More Open Source Security episodes

Building a plan for disaster with David Bernstein thumbnail

Building a plan for disaster with David Bernstein

Published 20 Apr 2026

Duration: 39:19

Adaptive emergency management and disaster recovery demand dynamic strategies, structured frameworks like ISO 22301/NIST, cyclical preparedness, stress testing, stakeholder alignment, and resilience through collaboration and continuous learning to tackle evolving digital and physical risks.

Episode Description

Josh welcomes back David Bernstein to talk about creating a disaster recover plan. It's a very timely topic given all the current events. There are mo...

Overview

The podcast emphasizes the critical role of emergency management, disaster recovery, and business continuity planning in both digital and physical environments, highlighting the need for adaptable frameworks that evolve with emerging risks. It underscores the cyclical nature of emergency preparedness, stressing the importance of ongoing risk assessments, stakeholder engagement, and iterative updates to plans. Formal frameworks like ISO 22301 and NIST are presented as tools to structure planning processes, though the discussion critiques overly rigid approaches, advocating instead for flexible, context-specific adaptations. Challenges in initiating emergency programs include aligning organizational assumptions and ensuring stakeholder awareness, while validation through stress testingrather than superficial demonstrationsis framed as essential to identify plan gaps and prepare for unpredictable scenarios.

A significant focus is placed on the digital landscape, linking recent vulnerabilities in open-source software to the necessity of proactive risk mitigation and robust emergency planning in digital ecosystems. The conversation stresses the importance of continuous improvement cycles, such as the Plan-Do-Check-Act model, to refine plans dynamically and align them with evolving threats. It distinguishes between reactive, impulsive responses and deliberate, pre-established strategies, arguing that structured plans reduce reliance on last-minute improvisation. Practical considerations include avoiding overcomplication by prioritizing identified hazards, establishing clear decision-making authority, and fostering stakeholder collaboration through communication tools and clear role definitions.

Key themes also address the balance between preparedness and organizational resilience, emphasizing the need for realistic, adaptable plans that avoid burnout by cycling team members through tasks and managing workload effectively. The discussion advocates for simplified incident response processes, formal issue-raising mechanisms, and tailoring strategies to organizational size and complexity. Highlighting the importance of stakeholder involvement, including executives and operational leaders, the podcast underscores that effective planning requires balancing foresight with flexibility, ensuring that plans remain dynamic tools rather than static solutions. Ultimately, the content promotes a culture of continuous learning and iterative refinement in emergency management practices.

Recent Episodes of Open Source Security

31 Aug 2026 Sovereign Tech Agency with Erik Moller

"Explores the Sovereign Tech Agency's efforts to sustain open-source software as critical infrastructure, emphasizing public investment, digital sovereignty, and strategic funding for projects like *curl* and AI security."

17 Aug 2026 Maintaining EOL Open Source with Commonhaus and HeroDevs

"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."

10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e

"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."

3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity

"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."

27 Jul 2026 Securing critical infrastructure with Josh Corman

"Cybersecurity faces escalating threats to critical infrastructure, requiring stronger OT security, IT-OT collaboration, proactive threat modeling, and resilience engineering to prevent real-world disasters."

More Open Source Security episodes