things wrong. The difference we are actually committing to is that the rules are written down, in public, in advance, so that being wrong is visible rather than deniable.
If that sounds like something you want to be in a room for, the CFP is open.