Categories
Artificial Intelligence Conferences Tampa Bay

Tampa Bay Tech Week presents 727 Tech Day!

Monday, 7/27, is the day when we celebrate the techies and tech companies in the 727 area code: 727 Tech Day!

727 Tech Day is a one-day, all-in celebration of the St. Pete / Clearwater / Pinellas tech community, presented by the folks behind Tampa Bay Tech Week (with HyLo Innovation and W3RTech). If TBTW is the five-day, five-neighborhood sprawl, then 727 Tech Day as the encore focused on a single Tampa Bay county, with everybody in the same few rooms.

If you’re anywhere near the 727 and you build systems or software for a living, this is the easiest “yes” on your calendar this week.

The essentials

  • When: Monday, July 27, 2026
  • Where: Clearwater and St. Pete. It’s a venue-hop (details below)!
  • Cost: Register on Luma → luma.com/567lh3c0
  • Vibe: Panels, hands-on workshops, a lot of open networking, and an evening that keeps going

727 Tech Day moves around the county!

This isn’t a sit-in-one-ballroom-until-4pm situation. The day migrates across Clearwater and St. Pete, which is either a feature or a step-count challenge depending on your mood:

  • Sunrise yoga on the rooftop at Station House to kick things off. Yes, yoga. At a tech event. Bring your own mat or grab one onsite. I’m told no other tech event in Florida opens like this, and I believe it.
  • Morning sessions at Collaborative Labs (over at St. Petersburg College).
  • Afternoon sessions at NOVA 535 in downtown St. Pete.
  • Happy Hour Networking at 4 PM at the St. Pete Athletic Club, with three hours of the good stuff (founders, operators, investors, community folks, all in one place).
  • Closing Night at 7 PM at The Estate, because “conversations to activations” apparently requires at least one iconic venue and a proper send-off.
Event name and location Group Time
Rooftop Yoga
Station House
Tampa Bay Tech Week – 727 Tech Day 7:00 AM to 8:00 AM EDT
Registration and check-in
Collaborative Labs
Tampa Bay Tech Week – 727 Tech Day 8:30 AM to 9:00 AM EDT
St. Pete’s Economic Development Discussion
Collaborative Labs
Tampa Bay Tech Week 9:00 AM to 10:00 PM EDT
Maritime and Defense Tech Panel Discussion
Collaborative Labs
Tampa Bay Tech Week – 727 Tech Day 10:00 AM to 11:30 AM EDT
Build Your AI Workflow Live Workshop
Nova 535
Tampa Bay Tech Week – 727 Tech Day 12:00 PM to 1:00 PM EDT
AI + Marketing What Actually Works In 2026
Nova 535
Tampa Bay Tech Week – 727 Tech Day 1:00 PM to 2:00 PM EDT
Using AI As a Revenue Engine
Nova 535
Tampa Bay Tech Week – 727 Tech Day 2:00 PM to 3:00 PM EDT
Raising Capital in 2026 For Your Business
Nova 535
Tampa Bay Tech Week – 727 Tech Day 3:00 PM to 4:00 PM EDT
727 Tech Day Networking
St. Pete Athletic
Tampa Bay Tech Week – 727 Tech Day 4:00 PM to 7:00 PM EDT
727 Tech Day Closing Celebration Sponsored by XUNA AI
The Estate
Tampa Bay Tech Week – 727 Tech Day 7:30 PM to 12:00 AM EDT

Why go?

Because this is our scene! It shows up best when we show up. 727 Tech Day is pitched as “no filler, no fluff”. The afternoon track alone, which is a build-something-real AI workshop plus three panels that all promise to separate signal from hype, is worth the trip. Add the networking window and the closing night, and you’ve got a full day of the people you actually want to run into.

I’ll be around. Come say hi! I’m the one with the accordion energy and strong opinions about zero-trust networking.

Grab your spot: luma.com/567lh3c0. For more info, check out 727techday.com

See you in the 727!

Categories
Conferences Developer Relations

How to “work the room” at DevRelCon NYC 2026

DevRelCon NYC 2026 happens today and tomorrow!

DevRelCon was created by the developer relations agency Hoopy and began in London in 2015. It’s since grown into an international series of conferences with editions in London, Prague, San Francisco, Tokyo, China, Latin America, and online.

I’m speaking at this event, which is organized by Mike “Swift” Swift and Major League Hacking, the global community for early-career developers and software creators. It’s positioned as the premier conference for anyone working to grow developer adoption, spanning developer relations, developer experience, product marketing, platform product management, and everyone’s favorite three-letter acronym, GTM. In other words, it’s a room full of exactly the people my talk is about, which is either the best or the most terrifying possible audience for a talk on what the DevRel job market is really telling us. (Probably both.)

I’m here as of the many, many people you can meet. But meeting people requires a skill called “working the room.”

Fortunately for you, my life, whether as a developer advocate, musician, community organizer, and generally unhinged extrovert has me working the room regularly, and I’m sharing all my tricks in this article. There are a lot of them; feel free to scan this article, find the tips that work for you, and put them into practice!

Contents

  1. Before the conference
  2. At the conference (and conference events)
  3. After the conference

Before the conference

Do some homework

Review the schedule speaker bios, and sponsors (who’ll probably have a table in the exhibitor hall), so that you can determine:

  • What sessions do you want to attend? This will provide subject matter for conversations, as well as help you find other people who’ll be attending the same workshops/talks.
  • What speakers would you like to talk to? I’m a speaker, and I know that we’ve been told not to hide in the speaker ready room, but get out into the conference to mix, mingle, and start conversations. Think of us as “mini-hosts” for the event, and if our presentation covers a topic you’d like to talk about, please approach us!
  • What sponsors do you want to talk to? Is there some gear, software, or service that you’re interested in that some sponsor provides? Make a note to talk to them.

Arrive with goals

Decide what you want to achieve at DevRelCon, which can include any of the following:

  • Learning something new
  • Making new contacts or re-establishing old ones
  • Finding new work / hobby / social opportunities

Prepare your introduction

A one-line self-introduction is simply a single-sentence way of introducing yourself to people you meet at a conference. It’s more than likely that you won’t know more than a handful of attendees and introducing yourself over and over again, during the conference, as well as its post-session party events. It’s a trick that Susan RoAne, room-working expert and author of How to Work a Room: The Ultimate Guide to Making Lasting Connections In-Person and Online teaches, and it works. It’s pretty simple:

  • Keep it short — no longer than 10 seconds, and shorter if possible. It’s not your life story, but a pleasantry that also gives people just a little bit about who you are.
  • Make it fit. It should give people a hint of the cool stuff that you do (or, if you’re slogging it out in the hopes of doing cool stuff someday, the cool stuff that you intend to do.)
  • Show your benefits. Rather than simply give them your job title, tell them about a benefit that your work provides in a way that invites people to find out more. Susan RoAne likes to tell a story about someone she met whose one-liner was “I help rich people sleep at night”. That’s more interesting than “I’m a financial analyst”.

My intro at DevRelCon will be something along the lines of “I’m a rock and roll accordion player, but in my spare time, I do developer relations at NetFoundry!”

Have some “pocket stories” handy

Pocket stories are short, engaging, and easy-to-tell anecdote you keep ready for networking situations. They should be:

  • Brief: No more than a minute long; a minute and thirty seconds tops.
  • Relevant to DevRelCon or the people listening.
  • Open-ended, so listeners can respond or share their own experiences.

Here’s a tech-related pocket story:

“Last year I tried to refactor a core service during a two-week sprint. Halfway through, we realized we’d basically reinvented a library that already existed. The best part? We ended up contributing to that library instead, and now it’s in production at three other companies.”

“Local flavor” pocket stories are often a good conversation starter:

“This is my first time in Kansas City, and yesterday I went looking for barbecue. I asked a local for the ‘best’ spot… and ended up in a half-hour debate between two strangers about burnt ends. I still don’t know who won, but I definitely left full.”

Bring an interesting thing

We’re nerds! We love interesting gadgets, amusing tchotchkes, and funny techie T-shirts. They’re often interesting conversation-starters, and DevRelCon is the perfect environment for bringing them out!

Me? I’m bringing the accordion (of course).

The incredibly simple trick for instantly boosting your social confidence

Here’s the exercise: Before you leave to go to DevRelCon, find some text and read it out loud for three minutes. If for some reason you can’t find some text to read, use this article. You’ll find that it’s a self-confidence booster!

Even after DevRelCon has come and gone, do this exercise daily. Like any skill, frequent low-pressure practice builds familiarity, and if you read alound regularly, you’ll find yourself more comfortable when talking with strangers at networking events.

Choose something different to read out loud every day, and try emphasizing key parts of the text. If you’re reading something with dialogue, try expressing the emotion in that dialogue. If you listen to audiobooks or podcasts, try emulating the way audiobook narrators narrate their material.

Reading out loud boosts your confidence because:

  • It helps you get comfortable with your voice. Many people don’t like the sound of their own voice. Reading out loud gets you used to the sound of your voice, reducing any self-consciousness you may have about it. And when you’re comfortable with your voice, you’ll also be more comfortable speaking in social situations and making presentations.
  • Your speech will become more clear. The exercise of reading out loud forces you to articulate words clearly and speak at a steady pace. You’ll  also become more aware of your tone, rhythm, and pitch, so that you can adjust them to sound clear and confident, and mumble less.
  • It makes you more engaging. Read out loud with expression; it’ll give you practice with the kind of vocal variety and emphasis that keeps listeners interested in actual conversations.

At the conference (and conference events)

Use Inigo Montoya’s technique for introducing yourself

Inigo Montoya from The Princess Bride had the perfect self-introduction. Use his technique for yourself!

Example: “Hi! I’m Joey de Villa. I’m giving the fun Python “choose your own adventure” game talk on Friday. How are you doing?”

Project good posture

Having a good posture is generally good for all sorts of health reasons, but at a conference, it has the additional benefit of showing confidence, competence, and alertness. And because the body is a self-feedback system, you’ll find yourself feeling more confident, competent, and alert.

The general guidance for standing up straight is to imagine a string pulling you gently upward from the crown of your head. Keep your spine straight, knees soft, and feet shoulder-width apart.

When you do this, people will be more likely to approach you because you appear open and self-assured instead of reluctant and uncertain.

The general advice is to put your shoulders back — but not too far back. Your shoulders should be below your ears. Drawing your shoulders back just slightly opens up your chest, which is body language for “Hello. My name in Inigo Montoya. I’m killin’ it here. Prepare to converse.” You’ll appear more engaged and ready to interact.

That’s so much better that the forward, rounded shoulders look, which says “I don’t want to be here, and I definitely don’t want to talk to you.” It makes you look defensive or distracted.

You might find it helpful to roll your shoulders up, back, and down, just enough to relax your chest.

Here’s a WikiHow exercise to help you stand up straight.

Engage with eye contact

Eye contact — it’s a tricky thing, especially among nerdy types, but is one of the strongest ways to build trust quickly. What better place to brush up on your eye contact technique than DevRelCon?

