Time is Running Out – Tying it All Together – What Will You Do in the Near Term?

Josh Corman (Founder · I Am The Cavalry)

BSides Las Vegas 2025 · Day 1

Overview

This closing session for the I Am the Cavalry track at BSides Las Vegas is a synthesis talk and forward-looking briefing from Josh Corman, who describes himself as the founder of I Am the Cavalry and as driving a one-year pilot called Undisruptible 27 at the Institute for Security and Technology, a 501(c)(3) nonprofit. The pilot was initially funded (on the speaker’s account) by Craig Newmark of Craigslist. The talk’s stated aim is twofold: outline roughly the next two years of funded work now that additional support has been secured, and weave together themes from speakers across roughly two and a half days of the track. The framing is explicitly urgent: geopolitical timelines (references in the talk to 2027 and Xi Jinping / PLA readiness narratives), critical infrastructure risk (hospitals, water, power, food supply chains), and the need for empathy-driven public messaging that avoids both FUD and denial. The session includes playback and discussion of two draft advocacy videos focused on ransomware’s impact on hospitals and water-system dependence, audience reactions, and a detailed “theory of change” pivot from an information-gap model to one that also addresses motivation and enablement.

Watch on YouTube

Visual summary for Time is Running Out – Tying it All Together – What Will You Do in the Near Term? by Josh Corman
Visual summary for Time is Running Out – Tying it All Together – What Will You Do in the Near Term? by Josh Corman

Key moments

  1. 2:00 Opening framing: Undisruptible 27 pilot, Craig Newmark funding via IST, and the two-year roadmap plus synthesis of the track.
  2. 4:00 First video on hospital ransomware: delayed care, regional strain on outcomes, and critique of privacy-first shutdown messaging.
  3. 10:00 Second video on water and lifeline dependencies: connected-tech risk, Vault Typhoon naming, and the 2027 planning horizon in the narrative.
  4. 16:00 Audience pushback on messaging: distinguish compromise vs attack, remove 'time to prepare' if it enables procrastination.
  5. 24:00 Cyber-informed engineering example: analog pressure sensor and physical pump shutoff as a consequence-limiting control.
  6. 30:00 New theory of change: dozen hospital communities, water as weak link, regional exercises, and storytelling-driven replication.
  7. 38:00 Scale context: ~151k water plants, ~6k hospital-touching systems, ~4% ISAC participation—picking 12 pilot communities.
  8. 50:00 Closing rally: Slack/QR intake, stickers, secure-by-demand, and explicit call to nominate communities within weeks.

Time is Running Out – Tying it All Together – What Will You Do in the Near Term?

Speakers: Josh Corman, Founder, I Am the Cavalry; leading the Undisruptible 27 pilot, Institute for Security and Technology

Conference: BSides Las Vegas

YouTube: https://www.youtube.com/watch?v=57MWvStQzcw

Overview

This closing session for the I Am the Cavalry track at BSides Las Vegas is a synthesis talk and forward-looking briefing from Josh Corman, who describes himself as the founder of I Am the Cavalry and as driving a one-year pilot called Undisruptible 27 at the Institute for Security and Technology, a 501(c)(3) nonprofit. The pilot was initially funded (on the speaker’s account) by Craig Newmark of Craigslist. The talk’s stated aim is twofold: outline roughly the next two years of funded work now that additional support has been secured, and weave together themes from speakers across roughly two and a half days of the track. The framing is explicitly urgent: geopolitical timelines (references in the talk to 2027 and Xi Jinping / PLA readiness narratives), critical infrastructure risk (hospitals, water, power, food supply chains), and the need for empathy-driven public messaging that avoids both FUD and denial. The session includes playback and discussion of two draft advocacy videos focused on ransomware’s impact on hospitals and water-system dependence, audience reactions, and a detailed “theory of change” pivot from an information-gap model to one that also addresses motivation and enablement.

Background

▶ Watch: Opening framing: Undisruptible 27 pilot, Craig Newmark funding via IST, and t... (2:00)

Corman situates the work in a long-running thread: overdependence on undependable digital systems, contrasted with how physical engineering (bridges, buildings) rates loads and consequences. He references I Am the Cavalry as a twelve-year-old effort (launched August 1st, twelve years prior to the talk) and connects Undisruptible 27 to similar DNA: bridge Silicon Valley and national security concerns through a nonprofit educational lens.

