More Open Source Security episodes

Building a plan for disaster with David Bernstein thumbnail

Building a plan for disaster with David Bernstein

Published 20 Apr 2026

Duration: 39:19

Adaptive emergency management and disaster recovery demand dynamic strategies, structured frameworks like ISO 22301/NIST, cyclical preparedness, stress testing, stakeholder alignment, and resilience through collaboration and continuous learning to tackle evolving digital and physical risks.

Episode Description

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are mo...

Overview

The podcast emphasizes the critical role of emergency management, disaster recovery, and business continuity planning in both digital and physical environments, highlighting the need for adaptable frameworks that evolve with emerging risks. It underscores the cyclical nature of emergency preparedness, stressing the importance of ongoing risk assessments, stakeholder engagement, and iterative updates to plans. Formal frameworks like ISO 22301 and NIST are presented as tools to structure planning processes, though the discussion critiques overly rigid approaches, advocating instead for flexible, context-specific adaptations. Challenges in initiating emergency programs include aligning organizational assumptions and ensuring stakeholder awareness, while validation through stress testingrather than superficial demonstrationsis framed as essential to identify plan gaps and prepare for unpredictable scenarios.

A significant focus is placed on the digital landscape, linking recent vulnerabilities in open-source software to the necessity of proactive risk mitigation and robust emergency planning in digital ecosystems. The conversation stresses the importance of continuous improvement cycles, such as the Plan-Do-Check-Act model, to refine plans dynamically and align them with evolving threats. It distinguishes between reactive, impulsive responses and deliberate, pre-established strategies, arguing that structured plans reduce reliance on last-minute improvisation. Practical considerations include avoiding overcomplication by prioritizing identified hazards, establishing clear decision-making authority, and fostering stakeholder collaboration through communication tools and clear role definitions.

Key themes also address the balance between preparedness and organizational resilience, emphasizing the need for realistic, adaptable plans that avoid burnout by cycling team members through tasks and managing workload effectively. The discussion advocates for simplified incident response processes, formal issue-raising mechanisms, and tailoring strategies to organizational size and complexity. Highlighting the importance of stakeholder involvement, including executives and operational leaders, the podcast underscores that effective planning requires balancing foresight with flexibility, ensuring that plans remain dynamic tools rather than static solutions. Ultimately, the content promotes a culture of continuous learning and iterative refinement in emergency management practices.

Recent Episodes of Open Source Security

13 Apr 2026 Open Source Malware with Paul McCarty

Open Source Malware (OSM) addresses the gap in detecting intentional malicious open-source components by cataloging threats, de-obfuscating code, extracting indicators of compromise, and providing post-incident data, while tackling challenges like persistent malicious packages, limitations of traditional tools against interpreted languages, fragmented collaboration, AI risks, and the need for improved CI/CD security, audit tools, and balanced AI-human oversight.

6 Apr 2026 Package management challenges with Andrew Nesbitt

Challenges in package management across ecosystems demand standardization to address fragmentation in naming, versioning, and dependencies, interoperability gaps between system-level and language-specific tools, SBOM scanner inconsistencies, and cross-ecosystem complexity, urging collaboration on shared specs and protocols despite cultural and practical barriers.

30 Mar 2026 Open Source Security at scale with Michael Wisner

The Alpha Omega Project addresses open-source security by targeting leverage points like Node.js and Python ecosystems, advocating for systemic solutions, dedicated security roles, sustainable funding, and registry infrastructure improvements to counter fragmented practices and downstream risks.

23 Mar 2026 2026 State of the Software Supply Chain with Brian Fox

The State of the Software Supply Chain Report underscores explosive open source growth (10T annual downloads) paired with critical challenges like malware proliferation (1.2M malicious packages), unresolved vulnerabilities (65% unaddressed), infrastructure strain, AI's dual role in risk (hallucinations) and potential (MCP systems), and urgent needs for improved tools, policies, and cost management amid regulatory and scalability pressures.

16 Mar 2026 MCP and Agent security with Luke Hinds

The text explores AI agent security risks like prompt injection and open-source vulnerabilities, emphasizing the No-NO project's kernel-based sandboxing with a deny-by-default model, hardware enclaves, and Rust-driven efficiency, alongside layered defenses, restricted commands, and collaborative efforts to tackle evolving threats like social engineering and insecure coding practices.

More Open Source Security episodes