Here’s how you do it: when you meet someone, make eye contact by looking at them right at their eyes for a “one thousand one, one thousand two” count. That’s long enough to acknowledge them but not so long that it feels as though you’re staring them down.

If looking someone in the eyes isn’t your thing, try looking at some part of their face near their eyes, such as their forehead or cheek.

Done right, eye contact gives others a sense of warmth and attentiveness. It makes other people feel seen, which is crucial in noisy, crowded conference environments.

Find out more about eye contact here.

Allistic people — people who aren’t affected by autism — should be aware that people with autism find eye contact challenging. If you find that the person you’re talking to finds eye contact uncomfortable, look at their face, but not directly at their eyes (basically, use the trick I mentioned earlier).

How to join a conversation

You’ll probably see a group of people already engaged in a conversation. If this is your nightmare…

Click the screenshot to read the Onion article.

…here’s how you handle it:

  1. Pick a lively group of people you’d like to join in conversation. As people who are already in a conversation, they’ve already done some of the work for you. They’re lively, which makes it more likely that they’re open to people joining in. They’ve also picked a topic, which saves you the effort of having to come up with one. It also lets you decide whether or not it interests you. If they’re lively and their topic of conversation interests you, proceed to step 2. If not, go find another group!
  2. Stand on the periphery and look interested. Just do it. This is a conference, and one of the attendees’ goals is to meet people. Smile. Pipe in if you have something to contribute; people here are pretty cool about that.
  3. When acknowledged, step into the group. You’re in like Flynn! Step in confidently and introduce yourself. If you’ve got that one-line summary of who you are that I talked about earlier, now’s the time to use it.
  4. Don’t force a change of subject. You’ve just joined the convo, and you’re not campaigning. Contribute, and let the subject changes come naturally.

Feel free to join me in at any conversational circle I’m in! I always keep an eye on the periphery for people who want to join in, and I’ll invite them.

Observe, ask, reveal

In her book How to Work a Room, Susan RoAne talks about a conversation tool she refers to as “Observe, Ask, Reveal” or “OAR,” which is a way to make interactions feel more natural and engaging. It’s made up of three steps:

  1. Observe. Notice something about the person you’re talking to, their surroundings, or the situation. This could be as simple as their choice of drink, something they’re carrying, or something happening in the room.

  2. Ask. Follow your observation with a genuine, open-ended question. This invites the other person to share and keeps the conversation flowing.

  3. Reveal. Share a little about yourself related to the topic, which helps build rapport and makes the exchange feel balanced rather than like an interrogation.

    ⚠️ Don’t overshare! TMI often backfires. Also, don’t overdo it with the questions — it should feel like a conversation, not an interrogation.

The idea behind OAR is to create an easy rhythm between listening and contributing to the conversation.

Be more of a host and less of a guest

No, you don’t have to worry about scheduling or if the coffee urns are full. By “being a host,” I mean doing some of things that hosts do, such as introducing people, saying “hello” to wallflowers and generally making people feel more comfortable.

Being graceful to everyone is not only good karma, but it’s a good way to promote yourself. It worked out really well for me — when I first moved to Tampa, I simply attended events and helped out where I could, lending a hand at meetups. I gained a reputation for being helpful and knowledgable, which led me to being invited to speak at events, and I also wound up inheriting a couple of meetups as well!

Use social media

Follow the DevRelCon hashtag — the official one is  — to find out what’s going on, and to find and connect with attendees online.

Advice for lunch

Lunch at DevRelCon is a great opportunity to meet people! Here are some tips for lunch…

1. Choose your table with intention

  • Arrive early if possible. This gives you more freedom to choose your spot.

  • Look for tables with a mix of people already seated and empty chairs. It’s easier to integrate into an existing conversation than to start from scratch with a fully empty table.

2. Use OAR (“observe, ask, reveal”) to break the ice

Follow the “observe, ask, reveal” conversational framework I wrote about earlier to talk to people at the table.

Example: “I see you got the DevRelCon hoodie — did you brave the merch line this morning?”

3. Introduce yourself to your immediate neighbors first

  • Turn to the people on your left and right, give your name, where you’re from, and a quick “pocket story” or conference-related detail.

  • Then, when there’s a pause in the group’s conversation, introduce yourself to the whole table. This makes you seem approachable, and you’re not barging into the conversation.

4. Keep the conversation inclusive

  • If you notice someone at the table isn’t speaking much, pull them in by looping back to them with a related question.

  • Avoid overly niche technical deep dives unless everyone’s into it.

5. Have a graceful exit

  • When lunch is wrapping up, thank the table for the conversation.

  • Swap contact details or LinkedIn with anyone you clicked with.

  • Mention to people at the table that you might see them in another session. If you know what sessions you’re attending after lunch, let them know!

Advice for social events

Try these out at Thursday’s attendee party, as well as at DevRelCon’ other social events, including the karaoke event (taking place Thursday at 9:00 p.m. in the back room on the ground floor of the AC Hotel):

  1. Beware of “rock piles”. Rock piles are groups of people huddled together in a closed formation. It sends the signal “go away”. If you find yourself in one, try to position yourself to open up the formation.
  2. Beware of “hotboxing”. I’ve heard this term used in counter-culture settings, but in this case “hotboxing” means to square your shoulders front-and-center to the person you’re talking to. It’s a one-on-one version of the rock pile, and it excludes others from joining in. Once again, the cure for hotboxing is to change where you’re standing to allow more people to join in.
  3. Put your stuff down. Carrying your bag or other stuff is a non-verbal cue that you’re about to leave. If you’re going to stay and chat, put them down. When you’re about to leave, take your stuff and start saying your goodbyes.
  4. Save the email, texts, and social media posts for later, unless they’re important.They’ll draw your attention away from the room and also send the message “go away.”

After the conference

1. Organize your contacts soon after the conference

  • Review any business cards, LinkedIn connections, or conference app contacts you collected. Strike while the iron is hot — do this by the end of the following week!

  • Tag or note:

    • How you met

    • What you talked about

    • Any action items (e.g., “Send them article on API security”)

This makes your outreach to people feel more personal and less generic and spammy.

2. Send a brief, specific follow-up

  • Timing: ideally within 3 days of the conference.

  • Keep it short, but reference something from your conversation to jog their memory.

Example: “Great chatting with you at the DevRelCon lunch table about AI security. Here’s that GitHub repo I mentioned.”

3. Continue the conversation

  • Share a useful resource, article, or code snippet related to what you discussed.

  • Offer help or collaboration, even if it’s small. This shifts you from a “one-time meet” to a peer in their network.

4. Connect on the right channels

  • LinkedIn for professional connections and ongoing career updates.

  • GitHub for technical/code collaboration.

  • Twitter/X or Mastodon if you connected over shared interests in tech culture, events, or industry news.

5. Keep the relationship warm

  • Interact with their posts, star or fork their repos, or comment thoughtfully on something they’ve shared.

  • When you come across a relevant opportunity, event, or resource, send it their way with a short note.

6. Build a “conference alumni” list

  • Keep a lightweight spreadsheet or note with names, contact info, and event details.

  • Before your next DevRelCon (or other conference), skim this list so you can reconnect with past contacts.

Categories
Conferences Developer Relations What I’m Up To

My talk next week at DevRelCon NYC 2026: “The Market is Trying to Tell You Something”

I don’t think I’ve ever put in as much work into a talk as I have for my upcoming talk at DevRelCon NYC 2026 (that’s “DevRelCon” as in “developer relations conference”), The Market is Trying to Tell You Something. It’s a lightning talk meant to fill up no more that 10 minutes including Q&A and the transition between talks, but the ratio of hours-of-prep to minutes-of-actual-talk is massive.

What is DevRelCon?

DevlRelCon NYC 2026 logo
DevRelCon NYC 2026 takes place July 22 – 23 at Industry City, Brooklyn, New York.

DevRelCon is the long-running conference series for people who do developer relations/developer advocacy, which once upon a time also went by “developer evangelism”. This line of work involves helping software developers discover, understand, and actually stick with a product, whether that’s through a combination documentation, demos, community, and developer experience.

DevRelCon was created by the developer relations agency Hoopy and began in London in 2015. It’s since grown into an international series of conferences with editions in London, Prague, San Francisco, Tokyo, China, Latin America, and online. I’m speaking at the New York 2026 edition, which is organized by Mike Swift and Major League Hacking, the global community for early-career developers and software creators.

DevRelCon is positioned as the premier conference for anyone working to grow developer adoption, spanning developer relations, developer experience, product marketing, platform product management, and everyone’s favorite three-letter acronym, GTM. In other words, it’s a room full of exactly the people my talk is about, which is either the best or the most terrifying possible audience for a talk on what the DevRel job market is really telling us. (Probably both.)

Joey de Villa’s NetFoundry business card
My business card. Click to see at full size.

DevRelCon NYC 2026 will take place July 22 – 23 at Industry City, Brooklyn, New York. It is the first conference I’m speaking at as an official representative of NetFoundry.

What’s The Market is Trying to Tell You Something all about?

Arms in Christmas sweaters toasting with cans of beer under a Christmas wreath
Join me at the DevRelCon afterparty and I’ll tell you the Christmas Eve “homework assignment” story over a beer.

The talk is based on my experiences in 2025, when I did something I don’t recommend as a hobby but made for a great natural experiment: I let the DevRel job market interview me a couple dozen times. That’s my dressed-up way of saying “I was looking for a job”.

I went through recruiter screens, faced hiring panels, did take-home demos (one on Christmas Eve, based on the urging of a recruiter), and went through final rounds — across AI-native startups, enterprise infrastructure shops, and everything in between.

Somewhere around the tenth interview, I stopped just trying to get hired and started noticing a pattern:

  • Job descriptions had quietly rewritten themselves.
  • Interviews are testing for things the job description never mentions.
  • And “DevRel ROI”, which used to be a phrase that was thrown in with an accompanying hand-wave, now means something specific that it didn’t mean in the zero-interest 2010s or the Great Resignation hiring frenzy of a couple years ago.

My talk is my attempt to decode those signals: what the market is actually screening for, how what it says and what it wants are often different, and what any of us (whether you’re job-hunting, hiring, or just trying to make sure your role survives its next budget review) should do about it. It’s eight minutes. There will be an accordion. That’s all I’ll say for now.

Categories
Conferences Developer Relations What I’m Up To

I’m speaking at DevRelCon NYC 2026 (July 22 – 23 in Brooklyn)!

DevRelCon NYC is the developer relations conference for North America, it’s happening in Brooklyn on July 22 and 23, and I’m a speaker!

Here’s a quick writeup of my talk, as it appears on the schedule:

The Market is Trying to Tell You Something

The DevRel job market has been sending signals for two years. Most of us have been too busy surviving it to read them. After 15+ years in Developer Relations and a recent job search that took me across a couple dozen companies, I came away with both a new role and something just as valuable: a pattern.

