> ## Content Index
> Fetch the complete content index at: https://cje.io/llms.txt
> Use this file to discover other available public pages before exploring further.

# Fragile Foundations: 100 days on the cyber-poor
- URL: https://cje.io/2026/09/04/fragile-foundations-100-days-on-the-cyber-poor/
- Published: 2026-09-04T06:11:57.000Z
- Updated: 2026-09-04T06:11:57.000Z
- Description: A 100-day sprint on the AI and cyber disruption of water, power, and emergency care, aimed at operators Josh Corman calls cyber-poor. The threats come from cyber, but most of the fixes come from engineering. If you find bugs for a living, there's a translation job that mostly doesn't exist yet.
- Author: Casey Ellis

This morning, about 100 people sat in on the kickoff call for IST's Fragile Foundations Sprint.

Short version: It's a 100-day sprint, launched today and wrapping on December 10, aimed at the AI and cyber disruption of **life safety critical functions**. Water, power, emergency care, the stuff where downtime tolerance is measured in hours and the failure mode is people getting hurt rather than data getting stolen. Josh Corman developed the program, Jen Ellis and David Batz are running it, and the Institute for Security and Technology is where it lives. Get involved.

The part that makes it different from most of what's floating around right now, and critically needed, is who it's for: Most of the AI-security conversation has been written by and for organizations that already have a SOC, a patch cadence, a budget line, and a general sense of cybersecurity "fitting somewhere". Josh's term for everyone else is "cyber-poor" (a policy-friendlier spin one Wendy Nather's **security poverty line**, which [she and I have chewed on many times before](https://cje.io/2024/11/14/youre-soaking-in-it-systemic-cyber-struggles/) and, in general, a concept I wholeheartedly subscribe to), and he's careful about what it means: Poor in incentives, information, or resources, not necessarily in competence on in will to make things safe for the user. The small and rural water utilities, the county hospitals, the folks running 30-year-old PLCs from vendors that no longer exist... these people have an abundance of engineering expertise and close to zero cyber anything, and they're also the most interesting targets for an adversary who wants to disrupt rather than steal. Volt Typhoon has been living in exactly this kind of infrastructure for a while, which is a lot closer to what I meant by the [actual vulnpocalypse](https://cje.io/2026/08/04/wake-me-after-the-vulnpocalypse/) than anything in the slopdemic is.

The line carried over from #UnDisruptable27: "no water, no hospitals, no kidding."

The bit that stuck with me, and the reason I think this is worth the time of security people's time, is Josh's inversion: the threats come from cyber, but most of the fixes (for now, at least) come from engineering. It's not shields up, it's connections down. Sometimes the right advice for a facility that can't afford to protect something is to disconnect it, or at least to run a "day without the Internet" drill. A discovery scan that's harmless in an IT shop can brick a PLC. "Just patch faster" and "just do zero trust" aren't answers when the company that made the software went out of business years ago. It's the [offense scales with compute, defense scales with committees](https://cje.io/2026/04/08/offense-scales-with-compute-defense-scales-with-committees/) problem, except that down here the committee is one part-time operator and a vendor that stopped answering the phone. That's a humbling frame for those of us who've spent a couple of decades getting good at a very particular kind of security, and an important one to draw attention to and work on as offensive capability gets cheaper and more broadly distributed.

The sprint runs five working groups:

- **Consequences analysis:** which of the 55 national critical functions matter most when disrupted, and how failures cascade across them (co-chairs Mark Montgomery and Éireann Leverett).
- **OT/ICS sector engagement:** the suppliers, integrators, and systemically important entities the cyber-poor depend on (co-chairs Alison King and Mike Holcomb).
- **Pragmatic guidance for cyber-poor operators:** realistic, jargon-free, deployable advice, including what to ask your vendors, integrators, and insurers (co-chairs Whitney Bowman-Zatzkin and Samara Moore).
- **Novel mitigation analysis:** the spicy one, and the closest to the [non-cooperative defense](https://cje.io/2026/08/13/non-cooperative-defense/) argument I've been making. Surfacing the ideas being whispered at hacker cons, from bricker bots to patching without consent, and scoring them on whether they're lawful, ethical, effective, and fast enough (co-chairs Michael Daniel and Art Manion).
- **Policy and incentives design:** what policymakers actually need to hear about this demographic, which is not necessarily what enterprise IT vendors keep telling them (co-chairs Matt Hayden and Megan Samford).

Deliverables land on December 10: pragmatic guidance, a mitigations framework, an ecosystem map, a prioritized risk map, and a report that's meant as an on-ramp for whatever comes next rather than a mic drop.

If you find bugs for a living, you're a translation layer here between "we found a thing" and "here's a mitigation an engineer with a 30-year-old controller can actually apply," which is a job that mostly doesn't exist yet.

The ask is one to two hours a week, weekly working group calls, and an all-hands every few weeks. Sign up at [the registration form](https://form.jotform.com/262367406420049?ref=cje.io) or go via [fragilefoundations.org](https://fragilefoundations.org/?ref=cje.io), pick one group or several, and if you know an operator in any of these functions who'd sit for a 60 to 90 minute interview, they want to hear from you even more than they want to hear from me.

House rules: No pitching, and treat what's shared as confidential unless told otherwise.

I have to say, the amount of energy and enthusiasm on this initial call was amazing, and very encouraging to see. I hope you'll consider getting involved, or pointing this towards someone you know is passionate about solving these kinds of problems.