Cyber Volunteering & Community Defense 1 yr in - DC Franklin
Sarah Powazek, Jake Braun, Adrien Ogee
DEF CON 33 · Day 2 · Main Stage
Overview
Most DEF CON talks center on offensive techniques, novel vulnerabilities, or adversary tradecraft. This one is different. At DEF CON 33, Sarah Powazek, Jake Braun, and Adrien Ogee presented a frank on

Key moments
- 1:48 Hi everyone, I'm Adrian OG.
- 6:18 through the EBT account um from over $143,000 households.
- 12:09 that are currently identified.
- 18:54 the platform looks like before I hand over to to Jake.
- 25:38 day in medicine after or yeah sure yeah okay so I'll let I'll tell you more about this...
- 32:24 have your insider threats, your your employees, your disgruntled employees.
- 39:09 were an initial seed for for the organization and they're very heavily involved.
Cyber Volunteering & Community Defense: DEF CON Franklin and the Cyber Resilience Corps — 1 Year In
Speakers: Sarah Powazek, Jake Braun, Adrien Ogee
Conference: DEF CON 33
YouTube: https://www.youtube.com/watch?v=LdiawBeYOCc
Overview
Most DEF CON talks center on offensive techniques, novel vulnerabilities, or adversary tradecraft. This one is different. At DEF CON 33, Sarah Powazek, Jake Braun, and Adrien Ogee presented a frank one-year operational retrospective on two of the most active structured cyber volunteering programs in the United States and internationally: DEF CON Franklin (launched by Braun at DEF CON 32) and the CyberPeace Builders (operated by the CyberPeace Institute, represented by Ogee). The talk is less a research presentation than a structured accountability document: what was the problem, what did these programs do, what did they learn, and why does it matter to the DEF CON community.
The underlying argument — delivered with empirical data rather than rhetoric — is that there is a massive, widening cybersecurity market failure affecting the most vulnerable organizations in society, and that the skills concentrated in the DEF CON community represent one of the few scalable responses to it. For practitioners who have wondered what to do with their skills beyond protecting corporate infrastructure, this talk is a direct answer.
Background
▶ Watch: Hi everyone, I'm Adrian OG. (1:48)
The Market Failure in Cybersecurity
Powazek, who directs the Public Interest Cybersecurity program at UC Berkeley's Center for Long-Term Cybersecurity, framed the problem with precision: the average cost of a breach is $80,000, a figure that is existential for small nonprofits, rural utilities, food banks, and local government agencies. These organizations cannot afford the commercial cybersecurity products and services that protect enterprise environments — and yet they handle sensitive personal data, operate critical infrastructure, and serve populations with no fallback options.
The scale of the problem is hard to quantify directly, but the talk used research from the University of Maryland as a proxy: a study of US county governments found that a majority of US states had over 50% of their counties running publicly exposed insecure services — Telnet, FTP, RDP, or SSH — discoverable from the open internet. As Powazek noted, basic authorization controls are among the most fundamental cybersecurity hygiene measures, and this is the state of local government infrastructure across the country.
Who Bears the Burden
The impact of this market failure is not evenly distributed. Powazek presented evidence across two dimensions:
More exposed:
- Rural hospitals serve approximately 20% of the US population. They operate with limited IT budgets, reduced staffing, and aging infrastructure while handling highly sensitive patient data.
- Nonprofit electric cooperatives serve 92% of persistent poverty counties and cover the vast majority of US geography. Most people outside major metropolitan areas depend on a nonprofit co-op for electricity — organizations that typically lack dedicated cybersecurity personnel.
Less able to recover:
- When the University of Vermont Medical Center was hit with ransomware, it had to turn away 75% of its cancer patients. Many patients could not travel 4+ hours to Boston for alternative care. They had nowhere else to go.
- EBT (food stamp) account theft has reached $69 million stolen from over 143,000 households according to figures cited in the talk. Among victims, 53% had to skip meals as a direct result, and 44% had to borrow money or go into debt. These are people for whom cyber attacks translate directly into food insecurity.
The core point: cybersecurity failure in these organizations is not a corporate inconvenience. It produces measurable human harm to people who are already operating without safety margins.
What Cyber Volunteering Is (and Is Not)
The talk explicitly distinguished structured cyber volunteering from other forms of charitable contribution to the field:
What it is:
- Pro bono delivery of real security services: cyber maturity assessments, implementation guidance, penetration testing, incident response, hands-on training.
- Skilled professionals providing the same quality of work they would deliver commercially, at no cost to the recipient organization.
- Long-term relationship building with organizations that lack the expertise to evaluate or act on generic recommendations.
What it is not:
- Handing organizations a toolkit or free software license.
- Publishing guides and expecting resource-constrained organizations to implement them.
- Awareness campaigns or educational content consumption.
The distinction matters because underfunded organizations typically don't lack access to information — they lack the skilled human capacity to act on it. Volunteering addresses the capacity gap directly.
Key Findings: One Year of DEF CON Franklin
▶ Watch: that are currently identified. (12:09)
Jake Braun launched DEF CON Franklin at DEF CON 32, named for Benjamin Franklin and his concept of civic service. The program's core model is connecting DEF CON-community security professionals with resource-constrained organizations to deliver pro bono security assistance.
At the one-year mark, Braun reported that the program had:
- Built a structured intake and matching process for organizations seeking help and volunteers offering capacity.
- Delivered engagements across multiple sectors including local government, rural healthcare, and nonprofits.
- Connected with more than ten other volunteer initiatives operating in parallel, some of which the speakers had not been aware of before announcing Franklin — illustrating both the scale of the movement and the need for coordination infrastructure.
A key lesson from year one: individual volunteer programs operating in isolation have limited impact. The DEF CON 33 panel was deliberately structured to bring multiple organizations together to demonstrate the combined force of coordinated volunteer infrastructure — and to model the kind of coalition-building that makes the movement durable rather than episodic.
Key Findings: The CyberPeace Builders Program
▶ Watch: the platform looks like before I hand over to to Jake. (18:54)
Adrien Ogee represented the CyberPeace Institute, a Geneva-based nonprofit operating the CyberPeace Builders program. Unlike Franklin's DEF CON community focus, CyberPeace Builders operates globally, with a particular focus on civil society organizations, humanitarian NGOs, and institutions serving vulnerable populations internationally.
Key operational characteristics of the Builders program:
- Structured volunteer onboarding: Volunteers go through a vetting and training process to ensure consistent service quality.
- Team-based delivery: Engagements are delivered by small teams rather than individual volunteers, improving reliability and knowledge transfer.
- Scope-controlled assessments: Engagements are bounded and scoped to be achievable within a volunteer time commitment while still producing actionable outcomes.
- Impact measurement: The program tracks and publishes outcomes, enabling accountability and iterative improvement.
The CyberPeace Institute has documented cases where volunteer engagements identified and remediated critical vulnerabilities in organizations working with refugees, domestic violence victims, and medical services in conflict zones — populations for whom a data breach is not merely costly but potentially life-threatening.
Technical Deep Dive: The Structural Problem
▶ Watch: day in medicine after or yeah sure yeah okay so I'll let I'll tell you more a... (25:38)
While this talk is less technical than typical DEF CON content, the structural problem it describes has a technical core worth examining.
The Attacker-Defender Asymmetry at the Community Level
In enterprise security, defenders can purchase tooling, hire specialists, and maintain ongoing operations. The asymmetry between attacker and defender resources is real but partially addressable through capital expenditure.
For the organizations this talk focuses on, the asymmetry is absolute: they face the same threat landscape as enterprises but have essentially zero defensive capacity. The attack surface for a rural county government is almost identical to that of a comparable-size enterprise: public-facing web services, email, Active Directory or equivalent, RDP/VPN for remote access, financial systems. The threat actors — ransomware groups in particular — do not discriminate by victim type. They target whoever is vulnerable and whoever is likely to pay.
The University of Maryland research cited in the talk is technically unambiguous: Telnet, FTP, and exposed RDP services in 2024 are not hygiene failures with nuance — they are cleartext or weakly authenticated remote access services that any competent threat actor can exploit with commodity tooling. The fact that a majority of US county governments have at least one such service publicly exposed is an accurate measure of the gap between current state and a reasonable baseline.
Scaling the Volunteer Model
A persistent challenge in cyber volunteering is the mismatch between volunteer episodic availability and organizational need for continuous improvement. The programs discussed have addressed this through:
- Phased engagements: Breaking work into discrete, completable phases that match volunteer time availability (evenings, weekends).
- Standardized assessment frameworks: Using consistent methodologies that different volunteers can apply and that produce comparable outputs across engagements.
- Warm handoffs: Ensuring organizational continuity even when individual volunteers rotate off.
- Triage prioritization: Focusing on high-impact, low-cost remediations first — patching, disabling unnecessary services, enabling MFA — before more complex architectural work.
For the DEF CON community specifically, this maps well to the skill sets already present in the room: penetration testers can deliver fast, actionable assessments; incident responders can provide breach triage; engineers can help with implementation; educators can deliver training.
Demo / Proof of Concept
▶ Watch: have your insider threats, your your employees, your disgruntled employees. (32:24)
This talk's "demo" was its retrospective data. The speakers presented:
- Volume metrics: Number of organizations served, volunteers engaged, and engagements completed across both programs.