Job descriptions have quietly shifted. Hiring panels are asking different questions. “DevRel ROI” means something specific now that it didn’t mean in the zero-interest 2010s or the Great Resignation era of a couple of years ago. The skills companies say they want versus the skills that actually get you hired don’t look like they come from the same list.

This talk is an honest, experience-based, practitioner-level read of what the market is telling us about where DevRel is headed. It doesn’t have any LinkedIn takes or recycled frameworks; just patterns from the front lines, with implications for how you position yourself, make the case for your team, and think about the next few years of your career.

In addition to giving a talk, I’ll be there to learn as well as represent NetFoundry.

DevRelCon typically brings in about 300 attendees, mostly professionals from developer relations, developer experience, and developer community-building roles to discuss industry trends, methodology, and as of late, AI integration, as well as to do some networking (a key part of DevRel).

DevRelCon was created by the developer relations agency Hoopy and began in London in 2015. DevRelCon NYC is organized by Mike Swift and Major League Hacking, a global community for early-career developers and software creators, of which Mike is co-founder.

DevRelCon NYC takes place on Wednesday, July 22 and Thursday, July 23 at Industry City in Brooklyn, New York. I’m arriving early in the afternoon of Tuesday, July 21 and will be attending some of the pre-DevRelCon festivities.

Last year’s DevRelCon NYC talks

Here’s the set of DevRelCon NYC 2025 talks that have been posted to YouTube. I’m using these as a guide for my own talk (as well as for ideas for my own developer relations work at NetFoundry), and you might find these helpful for your own work, or to help you decide if DevRelCon NYC 2026 is for you!

Categories
Conferences Security Tampa Bay

Notes from BSides Tampa 13: “Dealing with Shadows” or “A day in the life of a threat actor negotiator”

If you’ve been anywhere near a screen this month, you saw the Canvas breach unfold in real time, where the ransomeware group known as ShinyHunters dropped a “rooting your systems since ’19 ;)” page onto the dashboards of nearly 9,000 schools during finals week. Instructure papered it over with a “scheduled maintenance” message that even the most gullible saw through. A few days later, they ended up paying the ransom in exchange for “shred logs” and a pinky-promise that no customers would be extorted further.

So when I sat down in a packed room at BSides Tampa 13 this past Saturday for a talk titled Dealing with Shadows: A Day in the Life of a Threat Actor Negotiator the timing felt less like a conference session and more like a debrief.

The speaker was Matt Barnett, CEO and co-founder of SEVN-X, a Pennsylvania-based cybersecurity firm. Matt spends his working hours talking to criminals on the dark web on behalf of clients whose systems have just been encrypted, whose data has just been exfiltrated, or  frequently both. He was joined onstage (in spirit, anyway) by his colleague Dave Zofran, who Matt repeatedly tried to make wave at the audience and who, in the great tradition of every backstage engineer at every conference ever, was having none of it.

This was easily one of the best talks of the day. Matt is jokey, sweary, self-deprecating, and irreverent, and the audience stayed well past the scheduled end for a Q&A that ended only because it was time for the closing keynote and raffle for Chris Machowski’s amazing BSides posters. Here’s what I took away.

“My career is a series of clerical errors”

Matt opened by describing his career path as “mostly an annoying inability to say no to things.” Somebody asked him if he wanted to do physical penetration testing. Sure. Forensic analysis school? Sure. Want to talk to criminals on the dark web? Hell yeah. Do you know what you’re doing? Not a clue. We’ll figure it out.

He compared himself to Jim Carrey in Yes Man, which he claimed was autobiographical. As somebody whose own career has been driven in no small part by saying yes to the next weird thing (DevRel, accordion-on-stage, organizing meetups, writing this blog for two decades), I felt seen.

Before getting into the meat of it, Matt did a room survey: students, IT folks (“the unpaid group, maybe the underpaid group”), cyber pros with one-to-five years (“the unjaded ones, because you still believe you can make a difference”), and the over-fives (“the unbothered”). Then he asked if there were any vendors in the room, and offered them the mic. Nobody took him up on it. They know a trap when they see one.

Myth-busting: paying ransoms, double-dipping, and “why does this exist?”

Matt opened with a couple of myths he wanted to put to bed.

Myth number one: Paying ransoms is illegal. Nope. Some payments are illegal, specifically payments to entities on the OFAC sanctions list, which is why you don’t want amateurs handling the wire. Ransom payment as a category is not, in itself, against the law.

Myth number two: You don’t always get what you pay for. Mostly false, with caveats. Double and triple extortion happen, but in Matt’s experience, they’re typically different groups exploiting the same unpatched Fortinet firewall (a refrain that came up roughly every six minutes during the talk; more on that in a moment), and not the original group going back on its word. Reputable ransomware crews are, weirdly, reputable, and that’s because their business model depends on it.

There is, however, no certification body for what Matt does. He has a GCFA, meaning that he’s a certified forensic analyst, but there’s no such thing as a certified-ransomware-negotiator credential. He quoted Jon DiMaggio (whom he says everyone calls ”Joe”) on the state of the field: nobody can really tell you whether you’re good at this job. You learn it the way Jason Statham’s character in The Mechanic learned his trade: “Good judgment comes from experience, and a lot of that comes from bad judgment.”

And on the moral question of “Why do negotiators exist at all? Doesn’t paying ransoms just feed the system?”, Matt invoked Tony Stark from the first Iron Man (alas, he’s no fan of the sequels): “It’s an imperfect world, but it’s the only one we got. The minute we don’t need threat actor negotiators anymore, I will build bricks and beams for baby hospitals.”

The ransomware industry is, in fact, an industry

Probably the most important reframe in the talk (and one I’m going to be repeating to people at NetFoundry and at Tampa Bay AI meetups) is that the mental image of “ransomware operator” most non-security people still carry around is wildly out of date.

The kid in his mom’s basement, surrounded by cold pizza, while she yells about meatballs? Not a thing anymore. Or more accurately, never coming back to a screen near you. Modern ransomware groups are full-on enterprises with:

  • Ransomware developers
  • Initial access brokers
  • Software and codebase maintainers
  • AI specialists (yes, really)
  • Web devs building the victim portals
  • Customer service / “help desk”
  • Translators (or rather, prompt engineers driving Google Translate and Claude and ChatGPT)
  • HR. HR.

“I don’t know if they have benefits,” Matt said. “The minute they have benefits, I might consider a career change.”

These aren’t lone actors. They’re businesses, and in many cases they’re tacitly or explicitly protected by their host governments because the money flowing back into their towns and villages props up local economies. As Matt put it: they’re heroes where they live. Which is one of those facts about the modern threat landscape that you have to sit with for a minute before you can keep going.

The shift to enterprise has changed everything about negotiation strategy. The old groups sometimes had a moral compass; for example, there was a group that would hand over decryption keys for free if they realized they’d accidentally hit a hospital, and another that announced they were retiring after they hit a billion dollars and then actually published a master decryption key on their way out. Those days are over. Today’s groups operate on margin and SLA, like any other B2B company. They just happen to be in the extortion vertical.

“Why use a negotiator?” Because you know everyone at your company.

Here’s a part of the talk worth keeping in mind should you find yourself or your company at the mercy of a ransomware organization.

Matt asked how many of us had worked at our current job for more than a year. Then more than five. Then more than ten. Then he asked the ten-plus hands: do you have kids? Because if you do, you have worked with these people longer than your kids have been alive. You know your coworkers better than you know your spouse, your friends, sometimes your own children.

Which means when your company gets ransomed, you’re most likely not going to be a calm, collected, rational actor. You’re a person watching your work-family bleed out, and you will do dumb things because of it. This is exactly why, in hostage negotiations, local PD will bring in officers from another jurisdiction the moment they realize anyone involved knows anyone involved. Emotional distance is the whole point.

A negotiator isn’t there because they’re smarter than you. They’re there because they don’t know your accounts receivable manager who just had her first kid, and that distance is, perversely, a gift.

The other thing negotiators bring is pattern recognition across hundreds of cases. There are really only two companies in the U.S. that actually facilitate ransom payments because it’s a risky line of work. Matt didn’t name them, but they’re not hard to find, and the negotiators who work with them have visibility into asks, settlements, durations, and outcomes that no individual victim can possibly have. Which brings us to the data.

Ransomware company discount curves

Hey, actual numbers!

Matt put up actual data from the last 12 months of facilitated payments. I’m reproducing the highlights here because they’re genuinely useful for anyone thinking about cyber insurance, incident response runbooks, or just calibrating their understanding of the threat landscape.

Akira (traditional / technical, business-oriented group)

  • Average initial ask: ~$1.3 million
  • Average settled payment: ~$429,000
  • Average discount: 60–70%
  • Average duration: ~20 days

Qilin (pronounced “CHEE-lin”; it’s Chinese and denotes a magical creature close in spirit to a unicorn or magical giraffe)

  • Average initial ask: ~$800,000
  • Average discount: ~62.5%, but with a hard floor around 50%
  • Tighter statistical clustering than Akira

ShinyHunters (the new kids; social engineering and help desk scams)

  • Much higher initial asks
  • Average discount: ~71%
  • Much shorter duration. Matt called it “almost like a fire sale.” I like to think of them as the TJ Maxx or Ross of malware.

The shape of the discount curve is the interesting part: time on the x-axis, percent off on the y-axis, and the curve goes up and to the right. Like buying a car, except the dealership is in a sanctions-adjacent country and the test drive is your production environment.

A practical consequence: if you’re paying for recovery (your systems are down, you’re hemorrhaging money), you pay faster and you pay more. If you’re paying for suppression (they didn’t encrypt anything, they just exfiltrated data and are threatening to leak), you can drag it out for a bigger discount. Which is exactly what we just watched happen with Canvas — Instructure ultimately paid for suppression and “shred logs,” not recovery.

The Black Basta “I had COVID” story

The single best war story of the talk involved Black Basta about a year and a half ago. The Black Basta victim portal, Matt said with what sounded like genuine professional admiration, is gorgeous. Looks like iMessage. Read receipts. Tight UX. “I wanted to send a meme. It doesn’t support that. The first ransomware group that allows GIFs [in their chats] is gonna be a work of art.”

But at the top of the portal: a countdown timer. Six days, twenty-three hours, fifty-nine minutes, fifty-eight seconds. Tick.

Matt was working a real case, was actually going to pay, and needed to stall. So he asked for more time. They gave him seven days. He asked again the following week. Seven more days. He was feeling pretty pleased with himself when, on the Friday of week three, they finally said: no more extensions. Pay or else.

Then Matt got on a flight home from Denver to King of Prussia, PA (which, as he pointed out, sounds like a Batman villain, as does his other hometown, Wayne, and look, I lived in Wayne; I can confirm it sounds exactly like the kind of place Bruce Wayne would buy a second house). He proceeded to get deathbed sick. Lost an entire weekend. Woke up Monday morning with roughly forty hours left on the clock and a portal full of increasingly unhinged messages from his criminal counterparts: “Are you there? Hello! I’m serious. Don’t make me do what I’m going to do.”

