Bringing Actionable Data to Internet Defenders @FIRSTdotorg
Bringing Actionable Data to Internet Defenders  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 4 hours ago
Bringing Actionable Data to Internet Defenders: Threat & Vulnerability Intelligence Capacity Building Efforts Across the Planet

Piotr Kijewski (The Shadowserver Foundation, NL)

Piotr Kijewski is the CEO and a Trustee at The Shadowserver Foundation, a non-profit organization with a mission of making the Internet a more secure environment. He also manages Shadowserver's large-scale data threat collection and sharing projects, as well as National CSIRT relationships. Piotr has over 20 years of operational experience in cybersecurity and incident response. He headed CERT.PL building up its various security data gathering and analysis projects as well as managing its anti-malware operations, including numerous botnet disruptions. Piotr is also a member of the Honeynet Project (where he has also served on the Board of Directors), a well-known and respected non-profit that is committed to the development of honeypot technologies and threat analysis. Recently, Piotr joined the Management Board of The Hague Chapter of the CyberPeace Institute.
--
The non-profit Shadowserver Foundation (https://shadowserver.org) has been active for over 15 years, delivering free daily threat and vulnerability intelligence feeds to 201 National CSIRTs covering 175 countries and territories, as well as over 8000 other organizations that have an Internet presence of any kind (including Sectoral CSIRTs, ISP/CSPs, hosting providers, enterprises, banks, academia, hospitals and SMEs).The presentation will cover Shadowserver's unique data driven approach to cybersecurity capacity building around the world. Shadowserver's focus is on delivering actionable, timely and relevant threat/vulnerability intelligence and victim data into the hands of Internet defenders at the operational level, and teaching them to understand the data being shared, automation, tools (such as IntelMQ) and processes necessary to respond to reported issues and incidents. It includes collaboration to understand and track the attack surface exposure of a country/constituency, potentially including deployment of dedicated sensor networks for improved insights. Our capacity building efforts aim to improve incident response capabilities across a country/constituency and strengthen its cyber resilience - by actioning, rather than merely collecting, reported security events or incidents. The goal is to help CSIRTs become high functioning through sustainable low cost solutions that can be realistically maintained for the mid to long term. As part of the talk, we will focus on our cyber capacity building efforts in Africa (which include collaboration with FIRST.org) and the Indo-Pacific, funded by the UK Foreign, Commonwealth and Development Office.
Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software SafetyBattle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST MemberThe Weaponization Gap: What 20 Million KEV Detections Reveal About Edge RemediationAztronomy: Establishing the Foundation of Attack Path Analysis in AzureImproving Security Across Nations with FIRST: Derek Manky, FIRST CORE Founding PartnerCVE/FIRST VulnCon 2026 & Annual CNA Summit Recap Video
FIRST |

Bringing Actionable Data to Internet Defenders

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER