Beyond the Alert

Pew's Robert Keefer on Reversing the Defender's Dilemma in Nonprofits


Listen Later

Robert Keefer, Associate Director of Security Operations at The Pew Charitable Trusts, has reversed the traditional security equation by building defense in depth that forces attackers to succeed multiple times rather than once. Unlike opportunistic criminal attacks that move on when initial methods fail, nation-state actors now specifically target nonprofits to destroy their ability to gather and disseminate truth, requiring continuous defense rather than single-point protection. His framework combines outsourced SOC providers, automated response systems, and zero trust principles, creating multiple layers where each bypass triggers immediate team response.

Robert positions security as a mission enabler rather than cataloging potential disasters, showing executives how to navigate regulatory requirements like GDPR without disrupting operations. He builds partnerships by being prescriptive about security goals while leaving implementation entirely to subject matter experts, treating each team member as a force multiplier rather than someone to micromanage. The philosophy extends to talent retention through genuine work-life balance where vacation means complete disconnection, mission-driven hiring that attracts people who prioritize purpose over maximum compensation, and vulnerability as a leadership strength. 

Topics Discussed:

  • Why nation-state actors now specifically target nonprofits, requiring different defense models than opportunistic criminal attacks
  • Building defense in depth that forces attackers to succeed multiple times before reaching valuable assets rather than defending perfectly
  • The prescriptive rather than proscriptive security approach that defines goals while leaving implementation to subject matter experts
  • How outsourced SOC providers enable continuous level-one triage through hundreds of rotating analysts who stay alert
  • Getting executive buy-in by positioning security as a mission enabler that streamlines operations
  • Attracting and retaining security talent through mission alignment, genuine work-life balance, and vulnerability as leadership strength
  • The shift from passwords to passphrases with MFA that eliminated help desk bottlenecks and half-day downtimes for remote workers.
  • Why security leadership has become a people role, with effective leaders spending time away from computers to build partnerships
  • The democratization of cybersecurity decision-making as organizations split CISO responsibilities by function and push security decisions down to teams doing day-to-day work
  • ...more
    View all episodesView all episodes
    Download on the App Store

    Beyond the AlertBy Dropzone AI