Blueprint: Build the Best in Cyber Defense
SANS Institute
0
Blueprint: Build the Best in Cyber Defense is a podcast for cyber defenders seeking to stay current with the latest tools, technologies, and security concepts. Hosted by John Hubbard and brought to you by the SANS Institute, it features interviews with top security practitioners and in-depth explanations of new technologies, protocols, and defensive tools. The show aims to help listeners take their defense skills to the next level.
Episoder
-
Building Trust Into Agentic SOC Tools with Oren Saban 02.07.2026 44minSANS Cloud Security Exchange Summit 2026 - Aug. 17-18, San Francisco: https://www.sans.org/mlp/cloud-security-exchange-2026 Save $50 off registration with special promo code "Cloud_Promo50"! Agentic SOC platforms are no longer a future pitch — they're shipping, and teams are using them to triage and investigate cases end to end. But speed and automation only matter if you can trust the output. John sits down with Oren Saban to unpack what it actually takes to build a trustworthy agentic SOC ... -
Preventing Silent Failures with Nir Loya Dahan 18.06.2026 55minThis episode is sponsored by Fig. This episode features a conversation with Nir Loya Dahan, Co-Founder and CPO at Fig, recorded at RSAC 2026. Our discussion covers telemetry health and SOC infrastructure resilience: what breaks in a log pipeline, why silent failures are so hard to catch, and how detection teams can build more confidence in their data foundation. Resources: Nir's Email: nir@fig.security Fig Website: https://www.fig.security Contact, Courses, and More: For feedback, reviews, gu... -
The 2 AM Call: A Ransomware Negotiator's Playbook with Wade Gettle 09.02.2026 48minWhat happens after you discover ransomware? You have to talk to the attackers. And that conversation can make or break your entire response. In this episode, Wade Gettle, a professional ransomware negotiator, pulls back the curtain on the high-stakes world of threat actor negotiations. Wade is the person who gets the call at 2 AM when organizations are facing their worst moment, and he's handled negotiations across every scenario imaginable. You'll learn: What actually happens in the first 72... -
Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam 05.01.2026 1t 36minThis episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak Stufflebeam shares a detailed case study involving a major investigation of multiple counterfeit IT employees within a company. The episode provides valuable insights and actionable detection tactics, covering everything from unusual VPN activity and AI-gen... -
Leading by Example: Confidence and Responsibility in Cybersecurity with Zak Stufflebeam 19.08.2025 1t 6minIn this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principles learned along the way. From his early days in basic training to leading complex cybersecurity teams, Zak’s story is one of perseverance, adaptability, and unwavering commitment. He delves into vital leadership lessons, the importance of confidence, and str... -
From the SANS Cyber Leaders Podcast: Fighting Back with John Hubbard 27.06.2025 52minThis podcast episode is from the SANS Cyber Leaders Podcast. The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on the ever-changing threat landscape and how SOC teams can stay ahead. John shares his expertise on spotting threats early, how to test your defences before the real attackers show up, and why he’s on a mission to simplify cybersecurity operations for the next generation of defenders. Contact, Courses, and More: For feedback, re... -
Redefining Security Operations: Lessons in AI Integration with James Spiteri 12.06.2025 1t 6minIn this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and automation, are reshaping the SOC landscape. Discover how AI enhances SOC efficiency, reduces mundane tasks, and integrates context-aware capabilities. Learn about the real-world applications, from automation in cybersecurity operations to the challenges and pro... -
From Special Forces to Cybersecurity: Rich Greene on Communication and Persuasion in Infosec 09.04.2025 47minIn this episode, we sit down with Rich Greene, a former United States Army Special Forces Green Beret and current SANS instructor for SEC275 and SEC301. Rich shares his incredible journey spanning 20 years in the Army, including his transition from military communication roles into the realm of cybersecurity. He talks about the importance of fundamentals in cybersecurity, the power of effective communication and persuasion, and dispels common misconceptions about entering the cyber field. Ric... -
SOC Dashboards Done Right with Ryan Thompson 18.02.2025 1t 3minIn this episode, we sit down with Ryan Thompson, a seasoned expert in building dashboards that actually detect real threats—not just look pretty. With experience at Elastic, Alert Logic, and top EDR vendors, Ryan shares deep insights into the science behind effective dashboards and how security teams can cut through the noise to find the threats on your network. We cover: Why most SOC dashboards fail to deliver real insights—and how to fix them.The right way to structure dashboards for SIEM, ... -
Success Simplified - The 3 Step Process for Hitting Your Career Goals in 2025 with John Hubbard 01.01.2025 29minSurprise!! It's a mini solo episode to kick off the new year and it's on one of the most important topics there is - how to achieve your goals in 2025 and beyond! In this episode I talk about a topic I've never covered anywhere before - my personal system for productivity and how it helps me, and can likely you help you stay on track for those 2025 goals and stay aligned with what is most important in your life. Check this episode out for some useful productivity tips, inspiration, re... -
How Phishing Resistant Credentials Work with Mark Morowczynski and Tarek Dawoud 02.12.2024 54minMark Morowczynski returns for his 4th(!) time with his Microsoft coworker and identity and authentication expert Tarek Dawoud in this incredibly insightful conversation on the what, why, and how of phishing resistant credentials that YOU can implement right now! This conversation covers: What makes MFA phishable?What phishing resistant credentials are and how they workThe history and modern methods for phishing resistant credentialsWhat attacks will be used once we move to phishi... -
How GenAI is Changing Your SOC for the Better with Seth Misenar 09.10.2024 1t 35minIn this mega-discussion with Seth Misenar on GenAI and LLM usage for security operations we cover some very interesting questions such as: - The importance of natural language processing in Sec Ops - How AI is helping us detect phishing email - Where and how AI is lowering the bar for entry-level security SOC roles - Should we worry about AI hallucinations or AI taking our jobs? - What is a reasoning model and how is it different than what we've seen so far? - The future of AI - Multimo... -
From Clues to Containment - Unraveling A Gift Card Fraud Scheme with Mark Jeanmougin 09.10.2024 36minIn this episode, we take you behind the scenes of a complex gift card fraud investigation. Join host John Hubbard and guest Mark Jeanmougin as they explore the intricate details of uncovering and combating a clever case of cyber fraud. In this episode Mark discusses how the incident was identified, investigated, contained, and what lessons were learned along the way. Episode Links: - Mark's LinkedIn Profile: https://www.linkedin.com/in/markjx/ - Mark's Teaching Schedule: https://www.sans.org/... -
Bonus Episode: What does it take to author a cybersecurity book? 03.08.2023 1t 31minHave you ever wondered what it takes to write and publish an information security book? In this special bonus episode following season 4, John discusses with Kathryn, Ingrid, and Carson the challenges and rewards of self-publishing, and the kind of effort that goes into producing a book like "11 Strategies of a World-Class Cybersecurity Operations Center". This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations ... -
Strategy 11: Turn up the Volume by Expanding SOC Functionality 18.07.2023 1t 26min"This final chapter of the book is no simple closer! "Turn Up the Volume by Expanding SOC Functionality" covers testing that your SOC is functioning as intended through activities such as Threat Hunting, Red and Purple Teaming, Adversary Emulation, Breach and Attack Simulation, tabletop exercises and more. There's even a discussion of cyber deception types and tactics, and how it can be used to further frustrate attackers. Join John, Kathryn, Ingrid, and Carson in this final chapter episode f... -
Strategy 10: Measure Performance to Improve Performance 10.07.2023 52min"Metrics, is there any more confusing and contentious topic in cybersecurity? In this episode the authors cover their advice and approach to measuring your team so that issues can be quickly identified and performance can continuously improve! This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of the book with the book’s authors Kathryn Knerler, Ingrid Par... -
Strategy 9: Communicate Clearly, Collaborate Often, Share Generously 05.07.2023 1t 3min"Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with the constituency, and with the greater cybersecurity community. SANS Cyber Defense Discord Invite - sansurl.com/cyber-defense-discord This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber S... -
Strategy 8: Leverage Tools and Support Analyst Workflow 26.06.2023 1t 25minTool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Answers to these questions and more are in this week's episode of Blueprint! This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a ch... -
Blueprint Live at the SANS Blue Team Summit 2023 22.06.2023 1t 4minIn this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From discussing the most effective strategies for building a successful SOC to sharing tips on how to stay ahead of emerging cyber threats, our guests provide invaluable advice for those who work in a security operations center (SOC). If you're looking to take y... -
Strategy 7: Select and Collect the Right Data 19.06.2023 1t 3minThere's no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sources? That's the topic of this episode. Join Kathryn, Ingrid, Carson, and John in this episode for a discussion on tactical data collection that will ensure your team doesn't miss the signs of an impending incident! This special season of the Blueprint Podc...
Populær i
Denne podcast optræder også i podcast-hitlister i disse lande.