The talk repeatedly returns to patient care as a consequence frame. One video argues that delayed or degraded care for time-sensitive conditions can worsen outcomes; the speaker cites (in the transcript) peer-reviewed work associated with Christian (identified in the talk as from UCSD and related collaborators) on topics like how longer ambulance rides affect mortality and how regional strain (including ransomware-affected regions) can harm heart patient outcomes. Separately, the speaker criticizes common hospital breach communications that emphasize privacy and “abundance of caution” shutdowns, arguing that the data may already be lost while operations are self-disabled—potentially for long enough to threaten hospital solvency. He mentions a statistic from the talk’s narrative arc: roughly 7,000 hospitals in 2015 versus about 6,000 later, and references (as presented on stage) hundreds at financial instability risk—described as not solely cyber-driven but accelerated by cyber.

The second video’s narrative introduces water as a lifeline dependency: hydrants, sanitation, hospital operations, and the claim that dependence on connected tech has outpaced security maturity. The speaker names Vault Typhoon as a PRC state-sponsored campaign discussed in public hearings, and mentions other actors (Russia, Iran) in the context of attacks on U.S. water systems. The talk notes bipartisan and White House alignment on seriousness, while also acknowledging messaging pitfalls (too scary vs. not scary enough; multiple stakeholder “love languages”).

Key Findings

▶ Watch: Second video on water and lifeline dependencies: connected-tech risk, Vault T... (10:00)

  1. Theory of change revision: The pilot began with a hypothesis that an information gap was primary—if people only knew, they would act. The speaker concludes that motivation and enablement/empowerment gaps must be addressed as well, requiring deeper engagement than education alone.
  1. Bullseye prioritization for the next phase: The center of the next push is described as preventing denial of patient care in hospital-serving communities (the speaker uses ~6,000 communities where water systems touch hospitals, against ~151,000 water plants nationally and ~50,000 serving homes). Water is treated as a likely weakest link relative to hospital continuity, alongside power and local governance.
  1. Community-scale delivery model: A plan is outlined to work directly with about twelve hospital communities (with three already selected but not named in the transcript), selected for diversity (urban/suburban/rural, red/blue states, at most two “cities” by the speaker’s constraint, unique topographies or strategic importance). The intent includes on-the-ground collaboration, regional exercises, capturing stories, and attempting national replication within resource constraints.
  1. Engineering-over-cyber-first mindset: The talk elevates cyber-informed engineering / consequence-informed engineering, citing Idaho National Lab training (including a free four-hour workshop referenced from the track) and examples like an analog pressure sensor tied to a physical pump shutoff (cost ballparks mentioned on the order of $2,000–$10,000 in the talk) as a way to absorb or prevent physical consequences when compromise is assumed inevitable.
  1. Trust and participation metrics: The speaker states very low ISAC participation among water utilities (~4% of 151,000), and contrasts water with sectors that have mandatory cyber controls (mentions NERC CIP for power). The implied finding is structural under-participation and uneven regulatory pressure.
  1. Narrative correction on “attacks”: The speaker intends to change messaging that implies successful destructive attacks have already occurred in some campaign contexts, emphasizing compromise versus attack (consequence not yet realized) to avoid a Sword of Damocles misframe—exact public attribution details are not fully specified in the transcript beyond the speaker’s intent to revise the video language.

Technical Deep Dive

▶ Watch: Cyber-informed engineering example: analog pressure sensor and physical pump ... (24:00)

The “technical” content here is split between operational technology consequence chains and program design.

Interdependence modeling: The talk describes hospitals as failing not only from direct ransomware but from regional strain and from utilities (no water means no hospital operations: stickers referenced include “no water, no hospitals”). Water hammer is used as a teachable physics failure mode accessible to engineers and storytellers alike.

Cyber-informed engineering (CIE): Rather than treating resilience purely as restore/recover, the speaker argues some failures are non-resurrectable (patient harm, catastrophic mains breaks). The emphasis is prevent/absorb for OT/ICS-style outcomes, analog safeguards, and consequence-driven design.

Stakeholder sequencing: Owners/operators (e.g., water engineers) first, then municipal leadership, emergency management / NIMS, public health, and later potentially everyday Americans—with concern expressed (including a named worry from Bryson) about premature public messaging.

