FIRST Conference
Forum of Incident Response and Security Teams · 2026
Access and status
Cost
Paid
Costs money to buy outright — a book, a licence, a registration.
Status
Current
Current as at the verification date below. Standards and tools both move — confirm at source before you rely on it.
What it is
The annual conference of FIRST, the global forum of incident response and security teams, which comprises over 800 member teams in more than 100 countries. The 2026 edition ran 14-19 June 2026 in Denver, Colorado.
Who it is for, and when
The attendees are the people who actually run CSIRTs and PSIRTs, in the public sector, industry and academia, so the content is incident response at organisational scale — coordination, disclosure, information sharing and cross-border handling — rather than artefact-level forensics. If your work involves handing an incident to, or taking one from, another organisation's response team, this is where those relationships get made.
What it does not cover
It is not a digital forensics conference: expect little on disk or mobile artefacts and nothing on expert testimony or litigation. Much of the programme assumes you work inside a response team, and some material and side meetings are member-oriented; registration fees are published per edition on the conference site.
Go to the source
Open at first.org (opens in a new tab)https://www.first.org/conference/2026/
Details
- Type
- Conference
- Written for
- Working examinerAdvancedWorking examiner, Advanced
- Publisher
- Forum of Incident Response and Security Teams
- Year
- 2026
- Topics
- conferences, incident-response, community, threat-hunting, network
- Checked at source
Related entries
SANS DFIR Summit & Training
Partly freeSANS's annual practitioner summit, with the 2026 edition running 15-16 October 2026 at the Hilton Arlington Rosslyn in Arlington, Virginia, followed by SANS courses 17-22 October. Both the summit and the courses can be attended in person or virtually.
Blue Team Labs Online
Partly freeA gamified platform, run by Centri, of "security investigations and challenges covering; Incident Response, Digital Forensics, Security Operations, Reverse Engineering, and Threat Hunting". Challenges are downloadable artefacts — memory dumps, phishing emails, packet captures, logs — while investigations run in hosted lab instances.
CyberDefenders
Partly freeA blue-team lab platform hosting scenario-based investigations grouped as endpoint forensics, network forensics, malware analysis, cloud forensics, threat hunting, detection engineering and threat intelligence. Challenges are question-and-answer over supplied evidence, with a scoreboard.
Forensics placed inside the incident response lifecycle: building a response capability, response frameworks, evidence acquisition, volatile memory, disk and network evidence, threat intelligence, malware analysis, threat hunting, and reporting — with this edition reframed around ransomware.
A short daily audio briefing, typically five to ten minutes, summarising the Internet Storm Center diaries and the day's notable vulnerabilities and exploitation activity.