- Impact case studies: Specific examples of vulnerabilities found and remediated, organizational outcomes improved, and communities protected through the work.
- Volunteer experience: Jonathan Farley, a volunteer with both DEF CON Franklin and CyberPeace Builders, spoke to his personal experience of the engagement process — what it actually felt like to deliver a security assessment to a food bank or rural healthcare provider, and why it was meaningful work.
- The gap in coverage: Maps and statistics illustrating the geographic and sectoral coverage of existing programs versus the scale of need — making clear that current volunteer capacity, while growing, is orders of magnitude below what is needed.
Defensive Implications
▶ Watch: were an initial seed for for the organization and they're very heavily involved. (39:09)
For the Security Community
The central ask of this talk is direct: bring your skills to the communities that need them most. Specific implications:
- Volunteer: Both DEF CON Franklin and CyberPeace Builders have structured intake processes for new volunteers. The barrier to entry is a willingness to commit time and skills, not any specialized credential.
- Employ your full skill set: Penetration testers, incident responders, GRC practitioners, engineers, educators — all of these are needed. Volunteer programs need breadth, not just technical depth.
- Help build the infrastructure: The talks' meta-message is that the volunteer ecosystem itself needs investment — coordination infrastructure, shared methodologies, training for volunteer onboarding, and organizational partnerships that scale the model beyond individual heroics.
For Policy Makers and Program Officers
- Fund coordination, not just capacity: Many volunteer programs exist in isolation. Funding organizations that provide shared infrastructure, training, and coordination multiplies the impact of individual programs.
- Measure the right things: Impact measurement in this space is hard. Programs need support developing outcome metrics that reflect real community resilience improvement, not just engagements delivered.
- Remove legal friction: Volunteers providing pro bono security services face potential liability exposure that corporate practitioners are insulated from. Legal clarity and Good Samaritan protections for pro bono security work would lower barriers to participation.
For Organizations Seeking Help
- Know that help exists: The talk explicitly addresses the stigma and information gap that prevents many organizations from seeking help. There are structured, free, professional security services available.
- Prioritize low-hanging fruit: The most impactful remediations for these organizations are often the most basic — disabling unnecessary internet-exposed services, enabling MFA, patching known vulnerabilities. You do not need to achieve enterprise security posture to dramatically reduce your risk.
Key Takeaways
- The cybersecurity market failure at the community level is large, measurable, and producing real human harm. This is not a theoretical problem.
- The DEF CON community has the skills to help, and structured programs exist to channel that help effectively. DEF CON Franklin and CyberPeace Builders are operational and scaling.
- Coordination across volunteer programs multiplies impact. The one-year retrospective shows that the ecosystem of volunteer programs is broader than any single initiative — and that connecting them is itself high-value work.
- Volunteer work in this space is technically substantive. Organizations are not asking for advice — they need real security assessments, hands-on implementation help, and incident response. The work matches the skills of serious practitioners.
- The problem is too large for volunteer capacity alone. Structural solutions — regulation, shared security services, government-funded programs — are necessary companions to volunteer efforts. But volunteering is what's available now.
About the Speakers
Sarah Powazek is the Program Director for Public Interest Cybersecurity at the UC Berkeley Center for Long-Term Cybersecurity (CLTC). Her work focuses on building the evidence base and programmatic infrastructure for cybersecurity assistance to under-resourced organizations, particularly in public interest sectors.
Jake Braun is the founder of DEF CON Franklin and has a background in government cybersecurity policy, including work on election security and critical infrastructure protection. He serves as a connector between the technical DEF CON community and the public and civic institutions that need its skills.
Adrien Ogee is the Chief Operations Officer of the CyberPeace Institute, a Geneva-based nonprofit. He leads the CyberPeace Builders program, which delivers structured pro bono cybersecurity assistance to NGOs and civil society organizations globally.
Jonathan Farley also participated in the panel as a practitioner voice, representing volunteer experience from both DEF CON Franklin and CyberPeace Builders. His background is in application security testing, penetration testing, and security education.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
One-year retrospective on DEF CON Franklin and CyberPeace Builders volunteer programs. Important mission, well-intentioned speakers, but this is a program update and a recruitment pitch, not a security talk. The technical content is thin and the structural market failure argument, while sound, has been made many times before.
Heather Calloway (CISO) — STRONG ACCEPT
A structured one-year retrospective on two volunteer security programs serving rural hospitals, food banks, local government, and NGOs — backed by empirical data on a market failure that is producing real human harm. The most governance-forward talk in any batch I have reviewed at this conference.