Funding and scope: A commitment is described of roughly $3.2 million or $2 million over two years (the transcript contains both figures in close proximity) from Craig Newmark for a refined plan, replacing a “bridge to nowhere” fear with a funded roadmap.

Volunteer pathways: References include Cyber Resilience Corps (spelled in multiple ways in the transcript), Cyber Civil Defense Network, DEF CON Franklin, and Cyber ACU View (insurance consortium of top 20 underwriters) as adjacent forces; the speaker wants lifeline sectors to take a punch before defaulting to generic cyber hygiene volunteering.

Demo / Proof of Concept

▶ Watch: New theory of change: dozen hospital communities, water as weak link, regiona... (30:00)

The session demonstrates two draft videos (audio-visual playback) rather than a software exploit demo. The first focuses on hospital disruption and patient harm framing; the second broadens to water/power lifelines and geopolitical escalation timelines, including mention of 2027 as a planning horizon in the narrative. The speaker also references stickers and a QR code intake to Slack / volunteer platform as lightweight participatory artifacts. No live exploit or tool demo is presented in the transcript beyond these media pieces and program slides.

Defensive Implications

▶ Watch: Closing rally: Slack/QR intake, stickers, secure-by-demand, and explicit call... (50:00)

For defenders and operators, the talk argues for:

  • Consequence-first planning across water–hospital–power dependencies, not siloed IT recovery metrics.
  • Community-level exercises that force prioritization questions (the speaker recounts an international exercise where data centers were restored before hospitals, and pushes back morally—even if “they might be right” economically).
  • Enrollment of legitimate engineering mitigations (CIE patterns) that work under assumed compromise.
  • Better procurement and vendor pressure (“secure by demand” alongside secure by design/default), including replacing bad edge devices implicated in known campaigns where possible.
  • Credentialing for helpers who want to integrate with incident command (references ICS as incident command systems, NIMS training).

For communications teams, the implication is to reject privacy-only breach framing when patient safety is at stake, while still avoiding careless exaggeration; the speaker advocates honesty akin to hurricane warnings.

Key Takeaways

  • Undisruptible 27 is positioned as a funded, nonprofit-backed effort to make lifeline services harder to disrupt, with a pivot from awareness to motivation + enablement.
  • Hospital communities and water dependencies are the near-term bullseye, with a dozen pilot geographies intended to surface edge cases and produce replicable playbooks and stories.
  • Cyber-informed / consequence-informed engineering is treated as the highest-yield near-term discipline for many scenarios, not more dashboard cyber alone.
  • Low ISAC participation and uneven mandatory controls mean many utilities lack the collective defense fabric present in other sectors.
  • Storytelling must be stakeholder-specific, deliberately imperfect where polish would read as sales, and iterated with community input.
  • The speaker issues a practical call: nominate candidate communities, join the project Slack, and treat the next 12–18 months as the relevant urgency window—while acknowledging uncertainty whether timelines slip.

About the Speaker(s)

Josh Corman presents himself as the founder of I Am the Cavalry and the driver of the Undisruptible 27 pilot under the Institute for Security and Technology, with funding ties described to Craig Newmark. He references personal motivation tied to grief after his mother’s death shaping an empathy-centered approach. He discusses past roles/contexts including work related to a CISA vaccine supply-chain effort (“ball bearings” metaphor), collaboration with Hack the Capital / Bryson Bort, and relationships with congressional staff and policy initiatives (mentions Jim Langevin, cyber caucus, Cyberspace Solarium Commission, and Nick Leiserson as examples in the narrative). Titles for some collaborators are as stated in the transcript; any items not explicitly verified beyond the talk are unknown.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

This is a mission-control keynote-style closer: heavy on narrative, coalition-building, and program mechanics, light on falsifiable technical claims. It is valuable if you are trying to understand how critical-infrastructure advocacy gets funded, messaged, and operationalized—but it is not a research talk.

Heather Calloway (CISO) — STRONG ACCEPT

This is governance in work boots: it forces executives and public communicators to confront that cyber incidents in hospitals and utilities are often safety and continuity incidents first. The program design—pilots, exercises, measurable replication—is how you translate dread into owned outcomes.

→ Top-rated talks at BSides Las Vegas 2025

All talks from BSides Las Vegas 2025