Welcome to the Blueprint Podcast!
Blueprint: Build the Best in Cyber Defense
Blueprint: Build the Best in Cyber Defense
Real conversations with the people building and running security operations. Practical insights from practitioners defending actual networks, not surface-level trends. Blueprint brings you in-depth discussions on detection engineering, SOC operations, incident response, and the tools and techniques that matter. Hosted by John Hubbard, SANS Cyber Defense Curriculum Lead, and brought to you by the SANS Institute.
Choose your favorite podcast player
Blueprint: Build the Best in Cyber Defense

Blueprint: The Podcast for Cybersecurity Operations Practitioners and Leaders

Real conversations with the people building and running security operations. Practical insights from practitioners defending actual networks, not surface-level trends.
Blueprint brings you in-depth discussions on detection engineering, SOC operations, incident response, and the tools and techniques that matter. Hosted by John Hubbard, SANS Cyber Defense Curriculum Lead, and brought to you by the SANS Institute.

About the Host

John Hubbard Profile Photo
John Hubbard

SANS Cyber Defense Curriculum Lead | Sr. Instructor

John Hubbard teaches people how to defend networks and leads curriculum strategy at SANS Institute, where he authors and manages multiple cybersecurity courses including SEC450 (SOC Analyst Training - Applied Skills for Cyber Defense Operations) and LDR551 (Building and Leading Security Operations Centers).
With a background in computer engineering and years of hands-on security work, John brings a systems-thinking approach to security, teaching, and podcasting. He's obsessed with translating complex security concepts into frameworks that actually make sense—whether that's improving security operations through security metrics, threat modeling, security data engineering, or leading a world-class cybersecurity team.
Blueprint cuts through the noise to explore what actually matters in cybersecurity: the people, processes, and decisions that make or break security programs. Real conversations with practitioners who've been in the trenches.

Recent Episodes

12
July 2, 2026

Building Trust Into Agentic SOC Tools with Oren Saban

Agentic SOC platforms are no longer a future pitch — they're shipping, and teams are using them to triage and investigate cases end to end. But speed and automation only matter if you can trust the output. John sits down with Oren Saban to unpack what it actually takes to build a trustworthy agentic SOC tool. They cover why these platforms are built as swarms of specialized agents rather than one generalist model, the role organizational context and data quality play in getting good results, ...
11
June 18, 2026

Preventing Silent Failures with Nir Loya Dahan

This episode is sponsored by Fig. This episode features a conversation with Nir Loya Dahan, Co-Founder and CPO at Fig, recorded at RSAC 2026. Our discussion covers telemetry health and SOC infrastructure resilience: what breaks in a log pipeline, why silent failures are so hard to catch, and how detection teams can build more confidence in their data foundation. Resources: Nir's Email: nir@fig.security Fig Website: https://www.fig.security Contact, Courses, and More: For feedback, reviews, gu...
10
Feb. 9, 2026

The 2 AM Call: A Ransomware Negotiator's Playbook with Wade Gettle

What happens after you discover ransomware? You have to talk to the attackers. And that conversation can make or break your entire response. In this episode, Wade Gettle, a professional ransomware negotiator, pulls back the curtain on the high-stakes world of threat actor negotiations. Wade is the person who gets the call at 2 AM when organizations are facing their worst moment, and he's handled negotiations across every scenario imaginable. You'll learn: What actually happens in the first 72 h
9
Jan. 5, 2026

Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam

Click here to send us your ideas and feedback on Blueprint! This episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak Stufflebeam shares a detailed case study involving a major investigation of multiple counterfeit IT employees within a company. The episode provides valuable insights and actionable detection tacti...
8
Aug. 19, 2025

Leading by Example: Confidence and Responsibility in Cybersecurity with Zak Stufflebeam

Click here to send us your ideas and feedback on Blueprint! In this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principles learned along the way. From his early days in basic training to leading complex cybersecurity teams, Zak’s story is one of perseverance, adaptability, and unwavering commitment. He delves into vit...
June 27, 2025

From the SANS Cyber Leaders Podcast: Fighting Back with John Hubbard

Click here to send us your ideas and feedback on Blueprint! This podcast episode is from the SANS Cyber Leaders Podcast. The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on the ever-changing threat landscape and how SOC teams can stay ahead. John shares his expertise on spotting threats early, how to test your defences before the real attackers show up, and why he’s on a mission to simplify cybersecurity operations for the next generatio...
Send a Voicemail