Join our Newsletter — 33% off our NHI Course

Call For Papers

A Call For Papers is an open invitation for speakers to submit proposed session topics for an event. In cybersecurity, it usually asks for a short summary, the learning value, and evidence that the talk is practical. CFPs help event organizers select content that is relevant, timely, and useful to practitioners.

What a call for papers actually does

A call for papers is the event organiser’s intake mechanism, not the programme itself. It sets the submission frame, defines the topic boundary, and signals what kind of content is likely to be accepted, usually by asking for practical outcomes, audience relevance, and enough detail to judge fit.

For practitioners, that matters because a CFP is often the first filter between useful technical material and promotional or overly abstract speaking proposals. The better the CFP brief, the easier it is for authors to pitch sessions that align with the audience, the event’s maturity level, and the organisers’ editorial intent.

What organisers are really evaluating

Most cybersecurity CFPs are evaluating whether the submission has a clear problem statement, a defensible lesson, and evidence that the speaker can explain the topic in a way practitioners can apply. This is why strong abstracts usually include scope, takeaway value, and some indication of real-world experience rather than pure theory.

That evaluation is as much about program quality as it is about topic selection. Organisers want sessions that fit the agenda’s balance, avoid duplication, and match the expected audience, whether that audience is focused on identity, cloud, operations, application security, or broader security leadership.

Because CFP language varies across conferences, vendors, and communities, the submission criteria are not fully standardised. One event may prioritise case studies, another may want research, and a third may prefer practitioner lessons learned, so authors should read the brief closely instead of assuming one abstract style works everywhere.

How speakers should approach a CFP

A good proposal answers the organiser’s question before the review committee asks it: what is the session about, why does it matter now, and what will attendees leave with? The strongest submissions are specific, concrete, and honest about the depth they can deliver in the allocated slot.

Speakers also need to match the tone of the event. A deeply technical summit CFP usually expects implementation detail and evidence, while a broader leadership conference may value decision-making, programme design, or risk framing more heavily. If the abstract oversells breadth, reviewers often read it as a sign that the speaker has not narrowed the subject enough.

In practice, this is similar to writing for a control audience rather than a marketing audience. If you can explain the problem, the method, and the practical lesson in plain language, the proposal is usually stronger than one that leans on jargon or aspiration.

Why CFP quality affects the event itself

A well-run CFP improves the whole conference by shaping content quality before scheduling begins. It helps organisers avoid mismatched sessions, encourages better subject coverage, and makes it more likely that the final agenda reflects current practitioner concerns rather than whichever proposals were easiest to submit.

SOC 2 Trust Services Criteria offer a useful comparison point for event operations because they reflect the same idea of structured expectations, clear accountability, and consistent review criteria. A CFP works best when the review process is explicit enough that speakers understand what “good” looks like before they submit.

For cybersecurity communities, that discipline matters even more because the audience is usually looking for applicability, not just novelty. A conference session that teaches a repeatable technique, a failure mode, or a decision pattern is usually more valuable than one that simply names a trend.

Risk and Threat Considerations

CFPs are not inherently security artefacts, but they can create governance and trust risk if the review process is weak. Poorly defined submission criteria can let in shallow, misleading, or overly promotional talks, while vague abstracts can hide a lack of technical substance until the event is already committed.

Failure mechanism: Reviewers may be forced to judge proposals on style rather than substance when the brief does not require enough detail, which increases the chance of weak content, agenda drift, or speaker misrepresentation.

Impact: The event can lose practitioner credibility, waste attendee time, and reduce confidence in future submissions, especially in cybersecurity communities where the audience expects practical accuracy and clear lessons.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
CIS Controls v8 CIS Control 5 — Account Management CFPs depend on clear ownership and review accountability for speaker submissions.
CIS Control 8 — Audit Log Management CFP review needs traceable decisions and evidence of why proposals were accepted or rejected.
Recommendation — Assign clear owners for CFP intake, review, and acceptance decisions. Log proposal review decisions and retain justification for programme governance.
NIST CSF 2.0 GV.RM — Risk Management Strategy CFPs shape event-quality risk by setting selection criteria and review expectations.
GV.OV — Oversight CFP governance requires oversight so reviewers apply consistent standards across submissions.
PR.AT — Awareness and Training Speaker guidance in a CFP works best when authors understand what reviewers expect.
Recommendation — Set CFP criteria that align session selection with event risk tolerance and audience needs. Oversee CFP scoring to keep acceptance decisions consistent and defensible. Brief speakers on abstract requirements so submissions better match review expectations.

Practitioner Guidance

Why practitioners should care: If you are submitting to a CFP, treat the abstract as a decision document, not a teaser. The reviewer should be able to see the problem, the audience fit, and the practical outcome without guessing.

Common misunderstanding: Many speakers think breadth makes a proposal stronger, when in practice narrowness often improves selection odds. A concise, well-scoped talk with one clear lesson is usually easier to place than a broad topic with no obvious takeaway.

Practitioner takeaway: The best CFP submissions make the organiser’s job easier by showing, up front, that the session will be useful to the intended audience.