UtahSAINT/SAINTCON, past, present, and future

Jup1t3r (Jup1t3r)

SAINTCON 2025 · Day 4 · Main Track 1

Overview

This talk, delivered by Jup1t3r, a foundational figure within the UtahSAINT organization, offers a candid, behind-the-scenes look at the evolution, challenges, and future trajectory of SAINTCON, Utah's premier cybersecurity conference. Far from a typical technical presentation on vulnerabilities or exploits, this session delves into the intricate operational complexities of scaling a community-driven event from a modest gathering to a major industry fixture. Jup1t3r provides a transparent account of the hurdles faced by an all-volunteer team managing exponential growth, financial demands, and the critical need to preserve the conference's unique culture.

Watch on YouTube

Visual summary for UtahSAINT/SAINTCON, past, present, and future by Jup1t3r
Visual summary for UtahSAINT/SAINTCON, past, present, and future by Jup1t3r

Key moments

  1. 0:00 Introduction to UtahSAINT and its founding
  2. 2:00 Joining the UtahSAINT community: organic growth
  3. 4:00 How to get involved: high-level planning committee
  4. 4:40 How to get involved: staff for contests and events
  5. 6:00 How to get involved: hundreds of volunteer positions
  6. 7:00 How to get involved: submitting talks as a speaker
  7. 8:00 Beginning to discuss SAINTCON's operational challenges

UtahSAINT/SAINTCON, past, present, and future

Speakers: Jup1t3r (Jup1t3r)

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=b08YeU9UDoA

Overview

This talk, delivered by Jup1t3r, a foundational figure within the UtahSAINT organization, offers a candid, behind-the-scenes look at the evolution, challenges, and future trajectory of SAINTCON, Utah's premier cybersecurity conference. Far from a typical technical presentation on vulnerabilities or exploits, this session delves into the intricate operational complexities of scaling a community-driven event from a modest gathering to a major industry fixture. Jup1t3r provides a transparent account of the hurdles faced by an all-volunteer team managing exponential growth, financial demands, and the critical need to preserve the conference's unique culture.

The presentation serves as both a historical retrospective and a forward-looking strategic discussion, appealing not only to attendees curious about the conference's inner workings but also to organizers of other community events grappling with similar growth pains. It underscores the immense dedication required to maintain a high-quality, impactful conference while navigating the realities of volunteer fatigue, logistical nightmares, and the ever-present threat of losing its core identity. Jup1t3r’s insights are invaluable for understanding the human and operational infrastructure that underpins successful large-scale technical gatherings.

Background

▶ Watch: Introduction to UtahSAINT and its founding (0:00)

The SAINTCON conference is the flagship event of the UtahSAINT organization, a 501(c)(6) nonprofit membership organization founded in 2014. While the conference itself predates the official organization, its formal structure as UtahSAINT provided the framework for its growth. Initially conceived as a local gathering to foster the cybersecurity community within Utah, the organization and its conference have since expanded their reach "far beyond" state lines, attracting participants from across the globe.

In its nascent stages, SAINTCON was a significantly smaller affair, catering to approximately 300 people. Jup1t3r reminisces that scheduling and managing a conference of that size, though seemingly daunting at the time, was "simple and easy" in hindsight. The early days saw various attempts at structuring community involvement, from vetted membership to a more open, organic approach. Currently, there isn't an official sign-up method for the UtahSAINT community; participation in the Discord server or attendance at SAINTCON signifies belonging. This organic growth reflects the organization's core philosophy: SAINTCON is "first and foremost a community conference, not a security conference," a distinction that heavily influences its operational decisions and cultural preservation efforts.

Over the years, the process for community involvement has become more structured to manage the increasing scale. Key opportunities for participation include:

  • Call for Committee: Occurs in January, seeking high-energy individuals for "planning committee" positions, akin to department heads, who commit from January through the conference.
  • Call for Contest, Community, and Event Staff: Held between February and March, this solicits individuals and teams to bring content, run contests, or organize community events.
  • Call for Volunteers: Generally happens between April and May, recruiting hundreds of individuals for on-site roles like badge checking, AV support, and general assistance.
  • Call for Speakers/Presentations: Also in the April-May timeframe, this is for individuals to propose and deliver technical or community-focused talks. The growing popularity of SAINTCON has made this increasingly competitive, with the conference now in a position to "deny presentations" dueating to the high quality and volume of submissions. This marks a significant evolution from earlier days where a handful of individuals carried the bulk of the content.

