From Dork to Diplomat: Communicating Coherently for Vulnerability & Incident Response @FIRSTdotorg
From Dork to Diplomat: Communicating Coherently for Vulnerability & Incident Response  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 5 hours ago
Tom Millar (CISA, US), Rina Rakipi (CISA, US)

If you’ve ever struggled to translate technical threat and vulnerability data into actionable risk information that both peers and senior decision‑makers can intuitively understand — this session is for you.

In the fast‑moving world of incident and vulnerability response, technical precision is critical — but it’s trust and communication that determine whether your message drives action or gets lost in translation. This talk, co‑presented by threat intel and vulnerability operations leaders, explores how to communicate effectively across silos, sectors, and sensitivities.

We’ll share real‑world lessons from coordinating across government, industry, and international partners — where the stakes are high, the timelines tight, and the audiences diverse. From decoding threat intel for non‑technical stakeholders to navigating disclosure diplomacy, we’ll show how clarity, credibility, and context can turn a “dork” into a trusted diplomat.

Attendees will leave with practical tools for briefing leadership, collaborating across teams, and building trust in the heat of response. Whether you’re deep in the hunt or leading the charge, this session will help you communicate with impact — and without compromise.

---

Tom Millar has served in CISA since 2009, working to strengthen the nation’s cyber defenses and resilience against emerging threats. His work has included increasing the level of public, private and international partner engagement, and supporting initiatives to improve information sharing, such as the standardization of the Traffic Light Protocol. As the Branch Chief of Cyber Resilience within the Cyber Security Division, he oversees CISA’s architectural cybersecurity assessments, the Cybersecurity Performance Goals program, and training and standards for assessment performance. Prior to his cybersecurity career, he served as a linguist with the 22nd Intelligence Squadron of the United States Air Force. Mr. Millar holds a Master’s of Science from the George Washington University and is a Distinguished Graduate of the National Defense University’s College of Information and Cyberspace.

Rina Rakipi serves as the Operations Coordinator within CISA’s Threat Hunting subdivision. She turns complex threat activity into clear, actionable intelligence, driving cyber campaigns and strengthening coordination across federal, industry, and international partners. She previously led CISA’s Secure by Design Alert series, advancing efforts to reduce systemic software vulnerabilities, and helped modernize the CVE Program to improve the speed and accuracy of national vulnerability records. Earlier in her career, she shaped major joint cybersecurity guidance as a lead technical editor and writer, bridging technical depth with strategic communication. Rina holds a B.A. in International Relations from Michigan State University and an M.Eng. in Cybersecurity Policy and Compliance from the George Washington University. Her work sits at the crossroads of global affairs, software security, and national cyber defense.
From Dork to Diplomat: Communicating Coherently for Vulnerability & Incident ResponseBroken Seals, Broken Trust: Flaws and Defences in the Certificate EcosystemBringing Chronological Context to Disparate Artifacts: Accelerating Digital ForensicsQuantifying Swiss Cheese, the Bayesian WayMind Over Malware: Reducing Decision Fatigue in Incident Response TeamsSupply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?Incident Preparedness Takeaways from 5000 Exercise ParticipantsEpisode 63: John Hollenberger, Fortinet, FIRSTCON26 SpeakerRevolutionizing Malware Analysis with Agentic AI: Lessons and InnovationsIdentifying Exploited and Likely-to-Be-Exploited VulnerabilitiesTaming the Scanner Storm: How VEX Brings Context to Vulnerability DataEpisode 62: Tim Brown, Team8, former SolarWinds CISO, FIRSTCON26 Keynote
FIRST |

From Dork to Diplomat: Communicating Coherently for Vulnerability & Incident Response

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER