Uploaded August 2025 | Updated September 2026, 4 hours ago
Bringing Actionable Data to Internet Defenders: Threat & Vulnerability Intelligence Capacity Building Efforts Across the Planet
Piotr Kijewski (The Shadowserver Foundation, NL)
Piotr Kijewski is the CEO and a Trustee at The Shadowserver Foundation, a non-profit organization with a mission of making the Internet a more secure environment. He also manages Shadowserver's large-scale data threat collection and sharing projects, as well as National CSIRT relationships. Piotr has over 20 years of operational experience in cybersecurity and incident response. He headed CERT.PL building up its various security data gathering and analysis projects as well as managing its anti-malware operations, including numerous botnet disruptions. Piotr is also a member of the Honeynet Project (where he has also served on the Board of Directors), a well-known and respected non-profit that is committed to the development of honeypot technologies and threat analysis. Recently, Piotr joined the Management Board of The Hague Chapter of the CyberPeace Institute.
--
The non-profit Shadowserver Foundation (https://shadowserver.org) has been active for over 15 years, delivering free daily threat and vulnerability intelligence feeds to 201 National CSIRTs covering 175 countries and territories, as well as over 8000 other organizations that have an Internet presence of any kind (including Sectoral CSIRTs, ISP/CSPs, hosting providers, enterprises, banks, academia, hospitals and SMEs).The presentation will cover Shadowserver's unique data driven approach to cybersecurity capacity building around the world. Shadowserver's focus is on delivering actionable, timely and relevant threat/vulnerability intelligence and victim data into the hands of Internet defenders at the operational level, and teaching them to understand the data being shared, automation, tools (such as IntelMQ) and processes necessary to respond to reported issues and incidents. It includes collaboration to understand and track the attack surface exposure of a country/constituency, potentially including deployment of dedicated sensor networks for improved insights. Our capacity building efforts aim to improve incident response capabilities across a country/constituency and strengthen its cyber resilience - by actioning, rather than merely collecting, reported security events or incidents. The goal is to help CSIRTs become high functioning through sustainable low cost solutions that can be realistically maintained for the mid to long term. As part of the talk, we will focus on our cyber capacity building efforts in Africa (which include collaboration with FIRST.org) and the Indo-Pacific, funded by the UK Foreign, Commonwealth and Development Office.
Bringing Actionable Data to Internet Defenders: Threat & Vulnerability Intelligence Capacity Building Efforts Across the Planet
Piotr Kijewski (The Shadowserver Foundation, NL)
Piotr Kijewski is the CEO and a Trustee at The Shadowserver Foundation, a non-profit organization with a mission of making the Internet a more secure environment. He also manages Shadowserver's large-scale data threat collection and sharing projects, as well as National CSIRT relationships. Piotr has over 20 years of operational experience in cybersecurity and incident response. He headed CERT.PL building up its various security data gathering and analysis projects as well as managing its anti-malware operations, including numerous botnet disruptions. Piotr is also a member of the Honeynet Project (where he has also served on the Board of Directors), a well-known and respected non-profit that is committed to the development of honeypot technologies and threat analysis. Recently, Piotr joined the Management Board of The Hague Chapter of the CyberPeace Institute.
--
The non-profit Shadowserver Foundation (https://shadowserver.org) has been active for over 15 years, delivering free daily threat and vulnerability intelligence feeds to 201 National CSIRTs covering 175 countries and territories, as well as over 8000 other organizations that have an Internet presence of any kind (including Sectoral CSIRTs, ISP/CSPs, hosting providers, enterprises, banks, academia, hospitals and SMEs).The presentation will cover Shadowserver's unique data driven approach to cybersecurity capacity building around the world. Shadowserver's focus is on delivering actionable, timely and relevant threat/vulnerability intelligence and victim data into the hands of Internet defenders at the operational level, and teaching them to understand the data being shared, automation, tools (such as IntelMQ) and processes necessary to respond to reported issues and incidents. It includes collaboration to understand and track the attack surface exposure of a country/constituency, potentially including deployment of dedicated sensor networks for improved insights. Our capacity building efforts aim to improve incident response capabilities across a country/constituency and strengthen its cyber resilience - by actioning, rather than merely collecting, reported security events or incidents. The goal is to help CSIRTs become high functioning through sustainable low cost solutions that can be realistically maintained for the mid to long term. As part of the talk, we will focus on our cyber capacity building efforts in Africa (which include collaboration with FIRST.org) and the Indo-Pacific, funded by the UK Foreign, Commonwealth and Development Office.










