<div dir="ltr"><div class="gmail_default" style="font-family:georgia,serif;font-size:small">Thank you Johan for sharing this! And thank Kathy and Ken for your inputs.</div><div class="gmail_default" style="font-family:georgia,serif;font-size:small"><br></div><div class="gmail_default" style="font-family:georgia,serif;font-size:small">The intriguing part is that the above listed entities and individuals sometimes tend to minimize how exposed they are to cyber threats, because they tell themselves they are not-for-profit organizations or individuals. I will read the document - I have just downloaded it and it is 19 pages long. </div><div class="gmail_default" style="font-family:georgia,serif;font-size:small"><br></div><div class="gmail_default" style="font-family:georgia,serif;font-size:small">Regards,</div><div class="gmail_default" style="font-family:georgia,serif;font-size:small"><br></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div class="gmail_default" style="font-family:georgia,serif;font-size:small">Gbeere Achille Eye</div><br><div href="http://WS_promo" style="color:rgb(34,34,34);width:auto;padding-top:2px;font-size:10px;border-top:1px solid rgb(238,238,238);margin-top:18px;display:table;direction:ltr;line-height:normal;border-spacing:initial"><div><i><font face="tahoma, sans-serif"><span style="color:rgb(165,3,16)"><br></span></font></i></div><i><font face="tahoma, sans-serif"></font></i></div><i style="color:rgb(34,34,34)"><font face="tahoma, sans-serif"></font></i></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, May 15, 2024 at 2:25 PM Ken Herman <<a href="mailto:ken@kherman.com">ken@kherman.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div class="msg2571879281412751740"><div lang="EN-US" style="overflow-wrap: break-word;"><div class="m_2571879281412751740WordSection1"><p class="MsoNormal"><span style="font-size:11pt">I also thank Julf for sharing this. I had not seen it before, but as a I work in the cybersecurity field the message resonates with me. <u></u><u></u></span></p><p class="MsoNormal"><span style="font-size:11pt"><u></u> <u></u></span></p><p class="MsoNormal"><span style="font-size:11pt">Kathy, as you point out, mitigating risk begins with establishing policies that protect, rather than expose. <u></u><u></u></span></p><p class="MsoNormal"><span style="font-size:11pt"><u></u> <u></u></span></p><p class="MsoNormal"><span style="font-size:11pt">Maybe we can also think about going beyond, to advocate for monitoring adherence to policy, followed by supporting our community to become aware of the policies and ways to query vendor (registrars?) regarding these policies, so covering all phases (establishment, adherence and awareness) of the policy lifecycle.<u></u><u></u></span></p><p class="MsoNormal"><span style="font-size:11pt"><u></u> <u></u></span></p><p class="MsoNormal"><span style="font-size:11pt">Ken<u></u><u></u></span></p><p class="MsoNormal"><span style="font-size:11pt"><u></u> <u></u></span></p><div><div style="border-right:none;border-bottom:none;border-left:none;border-top:1pt solid rgb(225,225,225);padding:3pt 0in 0in"><p class="MsoNormal"><b><span style="font-size:11pt;font-family:Calibri,sans-serif">From:</span></b><span style="font-size:11pt;font-family:Calibri,sans-serif"> NCSG-Discuss <<a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a>> <b>On Behalf Of </b>Kathy Kleiman<br><b>Sent:</b> Wednesday, May 15, 2024 8:40 AM<br><b>To:</b> <a href="mailto:NCSG-DISCUSS@LISTSERV.SYR.EDU" target="_blank">NCSG-DISCUSS@LISTSERV.SYR.EDU</a><br><b>Subject:</b> Re: CISA and Partners Release Guidance for Civil Society Organizations on Mitigating Cyber Threats with Limited Resources<u></u><u></u></span></p></div></div><p class="MsoNormal"><u></u> <u></u></p><p>Tx Julf.  Powerful what is being pointed out:<u></u><u></u></p><p><i>"Civil society, comprised of organizations and individuals—such as nonprofit, advocacy, cultural, faith-based, academic, think tanks, journalist, dissident, and diaspora organizations, communities involved in defending human rights and advancing democracy—are considered high-risk communities. Often these organizations and their employees are targeted by state-sponsored threat actors who seek to undermine democratic values and interests." </i><u></u><u></u></p><p>In RDDS/WHOIS, Proxy/Privacy, and intellectual property/UDRP/URS discussions, we have shared the same idea over many years of policy work. Our communities and groups need to be protected, not exposed, by ICANN policies.<u></u><u></u></p><p>Best, Kathy   <u></u><u></u></p><div><p class="MsoNormal">On 5/15/2024 8:26 AM, Johan Helsingius wrote:<u></u><u></u></p></div><blockquote style="margin-top:5pt;margin-bottom:5pt"><p class="MsoNormal">This might be of interest to some of our members. <br><br>    Julf <br><br><a href="https://www.cisa.gov/news-events/alerts/2024/05/14/cisa-and-partners-release-guidance-civil-society-organizations-mitigating-cyber-threats-limited" target="_blank">https://www.cisa.gov/news-events/alerts/2024/05/14/cisa-and-partners-release-guidance-civil-society-organizations-mitigating-cyber-threats-limited</a> <u></u><u></u></p></blockquote><pre>-- <u></u><u></u></pre><pre>Kathy Kleiman<u></u><u></u></pre><pre>Past President, Domain Name Rights Coalition<u></u><u></u></pre></div></div></div></blockquote></div>