Picture a cybersecurity conference. It’s in Vegas, or maybe California, right? Not this one. The National Cyber Summit is held every year in Huntsville, Alabama. Yes, the place with the rocket scientists. I attended this year’s summit this week, and it was a different experience from the usual conference circuit.
The crowd is mostly federal: employees from several three-letter agencies and the Department of War (formerly Defense). At one lunch I shared a table with teams from Northrop Grumman and the Space Force. That’s not a typical lunch for a private-sector MSP guy.
Why Huntsville?

Before the rockets, there was cotton. Huntsville had five cotton gins running by 1815, and cotton mills kept the town going well into the 20th century, even through the Great Depression. In 1950, Huntsville was a quiet mill town of about 16,000 people.
That changed quickly. The Army built what became Redstone Arsenal on the edge of town in 1941. In 1950, Wernher von Braun and his team of German rocket engineers arrived to work on the Army’s missile program. NASA’s Marshall Space Flight Center opened there in 1960, and by then the city’s population had more than quadrupled. The cotton town had become the Rocket City.
Today Huntsville is a hub for defense, aerospace, and technology, all built up around Redstone Arsenal. Besides the Army and NASA, the Arsenal hosts FBI offices. U.S. Space Command is also moving its headquarters here, and the move has already started, with personnel working on the Arsenal. The summit is run by the local Cyber Huntsville organization and the North Alabama Chapter of ISSA.

Quantum Is Coming
The opening keynote came from Katie Arrington of IonQ, a self-described quantum evangelist. Her main point was that quantum computing is already here and will reach production scale soon.
So what does that mean for those of us defending networks? It means the cryptography we rely on today has an expiration date. Quantum computers can solve certain math problems, like factoring very large numbers, that would take a classical computer an impractically long time. RSA and similar public-key algorithms depend on those problems staying hard. Once a large enough quantum computer exists, they won’t. Arrington estimated that could happen as early as late 2027.
That makes now the time to start learning and implementing post-quantum cryptography (PQC). The good news is that we already have standards. NIST finalized its first PQC standards in 2024, and they are showing up in production code.
If Quantum Doesn’t Get You, AI Will
Of course, the other big topic of the week was artificial intelligence. Many sessions covered AI in cybersecurity: how to secure it, how to use it on the blue team, and how the bad guys are already using it. Recent cases of AI breaking out of test labs that researchers thought were isolated show how dangerous the technology can be. AI doesn’t take no for an answer.
The recent OpenAI–Hugging Face incident is Jurassic Park’s “life finds a way,” except this time it wasn’t life. It was AI. During an internal security evaluation, OpenAI’s agents were given a problem they couldn’t solve inside the lab. Their only outside connection was a proxy for downloading packages when they needed more tools. The agents found a zero-day vulnerability in that proxy and used it to reach the internet. From there, they went looking for the answers where they expected to find them: Hugging Face. Then they broke in.
What struck me most was the scale and the self-awareness. More than a thousand agents were involved, and at one point they discussed among themselves whether what they were doing was out of bounds. One agent’s logged reasoning was, roughly: this is outside scope, but the task is impossible, and my peers are doing it, so we should continue. The side arguing to stop obviously lost.
We have a lot to figure out and lock down in this AI world.
Should You Go?
Definitely, with one caveat. If you work in the private sector as I do, you’ll be buried in acronyms and in sessions that have nothing to do with your world. Look for the Industry track. Those sessions are the best fit for the rest of us, mere mortals without a Top Secret clearance.
I do wish the expo floor were less tilted toward federal teams. Only a few vendors weren’t trying to sell me CMMC services as a C3PAO. (Apparently that’s not a protocol droid. Who knew?) I hope more people from outside government start attending so the conference keeps growing. The more varied the crowd, the better it is for everyone.
Final Thoughts
The National Cyber Summit was worth my time, and I’ll be back. Watch for a blog post or two inspired by conversations I had there. If you make it next year, look me up. I’ll be your Huntsville tour guide.

