Welcome to the Blueprint Podcast!

Episodes

Jan. 5, 2026

Infiltration Alert! How to Catch Fake IT Employees in Your Network wi…

Click here to send us your ideas and feedback on Blueprint! This episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak…

Listen to the Episode
Aug. 19, 2025

Leading by Example: Confidence and Responsibility in Cybersecurity wi…

Click here to send us your ideas and feedback on Blueprint! In this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principle…

Listen to the Episode
June 27, 2025

From the SANS Cyber Leaders Podcast: Fighting Back with John Hubbard

Click here to send us your ideas and feedback on Blueprint! This podcast episode is from the SANS Cyber Leaders Podcast. The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on the ever-changing threat landscape and how SOC teams can stay ahead. J…

Listen to the Episode
June 12, 2025

Redefining Security Operations: Lessons in AI Integration with James …

Click here to send us your ideas and feedback on Blueprint! In this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and auto…

Listen to the Episode
April 9, 2025

From Special Forces to Cybersecurity: Rich Greene on Communication an…

Click here to send us your ideas and feedback on Blueprint! In this episode, we sit down with Rich Greene, a former United States Army Special Forces Green Beret and current SANS instructor for SEC275 and SEC301. Rich shares his incredible journey spanning 20 years in the Army, including his transi…

Listen to the Episode
Feb. 18, 2025

SOC Dashboards Done Right with Ryan Thompson

Click here to send us your ideas and feedback on Blueprint! In this episode, we sit down with Ryan Thompson, a seasoned expert in building dashboards that actually detect real threats—not just look pretty. With experience at Elastic, Alert Logic, and top EDR vendors, Ryan shares deep insights into …

Listen to the Episode
Jan. 1, 2025

Success Simplified - The 3 Step Process for Hitting Your Career Goals…

Click here to send us your ideas and feedback on Blueprint! Surprise!! It's a mini solo episode to kick off the new year and it's on one of the most important topics there is - how to achieve your goals in 2025 and beyond! In this episode I talk about a topic I've never covered anywhere before - my…

Listen to the Episode
Dec. 1, 2024

How Phishing Resistant Credentials Work with Mark Morowczynski and Ta…

Click here to send us your ideas and feedback on Blueprint! Mark Morowczynski returns for his 4th(!) time with his Microsoft coworker and identity and authentication expert Tarek Dawoud in this incredibly insightful conversation on the what, why, and how of phishing resistant credentials that YOU c…

Listen to the Episode
Oct. 9, 2024

From Clues to Containment - Unraveling A Gift Card Fraud Scheme with …

Click here to send us your ideas and feedback on Blueprint! In this episode, we take you behind the scenes of a complex gift card fraud investigation. Join host John Hubbard and guest Mark Jeanmougin as they explore the intricate details of uncovering and combating a clever case of cyber fraud. In …

Listen to the Episode
Oct. 9, 2024

How GenAI is Changing Your SOC for the Better with Seth Misenar

Click here to send us your ideas and feedback on Blueprint! In this mega-discussion with Seth Misenar on GenAI and LLM usage for security operations we cover some very interesting questions such as: - The importance of natural language processing in Sec Ops - How AI is helping us detect phishing em…

Listen to the Episode
Aug. 3, 2023

Bonus Episode: What does it take to author a cybersecurity book?

Click here to send us your ideas and feedback on Blueprint! Have you ever wondered what it takes to write and publish an information security book? In this special bonus episode following season 4, John discusses with Kathryn, Ingrid, and Carson the challenges and rewards of self-publishing, and th…

Listen to the Episode
July 18, 2023

Strategy 11: Turn up the Volume by Expanding SOC Functionality

Click here to send us your ideas and feedback on Blueprint! "This final chapter of the book is no simple closer! "Turn Up the Volume by Expanding SOC Functionality" covers testing that your SOC is functioning as intended through activities such as Threat Hunting, Red and Purple Teaming, Adversary E…

Listen to the Episode
July 10, 2023

Strategy 10: Measure Performance to Improve Performance

Click here to send us your ideas and feedback on Blueprint! "Metrics, is there any more confusing and contentious topic in cybersecurity? In this episode the authors cover their advice and approach to measuring your team so that issues can be quickly identified and performance can continuously impr…

Listen to the Episode
July 5, 2023

Strategy 9: Communicate Clearly, Collaborate Often, Share Generously

Click here to send us your ideas and feedback on Blueprint! "Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with th…

Listen to the Episode
June 26, 2023

Strategy 8: Leverage Tools and Support Analyst Workflow

Click here to send us your ideas and feedback on Blueprint! Tool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Ans…

Listen to the Episode
June 22, 2023

Blueprint Live at the SANS Blue Team Summit 2023

Click here to send us your ideas and feedback on Blueprint! In this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From…

Listen to the Episode
June 19, 2023

Strategy 7: Select and Collect the Right Data

Click here to send us your ideas and feedback on Blueprint! There's no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sou…

Listen to the Episode
June 12, 2023

Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence

Click here to send us your ideas and feedback on Blueprint! Every security team has limited budget and time, how do you know where to focus? Cyber Threat Intelligence provides those answers! In this episode, Ingrid, Carson and Kathryn describe how we can use CTI to focus our defensive efforts to un…

Listen to the Episode
June 5, 2023

Strategy 5: Prioritize Incident Response

Click here to send us your ideas and feedback on Blueprint! No security team is perfect, so in this episode, authors Carson, Ingrid, and Kathryn discuss what it takes to prepare for fast, effective incident response capability. Covering preparation, planning and execution, Strategy 5 will teach you…

Listen to the Episode
May 29, 2023

Strategy 4: Hire AND Grow Quality Staff

Click here to send us your ideas and feedback on Blueprint! In this episode we dive deep on the "People" factor of the SOC. Who should you hire, what skills should you hire for, what backgrounds are most likely to lead to success for your team? We also get into what happens after the hire - trainin…

Listen to the Episode
May 22, 2023

Strategy 3: Build a SOC Structure to Match Your Organizational Needs

Click here to send us your ideas and feedback on Blueprint! In this episode we discuss how to decide on the right org structure and capabilities of your SOC. This includes questions like tiered vs. tierless models, which capabilities the SOC should focus on, centralized vs. distributed SOCs, outsou…

Listen to the Episode
May 15, 2023

Strategy 2: Give the SOC the Authority to Do Its Job

Click here to send us your ideas and feedback on Blueprint! Though a SOC is responsible for protecting your organization's assets, it is not the owner of those systems. If the SOC is not established with a clear charter and authority to act, it may quickly become difficult to be effective. Who shou…

Listen to the Episode
May 8, 2023

Strategy 1: Know What You Are Protecting and Why

Click here to send us your ideas and feedback on Blueprint! As the saying goes, "If you don't know where you're going, any road will take you there!" - an approach that is disastrous to a SOC. In order to succeed, the SOC must have a clear understanding of where they are going, how they're going to…

Listen to the Episode
May 8, 2023

11 Strategies of a World-Class Security Operations Center: Fundamenta…

Click here to send us your ideas and feedback on Blueprint! Welcome to a brand new season of Blueprint! In this intro episode we discuss "Fundamentals" chapter of the "11 Strategies of a World Class Cybersecurity Operations Center" with the authors. We get into the motivation behind updating the bo…

Listen to the Episode