Key Findings

▶ Watch: How to get involved: high-level planning committee (4:00)

The talk highlights several critical findings resulting from SAINTCON's rapid expansion, presenting a complex interplay of growth, sustainability, and cultural preservation:

  1. Explosive Growth and Capacity Limits: SAINTCON has officially crossed the 2,000 people threshold, a number the organizers "never thought would ever be interested in cyber security in the state of Utah." This year, all tickets sold out in an unprecedented 28 hours, demonstrating immense demand. However, this growth is seen as a double-edged sword, pushing the conference to its current venue's capacity and straining its all-volunteer operational model. Jup1t3r explicitly states that 2,000 attendees will be the maximum limit going forward, a decision driven by the need to maintain quality and culture.
  1. Sustainability Crisis and Volunteer Burnout: The most significant challenge is the sustainability of an "all volunteer effort." Committee members, including Jup1t3r himself, dedicate "nights, weekends, more nights, more weekends" from January until the conference. This intense commitment leads to widespread fatigue and burnout, resulting in turnover at the highest levels. Jup1t3r notes that at least two committee positions will see new faces next year, highlighting the fragility of relying solely on volunteer passion for such a large operation. This burnout also creates knowledge transfer issues, making it difficult to maintain the conference's unique feel and established successes without institutionalizing processes.
  1. Erosion of Culture and Community: As the conference grows, there's a profound concern about "losing the culture" – the "community, that family reunion style cyber security group" feel. The fear is that SAINTCON could transform into a more commercialized event where "so many people competing and writing bots for buying all the tickets," shutting out long-standing community members. To counteract this, efforts are being made to provide early registration opportunities for core community members, some of which will be "underground" to protect against general public competition.
  1. Logistical Overload and Infrastructure Strain: Managing a 2,000-person event creates immense logistical challenges. Simple tasks, like producing 2,000 badges, become full-time, multi-month endeavors for dedicated teams. Basic infrastructure like power strips becomes a "commodity" on setup day, disappearing rapidly. The talk also details significant strain on network infrastructure, which is further elaborated in the technical deep dive. Beyond physical logistics, the administrative burden of operating a 501(c)(6) nonprofit with ticket sales exceeding $1 million necessitates hiring professional accountants and developing robust policies, procedures, and governance structures, moving beyond the capabilities of a purely security-focused volunteer team.
  1. Content Alignment in a Diversifying Industry: The rapid expansion of the cybersecurity industry itself (red team, blue team, AI, API, appsec, pentesters, etc.) makes content alignment increasingly difficult. Curating presentations that cater to such a broad spectrum of niches while maintaining quality and relevance is a continuous challenge for the program committee. The goal is to ensure attendees can still find that "one nugget presentation" relevant to their specific interests.

Technical Deep Dive

▶ Watch: How to get involved: staff for contests and events (4:40)

While SAINTCON is a security conference, Jup1t3r's talk focuses not on traditional security vulnerabilities but on the technical and logistical challenges inherent in operating such a large-scale event. The "technical deep dive" here pertains to the infrastructure and operational hurdles faced by an all-volunteer team.

A primary technical challenge is network infrastructure for 2,000+ attendees. Jup1t3r highlights the sheer scale of demand: "many times during this week that we've seen well over 2,500 devices sitting on the network at any given time." The data throughput is staggering, with the conference moving "4.8 petabytes of data in and out of here" in just two days. This massive data transfer, attributed jokingly to "Cali downloads or whatever you guys are doing," underscores the need for robust, high-capacity networking. The organizers made a strategic decision this year to bring in "some of our own" network infrastructure to test its capabilities and better understand actual demands, indicating a proactive approach to managing this critical resource. This experimentation is a testament to the volunteer team's dedication, as finding "volunteer expert[s] willing to come in and spend an entire week just troubleshooting networking" is a significant ask. The speaker acknowledges that while the network generally performed well, they might "revert back to some of the old things" based on their findings, indicating an iterative, data-driven approach to infrastructure management.

Beyond networking, power management presents another recurring operational hurdle. Although the Utah Valley Convention Center provides "so much power, it's amazing," the distribution and availability of power strips become a significant problem. Jup1t3r describes how "power strips seem to disappear" and became a "commodity on Monday during setup day," highlighting a critical, often overlooked logistical detail for any hardware-intensive technical event.