Matt typed back: “Really sorry, I got super sick. I think I had COVID.”

They gave him seven more days.

Matt’s rules of engagement (lightly paraphrased and worth tattooing somewhere)

He’s a flat-fee operator. Never a percentage of savings — because at that point you’re not a negotiator, you’re a co-conspirator with a conflict of interest. (The two negotiators who got federally indicted for actively colluding with ALPHV BlackCat are the cautionary tale he doesn’t want to become.)

He will lie to criminals with abandon, but he won’t lie to clients.

He won’t negotiate in bad faith. If you tell him “just stall, we’re never paying a dime,” he walks. Because he’s seen what happens when threat actors realize they’ve been strung along. He told a story about a client that changed their mind at the last minute after a long negotiation. The group responded by publishing pediatric patients’ Social Security numbers on Facebook. One. At. A. Time, in a slow, painful, drip campaign.

He does not hack back. He has heard of illicit activities waivers. They take two to three years to get and they are not a Get Out of Jail Free card. They are, at best, a “you probably won’t go to jail” card.

He does not facilitate the actual payment, because (a) money laundering, (b) OFAC compliance is a specialty unto itself, and (c) the two payment-facilitation firms have current data on which Bitcoin addresses and chat fingerprints map to which sanctioned entities. He just does the talking.

The four things he wants from every threat actor

When Matt’s at the table, he is always asking for the same four things:

  1. The decryption key. Of course.
  2. Proof of deletion. Typically a screenshot, ideally a video. He has an eight-hour video of someone DoD-wiping a drive somewhere in his archive.
  3. How they got in. No guarantees on how honest they’ll be; sometimes ransomeware operators will literally copy-paste from a different victim’s report. Matt and another negotiator once compared notes and got the exact same “you had a Fortinet firewall” attribution for clients who, respectively, ran Meraki and Cisco.
  4. A promise to never do it again. Worth roughly what you’d expect, but worth getting in writing.

If he can get those four, he’s done his job.

Q&A

The Q&A ran long. A few highlights:

Where do ransomware group names come from? Matt blames CrowdStrike. Honestly, fair. “Every cool t-shirt you’ve ever gotten from Black Hat came from the CrowdStrike booth.” I jumped in to point out that Qilin (pronounced “CHEE-lin”) is a Chinese mythological creature usually translated as “unicorn” or, more delightfully, “magic giraffe.”

Is ransomware seasonal? Absolutely. American holidays, especially Thanksgiving, are target-rich, because skeleton crews and four-day weekends mean defenders are slow to respond. Attackers also take vacations themselves. Ransomware drops off in the summer months. Because who wants to be at their computer when the weather’s nice? Even criminals deserve a beach day.

Are you ever personally targeted? Matt’s whole career is built around not announcing himself as a negotiator on the live chat. He plays the dumb IT guy. He’s got a story about a colleague suggesting they ask the threat actor what a “botcoin” is (after one of them mistyped “Bitcoin” in a chat), and the threat actors spent two days patiently explaining cryptocurrency to him. “Best time stall ever.”

What about emotional toll? Matt has been a paramedic, a cop, and a firefighter. “I don’t know of a crisis I haven’t run head-first into. It’s a programming defect from up top.” Then: “Better living through pharmacology. Oh God, don’t call my therapist.”

What industries get hit hardest? Manufacturing. Not necessarily the most often, but the hardest, because of legacy systems. He told a story about a Pennsylvania university that literally cemented a Novell NetWare box into a basement wall during construction because it was running directory services and they didn’t want to unplug it. It’s been running since the ’80s. It’s still there.

Why I’m writing this up

Two reasons.

One: BSides Tampa is a regional con and the speaker quality this year was outstanding. Matt’s talk in particular deserves a wider audience than the room it ran in. It could’ve been a keynote.

Two: I spend most of my professional life right now thinking about zero trust and AI-plus-network-security at NetFoundry, and what Matt’s talk drove home (better than any threat report I’ve seen lately) is that the human layer of incident response is where most of the leverage is. You can do everything technically right at the perimeter and still lose a six-figure negotiation because somebody on your team panicked, told the truth at the wrong moment, or said the magic words that flipped a transactional extortion into a personal vendetta. Zero trust as a philosophy (not just a product category) is partly about acknowledging that humans will always be the soft target, and designing accordingly.

Also: I am now permanently delighted by the idea that every ransomware negotiator on the planet should adopt the alias “Matt” so that threat actor groups go forever convinced that U.S. companies are staffed by an army of identically-named slow-witted staff who don’t know what Bitcoin is. Matt, if you read this, I’m in. Sign me up.

Big thanks to Matt Barnett and SEVN-X for an outstanding session, and to the BSides Tampa crew for putting on one of the best regional security cons in the Southeast!

Categories
Conferences Tampa Bay

poweredUp Tampa Bay Tech Festival 2026

Here’s something you might not know about the poweredUP Tampa Bay Tech Festival (which happens tomorrow): because I decided to attend it, I landed a job — and this has happened not once, but twice!

The reason poweredUP Tampa Bay Tech Fest led to those jobs is because a lot of tech industry people here in “The Other Bay Area” also attend. If you’re looking to meet technology leaders, innovators, entrepreneurs, and students, they’re at poweredUP, and they make it an opportunity-rich environment.

