Firewalls Don't Stop Dragons Podcast
Becoming Cyber Resilient
In the US alone, there are tens of thousands of small organizations that are responsible for critical infrastructure and vital community services. Most of them don’t have an IT department let alone a cyber security expert on staff. And yet these organizations are being attacked by cyber criminal gangs with ransomware and are also being targeted by foreign adversaries who would like the ability to disrupt our very civilization. While the US federal cyber agencies have not properly responded to these threats, a handful of volunteer organizations have emerged, organized under the Cyber Resilience Corps, to address these needs. Today I’ll speak with Michael Razeeq, Grace Menna, Adrien Ogee and Eric Franco about their much-needed efforts.
Interview Notes- Cyber Resilience Corps: https://cltc.berkeley.edu/program/cyber-resilience-corps/
- Volunteer! https://cybervolunteers.us
- Cyber Security Clinics: https://cybersecurityclinics.org/
- The Ransomware Hunting Team: https://en.wikipedia.org/wiki/The_Ransomware_Hunting_Team
- Roadmap to Cyber Defense: https://cltc.berkeley.edu/publication/roadmap-to-community-cybersecurity/
- Path to Long-Term Cyber Resilience report: https://cltc.berkeley.edu/publication/a-path-to-long-term-cyber-resilience-for-under-resourced-organizations/
- Grace Menna’s BSides LV talk: https://www.youtube.com/live/v20rxx_afw0?&t=1410
- CISA Cybersecurity Resources for High-Risk Communities: https://www.cisa.gov/audiences/high-risk-communities/cybersecurity-resources-high-risk-communities
- FBI InfraGuard: https://www.infragardnational.org/
- My book: https://fdsd.me/book
- My newsletter: https://fdsd.me/newsletter
- Support the mission: https://fdsd.me/support
- Give the gift of privacy and security: https://fdsd.me/coupons
- Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
- 0:00:13: Intro
- 0:00:26: Couple announcements
- 0:01:09: Interview setup
- 0:03:38: Defining some terms
- 0:06:40: Introductions
- 0:07:51: What is the Cyber Resilience Corps?
- 0:13:59: What are some of the other affiliated cyber groups?
- 0:19:24: How do you reach organizations in need?
- 0:26:43: Do orgs ever resist or eschew your help?
- 0:34:22: How are these efforts funded?
- 0:42:14: is there agreement on where to focus efforts?
- 0:44:02: Which sectors are most important to secure?
- 0:51:11: Are there accepted standards for infrastructure security?
- 0:53:38: What are the requirements for volunteers?
- 1:04:19: How do match volunteers with needs?
- 1:08:28: How long do the support relationships last?
- 1:16:31: What key things have you learned from your initial work?
- 1:22:58: How do you scale this effort to address the massive need?
- 1:25:18: Shouldn’t Big Tech be doing more here?
- 1:33:49: How can we help?
- 1:37:28: If I’m an organization, how do I get help?
- 1:38:38: What’s next?
- 1:44:28: Wrap-up
- 1:47:59: Patron podcast preview
- 1:48:59: Looking ahead





Subscribe