The production of the conference badges also represents a unique blend of technical and logistical complexity. Jup1t3r clarifies that the badge itself isn't a "huge technical challenge" in terms of groundbreaking code, but the process of producing 2,000 custom badges is a massive logistical undertaking. This involves "getting the boards into the country, getting them all picked and placed, doing all of the error corrections, all those things." He contrasts this with the early days when "150 to 200 badges" could be "hand solder[ed]," emphasizing that 2,000 units require a completely different scale of manufacturing and quality control. The badge team dedicates full-time "nights and weekends since about July" to this task, illustrating the immense volunteer effort behind a seemingly simple conference component.

Finally, the alignment of content for presentations is a continuous technical and intellectual challenge. With the cybersecurity industry expanding into myriad niches—from red team and blue team operations to emerging fields like AI team, API security, appsec, and pentesters—curating a program that caters to diverse professional interests is increasingly complex. The goal is to ensure that even with broad appeal, attendees can still find specialized, "niche sort of cyber security thing[s]" that resonate with their specific research or practice areas. This requires a deep understanding of current industry trends and the ability to identify compelling, relevant speakers amidst a growing pool of submissions.

Demo / Proof of Concept

▶ Watch: How to get involved: submitting talks as a speaker (7:00)

Given the nature of Jup1t3r's talk as an organizational update rather than a technical security presentation, there was no traditional "demo" or "proof of concept" of a vulnerability or tool. Instead, the SAINTCON conference itself serves as the ongoing proof of concept for the UtahSAINT organization's ability to execute a large-scale, high-quality event with an all-volunteer team.

However, the talk indirectly references several elements that function as practical demonstrations of cybersecurity concepts and community engagement:

  • The Conference Badge Game: Jup1t3r mentions that the badge team kept the "badge game very quiet," allowing even him to "go around and wrench things just like you all did for a little bit" and enjoy the interactive challenge. These custom-designed badges often incorporate embedded systems, microcontrollers, and various electronic puzzles, serving as a hands-on technical challenge for attendees, demonstrating principles of hardware hacking, reverse engineering, and problem-solving in a fun, engaging format.
  • Past and Present Contests: The speaker recalls earlier contests such as Los Santos Hardcore, described as a "physical security escape challenge," where participants "instead of breaking in, you're breaking out." This type of event provides a tangible, real-world scenario for understanding physical security vulnerabilities. He also notes that "The Vault today" is "a lot more like the original vault," which was a "physical security breakin challenge" involving "compromised cameras and motion sensors and door locks and all the different things to try and break in." These contests are not merely games but serve to "teach physical security and you know the importance of some of the different technologies and things that we use," offering practical, experiential learning.
  • Family Night: While potentially evolving into a separate event, Family Night (mentioned as Jup1t3r's "favorite event") serves as a proof of concept for community outreach and early engagement in cybersecurity. It provides an opportunity for children to "get down on the floor, help some kid figure something out, see those aha moments," exposing them to STEM and security concepts through hands-on projects and activities. This demonstrates the organization's commitment to fostering the next generation of cybersecurity professionals and enthusiasts.

In essence, the "demo" of this talk is the living, breathing conference environment, where technical challenges are presented as interactive games, and community engagement is fostered through various hands-on activities, all orchestrated by a dedicated volunteer force.

Defensive Implications

▶ Watch: Beginning to discuss SAINTCON's operational challenges (8:00)

For an organization like UtahSAINT, "defensive implications" shift from protecting IT systems to defending the longevity, culture, and operational integrity of the conference itself. Jup1t3r's talk outlines several strategies—both explicit and implicit—that serve as "defenses" against the challenges of growth and burnout.

