Global Telemetry to Local Remediation: Operationalizing Threat Intelligence for the Underserved
Across the world many organizations that communities depend on every day— such as schools, libraries, shelters, healthcare providers, local media and NGOs etc —operate with limited cybersecurity resources. Yet when they are hit by a cyber incident, the consequences are very real: services become unavailable, sensitive data is exposed, public trust is damaged, and recovery often falls on a handful of people already stretched thin.
For years, the Shadowserver Foundation has helped defenders around the world identify and remediate threats through free daily intelligence feeds, victim notifications, vulnerability reporting, and Internet-scale measurements. Working through National CSIRTs, trusted partners, and directly with organizations, Shadowserver provides visibility into compromised systems, exposed services, vulnerable assets, and emerging threats that would otherwise go unnoticed.
But visibility by itself does not reduce risk.
Many organizations receive notifications or intelligence yet struggle to understand where to start, what matters most, or how to translate external signals into practical security improvements. National CSIRTs and cybersecurity authorities play a critical role, but community organizations often remain at the edge of the ecosystem, with limited capacity to operationalize the information they receive.
In this talk, we present our approach to what we call the "last mile" of cyber defense for Critical Community Infrastructure (CCI). This will be presented in the context of a new project launched by the Shadowerver Foundation, focused on Central and Eastern Europe, with a particular emphasis on Ukraine.
The objective is “simple”: help under-resourced organizations across Central and Eastern Europe turn free community threat intelligence into measurable risk reduction. The payoff? Not just help to the underserved in Central and Eastern Europe from a regional perspective, but a blueprint that could be applied worldwide.
The approach combines daily CTI, outreach, awareness activities, practical guidance, and operational support as well as new tooling. Rather than focusing on complex frameworks, we start with a few practical questions: What is exposed? Who can access it? How quickly can exposure be reduced? How do we reach the underserved who are unlikely to understand technical information and lack the resources as well as know-how to mitigate threats? Is there any tooling missing? How can we improve messaging? And importantly, given the participants of hack.lu: How can the wider infosec and hacker community help?
Sebastian Wagner is a Free Software enthusiast, full-stack software developer, and project manager.
He is located in Austria and currently works at Intevation, a small software firm in Germany.
With over ten years in IT security, including six years at CERT.at, he also co-maintains IntelMQ, a widely used CSIRT automation tool, for 12 years, and is a member of the Shadowserver Foundation and active and board member in two NGOs: The Institute for Common Good Technology and Engineers without Borderers Austria.
Joining Shadowserver in 2016, Jon brings a range of skills and experience from UK Law Enforcement cyber crime investigation to the Foundation.
Engaging in consumer outreach, incident handling and the training of constituents in the use of Shadowserver public benefit services allows Jon the opportunity to deliver current threats and insights to all areas of the cyber community.
Of specific interest to Jon is international liaison and with the support of key public/private sector partners, the upskilling of developing cyber regions and National CERTs to ensure the effective use and understanding of Shadowserver’s bespoke datasets for a more secure internet.