Reclaim Tech: A Community Movement

Janet Vertesi, Andy Hull

DEF CON 33 · Day 1 · Main Stage

Overview

In an era defined by perpetual digital and sociopolitical upheaval, Rebecca Miller, a seasoned cyber risk analyst and CISSP instructor, delivered a compelling talk at DEF CON, challenging attendees to apply the rigorous principles of Business Continuity and Disaster Recovery (BCDR) planning to their personal lives, families, and communities. While the overarching theme of "Reclaim Tech: A Community Movement" suggests a broader discourse on technological agency, Miller's specific focus was on empowering individuals to reclaim control over their resilience and security by systematically preparing for disruptions that extend far beyond typical cybersecurity threats. Her presentation, delivered without slides due to technical issues, underscored the improvisational spirit often required in crisis, yet emphasized the critical importance of proactive, documented planning.

Watch on YouTube

Visual summary for Reclaim Tech: A Community Movement by Janet Vertesi, Andy Hull
Visual summary for Reclaim Tech: A Community Movement by Janet Vertesi, Andy Hull

Key moments

  1. 0:00 Introduction and why personal resilience matters
  2. 2:15 Applying business continuity principles to personal life
  3. 2:50 First step: Conduct a personal impact analysis
  4. 4:09 Detailed examples of personal essential functions and resources
  5. 6:10 Evaluating personal infrastructure and security weaknesses
  6. 7:23 Inventorying assets and planning for portability
  7. 8:10 Considering personal safety and data compromise impact

Reclaim Tech: A Community Movement

Speakers: Janet Vertesi; Andy Hull

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=twi2m77YxQ0

Overview

In an era defined by perpetual digital and sociopolitical upheaval, Rebecca Miller, a seasoned cyber risk analyst and CISSP instructor, delivered a compelling talk at DEF CON, challenging attendees to apply the rigorous principles of Business Continuity and Disaster Recovery (BCDR) planning to their personal lives, families, and communities. While the overarching theme of "Reclaim Tech: A Community Movement" suggests a broader discourse on technological agency, Miller's specific focus was on empowering individuals to reclaim control over their resilience and security by systematically preparing for disruptions that extend far beyond typical cybersecurity threats. Her presentation, delivered without slides due to technical issues, underscored the improvisational spirit often required in crisis, yet emphasized the critical importance of proactive, documented planning.

Miller's core argument is that just as organizations require detailed strategies to maintain essential functions during crises, individuals, families, and communities need their own actionable plans. This necessity arises from the constant barrage of social media-driven scare tactics, the pervasive threats of data mining, ransomware, PII breaches, and broader sociopolitical instabilities. The talk moved beyond common cybersecurity buzzwords like MFA and strong passwords, urging a deeper consideration of what happens when these safeguards inevitably fail. By demystifying BCDR processes and translating them into a personal context, Miller provided a practical framework for building robust personal resilience, ensuring livelihood and inner circles remain intact amidst an unpredictable world.

This talk is particularly relevant for anyone navigating the complexities of modern life, from cybersecurity professionals looking to extend their expertise to personal security, to individuals seeking to fortify their foundational preparedness against a spectrum of potential disruptions. Miller’s approach offers a structured methodology for identifying critical personal functions, assessing vulnerabilities, implementing protective measures, and developing fallback strategies, ultimately fostering a sense of control and calm in the face of potential chaos.

Background

▶ Watch: Introduction and why personal resilience matters (0:00)

Rebecca Miller's journey into the realm of business continuity and disaster recovery was profoundly shaped by a personal and professional crucible. Years ago, while serving on the leadership team of a hospital, her organization experienced a catastrophic disruption: the complete failure of their time clock and payroll system. Lacking any pre-existing continuity plan, the team was forced to navigate an agonizing "over six-week downtime" through sheer trial and error, working "7 days a week" to manually calculate and process payroll, desperately striving to keep staff paid and present. This intense, unplanned ordeal left an indelible mark on Miller, igniting a fervent commitment to preventing others from experiencing such profound vulnerability. This experience propelled her to career pivot, dedicating herself to creating and updating robust business continuity, disaster recovery, and incident response plans for businesses across diverse industries.

The problem Miller addresses is not merely a corporate one but a universal human challenge in the 21st century. She highlights a world saturated with "constant disruption," where "social media and scare tactics coming at us from all angles" keep everyone "on edge." While conventional cybersecurity measures like Multi-Factor Authentication (MFA), strong passwords, and password vaults are undeniably "critical in our current digital climate," Miller poses a fundamental question: "What happens when those safeguards fail? What's your backup plan?" This query underscores the inherent limitations of purely technical solutions when confronted with broader, systemic failures or personal vulnerabilities.

Her talk aims to bridge the gap between enterprise-level resilience strategies and individual preparedness. She asserts that the same methodical approach used to protect corporate assets and operations can, and should, be applied to personal lives. This includes safeguarding against the omnipresent threats of data mining, ransomware, and Personally Identifiable Information (PII) breaches, as well as navigating the broader "socio-political upheaval that we're all dealing with." By translating the theoretical frameworks of BCDR into practical, actionable steps for individuals, Miller provides a necessary antidote to the pervasive anxiety of an increasingly uncertain world, empowering attendees to build personal resilience from the ground up.

Key Findings

▶ Watch: First step: Conduct a personal impact analysis (2:50)

Rebecca Miller's central contribution is the systematic application of established BCDR methodologies to personal and community resilience. Her talk outlines a comprehensive, multi-step framework, effectively transforming complex enterprise strategies into an accessible personal contingency plan. The key findings are the practical, actionable phases of this planning process:

  1. Personal Impact Analysis: This foundational step involves identifying "essential functions" – activities one must continue regardless of crisis. For businesses, this might be core operations; for individuals, it translates to necessities like "going to work and paying bills." Crucially, this analysis extends to listing all necessary resources to perform these functions, encompassing everything from childcare and personal documents (birth certificates, passports, marriage certificates, medical records, medication documentation) to financial access (bank logins, money supply), communication tools (phones, Wi-Fi), and even physical assets (work/personal laptops, vehicles, specialty food stockpiles, pet care arrangements). This holistic view ensures no critical dependency is overlooked.
  1. Infrastructure and Security Design Evaluation: Miller emphasizes scrutinizing one's personal "infrastructure" – whether data is housed on a home server or in the cloud. The key here is identifying Single Points of Failure (SPOF). She recommends implementing redundancies, such as a UPS (Uninterruptible Power Supply) for power outages, or considering a secondary or round-robin DNS if managing personal web services, to ensure continuous access to data even if a primary connection fails. This proactive assessment of one's digital and physical environment is critical for identifying and mitigating vulnerabilities.
  1. Asset Inventory and Portability Assessment: Beyond digital assets, a thorough inventory includes spare hardware (laptops, phones), and often-forgotten essentials like chargers and power blocks for travel. The concept of "portability" is paramount: preparing for scenarios where one might need to quickly relocate and maintain functionality.
  1. Personal Impact of Data Leaks and Threat Assessment: This phase requires radical honesty, prompting individuals to consider how a data leak could affect their "personal safety" or professional standing. Miller highlights the myriad entities scraping data from social media and the web, the increasing sophistication of AI machine learning-boosted hacker attacks, and the specific threats faced by vulnerable communities (immigrants, LGBTQ+ individuals, activists, those with past legal entanglements). This deep self-assessment informs the subsequent choice of protective tools.
  1. Data Integrity Confirmation and Post-Breach Protocols: Recognizing that breaches are often inevitable, Miller stresses confirming data integrity through practices like hashing, using digital signatures, verifying sources, and regularly validating backups. Equally important are post-breach actions: immediately logging out of all accounts, changing to unique and strong passwords, enabling MFA, monitoring financials, spinning up new email addresses, and establishing emergency call trees with "code words" to communicate unusual activity to loved ones.
  1. Controls Evaluation and Gap Analysis: This involves listing existing security controls (MFA, password managers, secure messaging apps like Signal, knowledge of tools like VidID) and then identifying "gaps." Recommendations include implementing a VPN or critically evaluating one's relationship with social media, emphasizing the dangers of poorly thought-out posts, even by friends and family. She points to resources like Shannon Miller at Lockdown Your Life for data deletion and online presence cleanup.
  1. Alternate Strategies (Workarounds): Availability is key. This step focuses on developing "workarounds" for critical functions. Examples include opening secondary bank accounts, stocking prepaid debit cards, maintaining a "petty cash slush fund," and meticulously calculating monthly survival expenses. For employment, this means exploring PTO banks, alternate shifts, or remote work options to maintain cash flow during a crisis.
  1. Documentation, Testing, and Continuous Updates: The entire plan must be meticulously "written down," with clear assignments of responsibility, and stored in "multiple copies" in "different locations." Crucially, these plans are not static; they require regular "testing" through scenario walkthroughs with all involved parties to ensure a "well-oiled machine" response. Plans must be reviewed and updated whenever personal circumstances change, ensuring they remain current and viable. Miller underscores the importance of deciding now when to act, rather than waiting until stress and crisis cloud judgment.

