Panel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ... @FIRSTdotorg
Panel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...  @FIRSTdotorg
Uploaded August 2026 | Updated September 2026, 3 hours ago
Panel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim Notification Processfor International Law Enforcement Cybercrime Disruption Operations

Tod Eberle (The Shadowserver Foundation, US), Adam Diament (Defense Criminal Investigative Service (DCIS), US), Stu W (NCSC, GB), Stewart Garrick (Shadowserver, GB), Chris Butera (CISA)

The panel will examine the operational means and challenges in each stage of the data‑sharing pipeline of the victim‑notification process associated with international law‑enforcement cybercrime takedowns and disruption operations. The panelists will include a federal law‑enforcement officer, a representative of the Shadowserver Foundation, and a representative of a National CSIRT, who each will provide their unique perspectives on the victim‑notification process from start to finish.

The discussion will include their respective roles in the data‑sharing pipeline; the current framework in place for sharing victim data on a global scale; the various operational means by which each entity shares data with third parties; limitations on data sharing due to legal, technical, and jurisdictional factors; overcoming challenges that arise in the process; and the impact of Early Warning Services and similar mechanisms by which National CSIRTs can most effectively share victim data with ISPs and help make notifications to end‑user victims.

---

Tod Eberle is the Alliance Director at The Shadowserver Foundation, a nonprofit cybersecurity organization. Shadowserver collects cyber threat data at Internet-scale and distributes free daily network remediation reports to help 10,000+ organizations and National CSIRTs covering 175 countries secure their networks. Shadowserver also provides free support to many of the world’s most significant international Law Enforcement cybercrime disruption operations. Tod leads Shadowserver’s Alliance Partnership, a community of like-minded organizations that support Shadowserver’s nonprofit mission and work collaboratively to share information and address the latest cyber threats.

Adam Diament is a Special Agent with the Defense Criminal Investigative Service (DCIS), where he’s responsible for conducting complex cybercrime investigations, including investigations into botnets and malicious proxy services. Prior to joining DCIS, Adam worked as a Special Agent for the US Secret Service, where he specialized in cyber-enabled fraud and network intrusion investigations. He also served as a Cryptologic Linguist in the US Marine Corps and holds a bachelor’s degree from the George Washington University and a master’s degree from George Mason University.

Stu graduated in 2004 with a degree in Computer Science, before embarking on a career in cyber related roles for His Majesty’s Government. 22 years later, he’s still there. Stu moved to the National Cyber Security Centre in 2021 to head up the Incident Management operational team – a role that has kept him fairly busy for the last 5 years!

Stewart Garrick (Law Enforcement Liaison and Operations Manager, male)

Has worked for the Shadowserver Foundation for over ten years, having previously served thirty years in UK Law Enforcement (twenty-seven years with the Metropolitan Police before moving to the National Crime Agency as a Senior Investigating Officer). As a career detective, he worked primarily on major crime units engaged in both proactive and reactive investigations, including many high-profile cybercrime cases as the senior investigator— such as the Dridex and Gameover Zeus botnet takedowns. He now works in Law Enforcement supporting roles for Shadowserver. He is currently actively engaged in multiple ongoing international investigations. He understands the operational challenges and differing evidentiary restrictions and capabilities across the EU and worldwide. His focus is always to help Law Enforcement achieve their intelligence and evidential needs in ways they can actually use. Qualifications: MSc in Countering Organised Crime and Terrorism at UCL and Certified Information Systems Security Professional (CISSP).

Chris Butera is the Acting Executive Assistant Director for the Cybersecurity Division of the Cybersecurity and Infrastructure Security Agency (CISA). As CISA’s senior career cybersecurity official, he is responsible for leading the agency’s mission to address the nation’s most significant cyber threats and vulnerabilities and to increase the security and resilience of U.S. critical infrastructure. Mr. Butera additionally serves as a board member for both the Technology Modernization Fund and the Federal Risk and Authorization Management Program (FedRAMP).
Panel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...Bringing Actionable Data to Internet DefendersUnlocking Insights: The Role of TI in Modern DFIR OperationsThe Quality Era of CVE: A Blueprint for Global Software SafetyBattle-Tested Incident Recovery: Lessons from the Front LinesThe AI Assistant’s Betrayal: One-Click for AI to Turn into the Perfect InsiderBoosting Vulnerability Intelligence: How Accurate CWE Mappings Transform ML Model PerformanceCan a General-Purpose LLM Do Tier-1 Triage?Improving Security Across Nations with FIRST: Esmeralda Kazia, FIRST MemberThe Weaponization Gap: What 20 Million KEV Detections Reveal About Edge RemediationAztronomy: Establishing the Foundation of Attack Path Analysis in AzureImproving Security Across Nations with FIRST: Derek Manky, FIRST CORE Founding Partner
FIRST |

Panel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER