The Unserved Market: Small Organizations at Risk

▶ Watch (3:19)

The average breach costs $80,000. For a small nonprofit, a rural hospital, or an electric co-op, that amount shuts them down. Sarah Powazek shared a University of Maryland study showing over 50% of US counties have open Telnet, FTP, RDP or SSH services. Rural residents and people in poverty face more risk and have less recovery. The University of Vermont Medical Center ransomware attack forced 75% of cancer patients to find care elsewhere. EBT food stamp theft hit $69 million, causing 53% of victims to skip meals.

The Cyber Resilience Corps: 4,213 Volunteers and Growing

▶ Watch (8:56)

The Corps is a collaborative of 51 cyber volunteering groups across the United States. Four groups serve nationwide; the rest are regional. They cover 29 states with 4,213 volunteers. The new platform at cybervolunteers.us collects data on all programs, services, and subsectors they support. It also matches volunteers with programs and beneficiaries with help. Powazek noted that while scale is growing, they cannot yet reliably point every organization in any state to an available program.

Cyber Peace Builders: Corporate Volunteers Serving Nonprofits

▶ Watch (17:10)

Adrien Ogee runs a matchmaking platform that pairs corporate volunteers with nonprofits. The program has 500+ companies and 620 nonprofits served worldwide. Missions are scoped to 1 to 4 hours. Volunteers have completed 2,000 missions totaling 3,500 hours. Ogee emphasized that the 1.3 million US nonprofits are a massive unmet need. Corporate social responsibility budgets pay for the platform, and companies use it for talent retention. Volunteers get badges and can work on phishing simulations, incident response plans, or basic hygiene training.

DEF CON Franklin: Water Utility Pilot and Hackers’ Almanac

▶ Watch (25:44)

Jake Braun launched Franklin last year. The project has two parts. First, a water utility pilot partnered with the National Rural Water Association, working with five small utilities. Volunteers changed default passwords, performed asset inventory, and assessed endpoints. The pilot succeeded and will expand. Second, the Hackers’ Almanac compiled top findings from DEF CON for the first time in 32 years. University of Chicago students annotated hundreds of talks. Braun noted that threats from China and Iran are rising while federal funding drops, so they are partnering with industry for free tools to scale faster.

On the Ground: A Volunteer’s Experience

▶ Watch (33:59)

Jonathan Farley described his work at a Utah water utility. Leadership initially asked, “who would want to attack us?” A spear phishing attempt on a 500-person town proved small communities are targets. The team started with CIS top 18 controls. Inventory was unknown. They deployed password managers via group policy and audited external endpoints. MFA was mostly solid, but third-party apps lacked coverage. Vulnerability scanning found “spicy services” on the ICS network. Wireless was a mess with pre-shared keys. Next steps include incident response planning and disabling Office macros. Farley also volunteers with Cyber Peace Builders, recently running a phishing exercise for an 80-member organization across 30 countries.

Q&A

Why does Cyber Peace Builders exclude public sector volunteers? The program avoids public sector volunteers because of political tensions between governments and nonprofits in certain countries; they stick with private sector for now. ▶ 42:42

Why does the cyber resilience corps map not show local groups for my state? The map often returns nothing because many states lack programs. The speakers’ biggest ask is for attendees to start local programs if none exist. ▶ 43:36

Notable Quotes

The average cost of a breach is $80,000 Sarah Powazek · ▶ 3:19

we have about 4,213 volunteers Sarah Powazek · ▶ 9:34

they didn’t know their own inventory Jonathan Farley · ▶ 34:41

no one cares about us is just not true Jonathan Farley · ▶ 33:49

I haven’t said a thing about penetration testing yet Jonathan Farley · ▶ 39:14

Key Takeaways

  • The Cyber Resilience Corps has 4,213 volunteers but needs more in underserved states.
  • Cyber Peace Builders provides 1-4 hour scoped missions for corporate volunteers.
  • DEF CON Franklin’s water pilot showed basic inventory and MFA gaps even in 500-person towns.

About the Speaker(s)

Sarah Powazek is the Program Director of Public Interest Cybersecurity at the UC Berkeley Center for Long-Term Cybersecurity (CLTC). She leads research on defending low-resource organizations, serves as Co-Chair of the Cyber Resilience Corps, and hosts the Cyber Civil Defense Summit. She previously worked at CrowdStrike Strategic Advisory Services and as Program Manager of the Ransomware Task Force.

Jake Braun is the Executive Director of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy. He served in the White House as acting Principal Deputy National Cyber Director. Braun co-founded the DEF CON Voting Machine Hacking Village and authored Democracy in Danger. He launched DEF CON Franklin to memorialize conference findings and recruit volunteers for underresourced critical infrastructure.

Adrien Ogee spent his career in cyber crisis response at Thales, the French and European Cybersecurity Agencies (ANSSI and ENISA), and the World Economic Forum. He oversees cybersecurity assistance to vulnerable populations at the Capist Institute and co-founded the Cyber Peace Builders.