They’re mixing up their usual formula this year with a new format whose aim is to give attendees both the big-picture view of where technology is heading in Tampa Bay and the practical knowledge they can take back to their teams.

Here’s what’s on the agenda:

  • Job Seeker Hiring Event with High Tech Connect
    This will start at 10:30 (a little earlier than the rest of the conference) and it’s your chance to see who’s hiring and who’s looking! Bring your resume and your A-game.
  • The State of Tech – Tampa Bay
    They’ll kick off the day with a forward-looking conversation about how technology (and especially AI) is shaping Tampa Bay’s economy, workforce, and innovation ecosystem. They’ll have regional leaders, founders, and industry experts talk about the momentum building across our tech community and what it means for the future of our region.
  • Networking + Exploring Geek Row
    My favorite part! It’s happens in the part of the Mahaffey with the big windows and the view of the Bay, where you can connect with fellow attendees, meet innovative companies, and explore the Geek Row exhibitor area, where you can see what the local tech companies and orgs are up to.
  • Technical Keynote + Deep-Dive Sessions
    In the afternoon, poweredUP shifts into technical programming, featuring an inspiring keynote and multiple tech tracks focused on real-world implementation and best practices across today’s most important technologies.
  • More Networking + Happy Hour
    Wind down and reflect on the day’s insights with fellow attendees at our celebratory happy hour. Enjoy two complimentary drink tickets (21+) and build lasting connections in a relaxed setting.

Over the years, poweredUP has become a cornerstone event for Tampa Bay’s tech community, bringing people together to learn, collaborate, and spark new ideas about what’s next.

And I’ve said before, it’s led to some very nice outcomes for me. Go on May 20 and be part of the conversation shaping the future of technology in Tampa Bay!

Here’s where you can register for poweredUP Tampa Bay Tech Fest.

Categories
Conferences Editorial Security Tampa Bay

Go to BSides Tampa, because 80% of success is showing up

The 13th edition of BSides Tampa is happening tomorrow, Saturday May 16. It’s not too late to get tickets ($45 for general admission, $30 for students and military), and you can save 20% by using Tampa Devs’ discount code, TampaDevs20_BSIDESTAMPA_2026.

There are plenty of reasons to attend BSides Tampa, a cybersecurity conference that brings in 2,000+ attendees, including…

  • Great keynotes and presentations across seven tracks: keynotes, red team, blue team, cloud security, GRC and privacy, appsec, and AI and emerging
  • The exhibitor hall, where they don’t scan your badge, which means that you won’t get spammed as a result and they won’t sell your info
  • Interactive villages: malware, social engineering, IOT, network, lockpicking
  • A chance to meet the technology and cybersecurity professionals in the area, including these two…

But the most compelling reason I can think of to go is…

Let me repeat that:

80 percent of success is just showing up.

Let me illustrate with a story. Last May, techie-about-town Ammar Yusuf said he could hook me up with a free ticket to VueConf, which was taking place right here in Tampa.

I’d just come back from an expensive two-week trip, and I was still operating as an independent consultant. The spring and summer of 2025 were pretty slow; the well of clients was running dry.

I was strongly tempted to turn down the free ticket so I could devote more time and energy to finding my next job or client. Some might argue that it would be the smart thing to do.

But I decided to take the free ticket and go to VueConf instead, because I remembered all those times when showing up led to great things. Again, I remind you:

At VueConf, I met one of the organizers, Pratik Patel. When he came here in February, I decided to say hi and attend the Java User Group meetup where he gave a talk about AI architecture, pictured below:

I ended up chatting with Pratik, who then offered both me and Anitra free tickets to the Dev/Nexus conference in Atlanta that would take place a couple of weeks later. It was short notice, and Atlanta’s a 7+ hour drive from Tampa. But we remembered the rule:

So we went, learned a lot, and had a great time:

And while we were at Dev/Nexus, I ran into Pratik, who was walking the exhibitor floor with Venkat Subramaniam, who knows me because I show up to his talks whenever he comes to town.

Here’s the “Bollywood Buddy Movie Poster” photo taken at the meetup where I met Venkat:

When I ran into Pratik and Venkat at Dev/Nexus, Pratik suggested to Venkat that I speak at the Arc of AI conference that would take place the following month. Venkat thought that would be a good idea, and asked me to submit a couple of talk proposals. So I did, even though I was knee-deep in contract work and a job search, because…

My submissions got accepted, and the result was my talk about writing documentation and example code for consumption by AI agents:

…and I met a lot of people:

And here’s the kicker: not only did I get to meet new people and attend (and speak) at conferences, but all this helped me land my current job at NetFoundry. The fact that I’d managed to land a speaker gig at Arc of AI was a key point in my job interviews. And I wouldn’t have the key point for that interview if…

  • I didn’t speak at Arc of AI, which wouldn’t have happened if
  • I didn’t apply to speak at Arc of AI, which wouldn’t have happened if
  • I didn’t go to Dev/Nexus, which wouldn’t have happened if
  • I didn’t go to Pratik’s talk at the Tampa Java User Group meetup, which wouldn’t have happened if
  •  I didn’t go to VueConf with the free ticket Ammar gave me.

The lesson here is simple:

So if you don’t have prior commitments and you can afford to do so and you’re in a tech/tech-adjacent/cybersecurity/cybersecurity-adjacent field — and especially if you’re looking for work — consider going to BSides Tampa tomorrow, because you know what showing up can do for you!

Once again, ticket prices are:

  • $45 for general admission
  • $30 for students and military

…and you can save 20% by using Tampa Devs’ discount code, TampaDevs20_BSIDESTAMPA_2026.