These findings collectively present a holistic, proactive, and continuously adaptive framework for personal resilience, moving beyond reactive cybersecurity fixes to comprehensive life continuity planning.

Technical Deep Dive

▶ Watch: Detailed examples of personal essential functions and resources (4:09)

Rebecca Miller's talk, while focused on personal resilience, leverages numerous technical concepts and tools rooted in enterprise security and IT best practices. The "technical deep dive" into her recommendations reveals a sophisticated understanding of how these principles can be adapted for individual protection.

At the core of her advice is a Personal Impact Analysis, mirroring a Business Impact Analysis (BIA). This isn't just a list; it's a critical assessment of dependencies. For instance, accessing a password vault (e.g., Bitwarden or 1Password) is listed as a necessity for logging into everything from "banks to medical necessities." This immediately highlights the critical role of robust password management tools in maintaining access to digital life. The mention of medication and specialty food stockpiles, while seemingly non-technical, underscores the physical infrastructure dependencies that underpin personal continuity.

When discussing personal infrastructure, Miller introduces concepts directly from IT operations. She advises evaluating whether personal data is on a "server at home or in the cloud," and warns against single points of failure (SPOF). Her recommendation of a UPS (Uninterruptible Power Supply) for battery backup in case of power loss is a direct application of data center redundancy to a home environment. Furthermore, for those managing personal web services or internal networks, she suggests implementing a "secondary or round-robin DNS." This technique, commonly used in enterprise environments for load balancing and failover, ensures that if one server or IP address fails, traffic is automatically rerouted, maintaining "access to data, to websites, even if that primary connection goes down." This demonstrates a sophisticated understanding of network resilience.

The talk delves into threat intelligence and data leak detection, recommending specific tools:

  • dehashed and Have I Been Pwned: These services allow individuals to check if their email addresses or other credentials have appeared in known data breaches.
  • Intelligence X: A broader data intelligence platform for searching leaked data.
  • Shodan and Census: These are search engines for internet-connected devices, enabling individuals to perform "thread intel on any internet connected devices" they might own, identifying potential attack surfaces. This is a direct application of hacker reconnaissance tools for defensive purposes.

For password management, beyond Bitwarden and 1Password, she emphasizes the critical need for "randomly generated passwords" and the universal adoption of MFA, specifically advocating for moving "away from SMS" due to its inherent vulnerabilities (e.g., SIM swapping attacks).

Data integrity is another key technical concern. Miller advises to "hash all the things," use digital signatures, "verify sources," and "perform backups, and validate them regularly." Hashing (e.g., using SHA-256) creates a unique digital fingerprint of data, allowing verification that it hasn't been altered. Digital signatures provide cryptographic assurance of authenticity and integrity. Regular validation of backups ensures that recovery data is not corrupted or incomplete.