  1. Proactive Community Engagement and Succession Planning: To combat volunteer burnout and knowledge transfer issues, SAINTCON actively solicits involvement at all levels: committee, staff, and general volunteers. The emphasis on "nag[ging] the crap out of them" for consistent interest highlights the need for persistent, organic engagement to identify future leaders. Critically, Jup1t3r acknowledges the need for succession planning as long-term committee members tire. This involves consciously identifying and training replacements to ensure the conference's core feel and successful elements are retained, rather than allowing it to "die and let something fill that void." This is a defense against the loss of institutional knowledge and leadership.
  1. Cultural Preservation Strategies: The threat of losing SAINTCON's "family reunion" culture is a significant concern. The proposed "underground" early registration opportunities for established community members is a direct defensive measure against ticket scalping and commercialization, aiming to prioritize the loyal community over new, potentially less engaged attendees. This strategy seeks to maintain the intimate, welcoming atmosphere despite the large attendance numbers. Jup1t3r also emphasizes maintaining a "clean environment where you where you feel comfortable bringing your kids to St. con," balancing the raw authenticity of A-list speakers with community values.
  1. Robust Financial and Administrative Governance: Crossing the $1 million threshold in ticket sales necessitates a stronger financial defense. Hiring accountants and developing formal policies, procedures, processes, governance, and compliance mechanisms are crucial. This professionalization is a defense against financial mismanagement, legal liabilities, and ensuring the organization's long-term stability and transparency as a 501(c)(6) nonprofit. It shifts the burden from volunteers to specialized professionals for complex administrative tasks.
  1. Strategic Logistical Foresight: Addressing the logistical overload requires proactive planning. The decision to cap attendance at 2,000 people is a defense against exceeding venue capacity and overwhelming volunteer resources. Experimenting with their own network infrastructure for 2,500+ devices and 4.8 petabytes of data is a defense against potential network failures and ensures a high-quality technical experience. Similarly, the early start to badge production (July) and volunteer recruitment (April-May) are defenses against last-minute logistical crises.
  1. Adapting to Industry and Community Needs: The challenge of content alignment in a diversifying industry is addressed by actively seeking out "niche sort of cyber security thing[s]" and encouraging diverse speakers. The potential evolution of Family Night into a separate, dedicated event held during the summer is a defense against burning out conference staff by trying to integrate too many disparate events into a single, intense week. This allows both the main conference and the family event to flourish with dedicated resources and planning.

In essence, the defensive posture of UtahSAINT is one of strategic adaptation, community empowerment, and professionalized oversight to ensure SAINTCON remains a sustainable, culturally rich, and impactful event for the cybersecurity community.

Key Takeaways

  • Growth is a Double-Edged Sword: SAINTCON's unprecedented growth to 2,000+ attendees, selling out in 28 hours, has created significant sustainability challenges for its all-volunteer operational model, leading to a hard cap on future attendance.
  • Volunteer Burnout is a Critical Threat: The intense, year-round commitment required from committee members leads to fatigue, burnout, and turnover, posing a serious risk to knowledge transfer and the long-term stability of the conference.
  • Cultural Preservation is Paramount: Maintaining SAINTCON's unique "community conference" and "family reunion" atmosphere is a top priority, with strategies like "underground" early registration being explored to protect against commercialization and ticket scarcity.
  • Logistical Demands are Immense: Running a conference of this scale involves massive logistical hurdles, from producing 2,000 custom badges over months to managing 4.8 petabytes of network data for 2,500+ devices in just two days.
  • Financial and Administrative Complexity Requires Professionalization: Exceeding $1 million in ticket sales necessitates hiring accountants and establishing robust governance, policies, and procedures, moving beyond purely volunteer-driven administration.
  • Future Hinges on Community Involvement and Succession: The confirmation of SAINTCON 2026 is accompanied by an urgent call for increased community involvement and proactive succession planning to ensure the conference's long-term viability and mitigate the risk of "drama or frustrations" leading to its demise.

About the Speaker(s)

Jup1t3r, the speaker for this insightful session, is a highly dedicated and foundational figure within the UtahSAINT organization and the SAINTCON conference. As one of the primary drivers behind the event's growth and continued operation, he holds a deep, personal connection to its mission and community. His role extends far beyond a typical speaker, encompassing significant responsibilities in the logistical, financial, and strategic planning of the conference.

Jup1t3r openly shares the personal toll of his commitment, describing "nights, weekends, more nights, more weekends" of effort, leading to fatigue and burnout. Despite the immense stress and anxiety associated with planning such a large-scale event, he remains passionately committed to the community, viewing SAINTCON as a place for attendees to "relax" and "recharge your batteries." He is often recognized as the public "face" of the conference, yet he humbly emphasizes the collective effort of the many volunteers who work "just as hard or harder" behind the scenes. His talk reflects a transparent and heartfelt dedication to the unique culture and continued success of SAINTCON.

All talks from SAINTCON 2025