More Open Source Security episodes

Building a plan for disaster with David Bernstein thumbnail

Building a plan for disaster with David Bernstein

Published 20 Apr 2026

Duration: 39:19

Adaptive emergency management and disaster recovery demand dynamic strategies, structured frameworks like ISO 22301/NIST, cyclical preparedness, stress testing, stakeholder alignment, and resilience through collaboration and continuous learning to tackle evolving digital and physical risks.

Episode Description

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are mo...

Overview

The podcast emphasizes the critical role of emergency management, disaster recovery, and business continuity planning in both digital and physical environments, highlighting the need for adaptable frameworks that evolve with emerging risks. It underscores the cyclical nature of emergency preparedness, stressing the importance of ongoing risk assessments, stakeholder engagement, and iterative updates to plans. Formal frameworks like ISO 22301 and NIST are presented as tools to structure planning processes, though the discussion critiques overly rigid approaches, advocating instead for flexible, context-specific adaptations. Challenges in initiating emergency programs include aligning organizational assumptions and ensuring stakeholder awareness, while validation through stress testingrather than superficial demonstrationsis framed as essential to identify plan gaps and prepare for unpredictable scenarios.

A significant focus is placed on the digital landscape, linking recent vulnerabilities in open-source software to the necessity of proactive risk mitigation and robust emergency planning in digital ecosystems. The conversation stresses the importance of continuous improvement cycles, such as the Plan-Do-Check-Act model, to refine plans dynamically and align them with evolving threats. It distinguishes between reactive, impulsive responses and deliberate, pre-established strategies, arguing that structured plans reduce reliance on last-minute improvisation. Practical considerations include avoiding overcomplication by prioritizing identified hazards, establishing clear decision-making authority, and fostering stakeholder collaboration through communication tools and clear role definitions.

Key themes also address the balance between preparedness and organizational resilience, emphasizing the need for realistic, adaptable plans that avoid burnout by cycling team members through tasks and managing workload effectively. The discussion advocates for simplified incident response processes, formal issue-raising mechanisms, and tailoring strategies to organizational size and complexity. Highlighting the importance of stakeholder involvement, including executives and operational leaders, the podcast underscores that effective planning requires balancing foresight with flexibility, ensuring that plans remain dynamic tools rather than static solutions. Ultimately, the content promotes a culture of continuous learning and iterative refinement in emergency management practices.

Recent Episodes of Open Source Security

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

13 Jul 2026 Red Hat's Project Lightwell with Mo Duffy

"Project Lightwell uses AI and open-source collaboration to detect and fix vulnerabilities missed by traditional tools, emphasizing upstream transparency, AI's role in security, and Red Hat's efforts to sustain long-term open-source security through collaboration and patch adoption."

29 Jun 2026 AIBOM, CBOM, and HBOM with Allan Friedman

The evolution of Software Bill of Materials (SBOM) beyond manufacturing into cryptographic, hardware, and AI domains faces challenges in unified integration, compliance, tooling, and dependency tracking, requiring open-source collaboration, standardized frameworks, and adaptive policies to meet industry demands in procurement and risk management.

22 Jun 2026 Packagist and Composer security with Jordi Boggiano

Strategies for securing open-source ecosystems include malware detection via third-party feeds, transparency logs, rapid incident response, blocking malicious downloads, private registry controls, immutable package releases, standardized workflows, MFA enforcement, and technical proposals like artifact validation and build attestation, while addressing challenges like maintainer hacking, AI risks, usability trade-offs, and the need for ecosystem-wide alignment and human verification.

15 Jun 2026 Sustaining Open VSX with Mike and Thabang

Eclipse Foundation's OpenVSX, a VS Code extension repository, surged to 600M monthly downloads, evolved to a commercial model with enterprise SLAs and security teams, while addressing scalability, open-source balance, and funding challenges for AI expansion.

More Open Source Security episodes