In the event of a breach, her "technical" advice includes:

  • Spinning up a new email address: Isolating compromised accounts and establishing a clean communication channel.
  • Emergency call trees with code words: A low-tech but highly effective "out-of-band" communication channel to verify identity and convey urgency, bypassing potentially compromised digital channels.
  • Security awareness and training: Educating one's "loved ones or community" on common attack vectors like phishing and social engineering, thereby strengthening the human firewall.

For secure communication, Miller explicitly recommends Signal, a widely recognized end-to-end encrypted messaging application, as a baseline. She also mentions VidID, which, within the DEF CON community, refers to a decentralized, untraceable communication network, suggesting an awareness of advanced privacy-preserving technologies. The recommendation of a VPN (Virtual Private Network) highlights the importance of encrypting internet traffic and masking IP addresses for enhanced online privacy and security.

Finally, the talk touches upon online presence cleanup, referencing Shannon Miller at Lockdown Your Life for "data deletion class" and information. This acknowledges the persistent digital footprint and the technical challenges of removing personal information from various online databases and public records.

Overall, the technical content of the talk, while presented in an accessible manner, draws heavily from established cybersecurity and IT resilience principles, offering a robust framework for individuals to implement sophisticated protective measures in their daily lives.

Demo / Proof of Concept

▶ Watch: Inventorying assets and planning for portability (7:23)

This talk was delivered as a conceptual and instructional presentation, outlining a methodical approach to personal resilience planning rather than demonstrating a specific tool, exploit, or system. The speaker, Rebecca Miller, focused on providing a theoretical framework and practical steps for individuals to implement, rather than showcasing a live demo or a proof of concept of a technical attack or defense. Her presentation style was didactic, aiming to educate and empower the audience with a planning methodology.

Defensive Implications

▶ Watch: Considering personal safety and data compromise impact (8:10)

Rebecca Miller's talk provides a critical blueprint for individuals, families, and communities to bolster their defenses against a broad spectrum of disruptions, extending far beyond traditional cybersecurity threats. The defensive implications are profound, urging a shift from reactive problem-solving to proactive, holistic resilience planning.

1. Proactive Personal BCDR Planning: The foremost implication is the necessity of an individualized Business Continuity and Disaster Recovery (BCDR) plan. Defenders must initiate a comprehensive "impact analysis" to identify "essential functions" (e.g., work, bill payment, medical access) and the resources required (e.g., documents, medication, financial access, communication tools). This means documenting everything from passport locations to pet care arrangements, ensuring no critical dependency is overlooked.

2. Strengthening Personal Infrastructure and Redundancy: Individuals should evaluate their personal digital and physical infrastructure for single points of failure (SPOF). This includes implementing a UPS (Uninterruptible Power Supply) for home power resilience, considering secondary DNS for personal web services, and ensuring physical backups for critical data. The emphasis on "portability" means having essential devices (laptops, phones, hotspots) and their chargers readily available for rapid relocation.

3. Enhanced Data Privacy and Security Hygiene: Defenders must adopt a more aggressive stance on data privacy. This involves:

  • Proactive Threat Intelligence: Regularly checking services like dehashed, Have I Been Pwned, and Intelligence X for personal data leaks, and using tools like Shodan or Census to inventory and secure internet-connected devices.
  • Robust Password Management: Universal adoption of password managers (e.g., Bitwarden, 1Password) for generating unique, strong passwords, coupled with mandatory MFA (moving away from less secure SMS-based MFA).
  • Data Integrity Measures: Implementing hashing, digital signatures, and regular validation of backups to confirm data authenticity and prevent tampering.
  • Secure Communication: Standardizing on end-to-end encrypted messaging apps like Signal and exploring advanced options like VidID for untraceable communication.
  • VPN Usage: Employing a VPN to encrypt internet traffic and enhance online anonymity, especially on public Wi-Fi.

4. Post-Breach Readiness and Incident Response: Recognizing that breaches are inevitable, defenders need a personal incident response plan. This includes immediate actions like logging out of all accounts, changing all passwords, setting up a new, clean email address, and meticulously monitoring financial accounts. Establishing emergency call trees with pre-arranged "code words" is crucial for verifying identity and communicating urgent information to loved ones when digital channels might be compromised.

