More Open Source Security episodes

How to actually test a disaster plan with David Bernstein thumbnail

How to actually test a disaster plan with David Bernstein

Published 4 May 2026

Duration: 34:58

A three-part disaster recovery framework emphasizing simplicity, clear roles, and collaboration, utilizing structured testing via HSEEP, real-world validation, and continuous improvement through exercises, while addressing pitfalls and balancing realism with psychological safety.

Episode Description

Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build...

Overview

The podcast discusses disaster recovery and emergency planning, emphasizing practical, simplified approaches to creating effective strategies. Key principles include the "KISS" methodology, which advocates for clear, straightforward plans that outline roles and responsibilities without unnecessary complexity. Post-plan actions focus on testing through tabletop exercises, which simulate incidents to identify gaps in preparedness. These exercises range from simple discussion-based scenarios to more complex functional simulations, balancing detailed realism with the need for focus. The Homeland Security Exercise and Evaluation Program (HSEEP) is highlighted as a resource for structured testing, stressing a continuous improvement cycle: plan, train, exercise, evaluate, and refine. Real-world testing is critical, as illustrated by a data center incident where a generator failure during a test triggered a real crisis, underscoring the need to validate systems like failover processes in controlled environments. The discussion also distinguishes between hot, warm, and cold disaster recovery sites, stressing the importance of verifying physical and operational readiness through exercises before assuming a plans viability.

The podcast further explores the design and execution of emergency preparedness exercises, emphasizing objective-driven scenarios that target specific goals, such as response time metrics, rather than arbitrary complexity. Clear terminology, like differentiating "vulnerability" from "exploit," is highlighted to prevent misunderstandings during high-stakes situations. Gamification techniques, such as using dice or cards to simulate unpredictability, are discussed as tools to test reactions but caution against letting them distract from core planning objectives. No-fault exercises are prioritized to evaluate processes rather than individual performance, ensuring constructive feedback over blame. Common pitfalls, such as overemphasizing perfection or creating overly stressful environments, are warned against to maintain the focus on learning and improvement. The discussion also touches on psychological factors, like avoiding unfair pressure on participants and addressing diverse personalities within teams. Finally, it connects disaster planning to broader contexts, including using fictional scenarios like Star Trek episodes to explore real-world security risks through frameworks such as MITRE ATT&CK, illustrating how creative approaches can deepen understanding of enterprise security challenges.

Recent Episodes of Open Source Security

31 Aug 2026 Sovereign Tech Agency with Erik Moller

"Explores the Sovereign Tech Agency's efforts to sustain open-source software as critical infrastructure, emphasizing public investment, digital sovereignty, and strategic funding for projects like *curl* and AI security."

17 Aug 2026 Maintaining EOL Open Source with Commonhaus and HeroDevs

"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."

10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e

"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."

3 Aug 2026 VulnCheck's State of Exploitation Report with Patrick Garrity

"Cybersecurity vulnerabilities are being exploited faster (80-day average), AI is both a tool and target, disclosure practices are inconsistent, and better coordination, transparency, and proactive patching are critical to mitigating risks."

More Open Source Security episodes