More Open Source Security episodes

How to actually test a disaster plan with David Bernstein thumbnail

How to actually test a disaster plan with David Bernstein

Published 4 May 2026

Duration: 34:58

A three-part disaster recovery framework emphasizing simplicity, clear roles, and collaboration, utilizing structured testing via HSEEP, real-world validation, and continuous improvement through exercises, while addressing pitfalls and balancing realism with psychological safety.

Episode Description

Josh and David finish up the disaster recovery and emergency planning trilogy. In this one David tells us how to test the plan he told us how to build...

Overview

The podcast discusses disaster recovery and emergency planning, emphasizing practical, simplified approaches to creating effective strategies. Key principles include the "KISS" methodology, which advocates for clear, straightforward plans that outline roles and responsibilities without unnecessary complexity. Post-plan actions focus on testing through tabletop exercises, which simulate incidents to identify gaps in preparedness. These exercises range from simple discussion-based scenarios to more complex functional simulations, balancing detailed realism with the need for focus. The Homeland Security Exercise and Evaluation Program (HSEEP) is highlighted as a resource for structured testing, stressing a continuous improvement cycle: plan, train, exercise, evaluate, and refine. Real-world testing is critical, as illustrated by a data center incident where a generator failure during a test triggered a real crisis, underscoring the need to validate systems like failover processes in controlled environments. The discussion also distinguishes between hot, warm, and cold disaster recovery sites, stressing the importance of verifying physical and operational readiness through exercises before assuming a plans viability.

The podcast further explores the design and execution of emergency preparedness exercises, emphasizing objective-driven scenarios that target specific goals, such as response time metrics, rather than arbitrary complexity. Clear terminology, like differentiating "vulnerability" from "exploit," is highlighted to prevent misunderstandings during high-stakes situations. Gamification techniques, such as using dice or cards to simulate unpredictability, are discussed as tools to test reactions but caution against letting them distract from core planning objectives. No-fault exercises are prioritized to evaluate processes rather than individual performance, ensuring constructive feedback over blame. Common pitfalls, such as overemphasizing perfection or creating overly stressful environments, are warned against to maintain the focus on learning and improvement. The discussion also touches on psychological factors, like avoiding unfair pressure on participants and addressing diverse personalities within teams. Finally, it connects disaster planning to broader contexts, including using fictional scenarios like Star Trek episodes to explore real-world security risks through frameworks such as MITRE ATT&CK, illustrating how creative approaches can deepen understanding of enterprise security challenges.

Recent Episodes of Open Source Security

20 Jul 2026 Abandoned open source with Josh Marpet

"Outdated vendor risk management processes, plagued by misrepresented questionnaires and slow vulnerability disclosures, demand faster, proactive security measures and greater transparency in open-source software."

13 Jul 2026 Red Hat's Project Lightwell with Mo Duffy

"Project Lightwell uses AI and open-source collaboration to detect and fix vulnerabilities missed by traditional tools, emphasizing upstream transparency, AI's role in security, and Red Hat's efforts to sustain long-term open-source security through collaboration and patch adoption."

29 Jun 2026 AIBOM, CBOM, and HBOM with Allan Friedman

The evolution of Software Bill of Materials (SBOM) beyond manufacturing into cryptographic, hardware, and AI domains faces challenges in unified integration, compliance, tooling, and dependency tracking, requiring open-source collaboration, standardized frameworks, and adaptive policies to meet industry demands in procurement and risk management.

22 Jun 2026 Packagist and Composer security with Jordi Boggiano

Strategies for securing open-source ecosystems include malware detection via third-party feeds, transparency logs, rapid incident response, blocking malicious downloads, private registry controls, immutable package releases, standardized workflows, MFA enforcement, and technical proposals like artifact validation and build attestation, while addressing challenges like maintainer hacking, AI risks, usability trade-offs, and the need for ecosystem-wide alignment and human verification.

15 Jun 2026 Sustaining Open VSX with Mike and Thabang

Eclipse Foundation's OpenVSX, a VS Code extension repository, surged to 600M monthly downloads, evolved to a commercial model with enterprise SLAs and security teams, while addressing scalability, open-source balance, and funding challenges for AI expansion.

More Open Source Security episodes