5. Community and Family Security Awareness: The defensive perimeter extends beyond the individual. Defenders are encouraged to educate their "inner circle" on cybersecurity best practices, including awareness training for phishing and social engineering attacks. This collective awareness strengthens the overall resilience of one's community network. Furthermore, critical discussions about the dangers of social media posting, even by friends and family, are necessary to prevent inadvertent exposure. Resources like Shannon Miller's "data deletion class" at Lockdown Your Life can be invaluable for cleaning up one's online presence.

6. Financial and Livelihood Contingency: Beyond digital security, defenders must prepare for economic disruptions. This involves establishing "alternate strategies" like secondary bank accounts, prepaid debit cards, or "petty cash slush funds," and calculating essential monthly survival expenses. For employment, exploring options like PTO banks, alternative shifts, or remote work capabilities ensures continuity of income.

7. Documentation, Testing, and Continuous Improvement: The most critical defensive implication is the need for meticulous documentation of all plans, stored in multiple, accessible locations. These plans are not static; they require regular "testing" through scenario walkthroughs with all involved parties. This practice builds muscle memory for crisis response, ensuring a "calm and structured response" rather than panic. Continuous review and updating are essential to keep plans current with changing personal circumstances and evolving threat landscapes.

By integrating these defensive strategies, individuals can transform themselves from passive targets into active participants in their own security and resilience, capable of navigating and recovering from the multifaceted disruptions of the modern world.

Key Takeaways

  • Personal BCDR is Essential: Apply business continuity and disaster recovery principles to your personal life, family, and community to prepare for diverse disruptions, not just cyber threats.
  • Conduct a Thorough Impact Analysis: Identify all essential functions (e.g., work, bills, medical care) and list every resource needed to perform them, including documents, finances, and communication tools.
  • Build Redundancy and Portability: Evaluate personal infrastructure for single points of failure, implement battery backups (UPS), consider secondary DNS, and ensure essential devices and chargers are portable for rapid relocation.
  • Proactive Data Security and Post-Breach Planning: Utilize threat intelligence tools (e.g., Have I Been Pwned, Shodan), adopt strong password managers and MFA, hash critical data, and have an immediate action plan for data breaches, including secure communication channels (Signal, code words).
  • Develop Alternate Strategies for Critical Functions: Create workarounds for potential failures, such as secondary bank accounts, emergency cash funds, and contingency plans for maintaining income during a crisis.
  • Document, Test, and Update Constantly: Write down all plans, store multiple copies securely, regularly test scenarios with your "inner circle," and continuously update plans to reflect changes in your circumstances or the threat landscape.

About the Speaker(s)

The speaker for this DEF CON talk was Rebecca Miller. She introduced herself as a cyber risk analyst who also "moonlights as a CISSP instructor." Her professional specialization lies in business continuity and disaster recovery planning, where she is responsible for creating, updating, and testing these vital plans for businesses across various industries. Miller's dedication to this field stems from a profound personal experience: a major disruption at a hospital where she was part of the leadership team, which suffered a "six-week downtime" due to a payroll system failure without a continuity plan. This challenging period, requiring "7 days a week" of manual effort, motivated her career pivot to help others avoid similar vulnerabilities. Her expertise is rooted in both theoretical knowledge and practical, crisis-driven experience, making her a credible voice on personal and organizational resilience.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

A well-intentioned talk from a credible practitioner that belongs at a community college continuing-ed night, not DEF CON. The BCDR-for-humans framing is coherent but the content is textbook material dressed up with jargon — nothing here would surprise a first-year security analyst, let alone a DEF CON crowd.

Heather Calloway (CISO) — WEAK

Rebecca Miller brings genuine practitioner credibility and a coherent framework, but the talk never escapes its own genre. Translating BCDR methodology into personal preparedness is a legitimate idea with real utility for a segment of the DEF CON audience — but the execution stays at the level of a checklist presentation, not a governance or operational shift.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33