DEF CON 33 - Reclaim Tech: A Community Movement - Janet Vertesi, Andy Hull

DEF CON 33 - Reclaim Tech: A Community Movement - Janet Vertesi, Andy Hull

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 19:12

CISSP Domains
No ratings yet Log in to rate
Transcript Available
Description

Rebecca Miller, a cyber risk analyst and BCDR specialist, discusses applying business continuity principles to personal resilience planning after experiencing a hospital payroll system disruption without a continuity plan.

Key Takeaways:

  1. Impact Analysis for Essentials: List non-negotiable functions (work, medical care, child/pet needs) and required resources (devices, documents, medications). Include overlooked items like dietary restrictions or pet evacuation plans.

  2. Infrastructure & Security Evaluation: Audit physical/digital infrastructure for weaknesses. Address single points of failure with redundancies like UPS battery backups, round-robin DNS, and geographically distributed backup servers. Maintain spare hardware for portability.

  3. Data Privacy & Controls: Implement layered security: password managers, MFA, and encrypted communication. Assess unique risks (e.g., LGBTQ+ status, activism history) and clean up digital footprints. Post-breach, log out of all accounts, update passwords, and notify contacts via an emergency call tree.

  4. Alternate Strategies for Control Failures: Prepare backups for critical failures, including secondary bank accounts, prepaid debit cards, or 1-6 months of emergency funds.

Testing and regularly updating your personal resilience plan creates calm, structured responses during crises. By documenting actionable strategies, you reduce fear and protect yourself, your family, and community when disruptions occur.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: CISSP Domains. Commonly maps to: Security and Risk Management, Security Architecture and Engineering, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello, I am Rebecca Miller and I am ready to talk to you about resilience. We're going to do it without slides because we're having some issues. So, um, use your imagination. I am a cyber risk analyst and I also moonlight as a CISSP instructor. I specialize in business continuity and disaster recovery planning. So, I create and update and test business continuity plans, disaster recovery plans, and incident response plans for businesses across all industries. Years ago, I was part of a leadership team for a hospital that had a major disruption. We had a time clock and payroll system and it went down. We did not have a continuity plan. So, we navigated an over six week downtime with trial and error. We worked 7 days a week. um doing all sorts of calculations to try and figure out how to kee…