Welcome to the Blueprint Podcast!

Episodes

Bonus Episode: What does it take to author a cybersecurity book?
12
Aug. 3, 2023

Bonus Episode: What does it take to author a cybersecurity book?

Click here to send us your ideas and feedback on Blueprint! Have you ever wondered what it takes to write and publish an information security book? In this special bonus episode following season 4, John discusses with Kathryn, Ingrid, and Carson the challenges and rewards of self-publishing, and the kind of effort that goes into producing a book like "11 Strategies of a World-Class Cybersecurity Operations Center". This special season of the Blueprint Podcast is taking a deep dive into MITRE...
Strategy 11: Turn up the Volume by Expanding SOC Functionality
11
July 18, 2023

Strategy 11: Turn up the Volume by Expanding SOC Functionality

Click here to send us your ideas and feedback on Blueprint! "This final chapter of the book is no simple closer! "Turn Up the Volume by Expanding SOC Functionality" covers testing that your SOC is functioning as intended through activities such as Threat Hunting, Red and Purple Teaming, Adversary Emulation, Breach and Attack Simulation, tabletop exercises and more. There's even a discussion of cyber deception types and tactics, and how it can be used to further frustrate attackers. Join John,...
Strategy 10: Measure Performance to Improve Performance
10
July 10, 2023

Strategy 10: Measure Performance to Improve Performance

Click here to send us your ideas and feedback on Blueprint! "Metrics, is there any more confusing and contentious topic in cybersecurity? In this episode the authors cover their advice and approach to measuring your team so that issues can be quickly identified and performance can continuously improve! This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operations Center. Each episode John will break down a chapter of ...
Strategy 9: Communicate Clearly, Collaborate Often, Share Generously
9
July 5, 2023

Strategy 9: Communicate Clearly, Collaborate Often, Share Generously

Click here to send us your ideas and feedback on Blueprint! "Research has shown that communication is one of the most important factors for success in security incident response teams. In this chapter, the authors discuss the critical types of information that must be shared within the SOC, with the constituency, and with the greater cybersecurity community. SANS Cyber Defense Discord Invite - sansurl.com/cyber-defense-discord This special season of the Blueprint Podcast is taking a d...
Strategy 8: Leverage Tools and Support Analyst Workflow
8
June 26, 2023

Strategy 8: Leverage Tools and Support Analyst Workflow

Click here to send us your ideas and feedback on Blueprint! Tool choice can be a make-or-break decision for security analysts, driving whether getting work done is a struggle, or an efficient, stress-free experience. How can we select the right tools for the job? Which tools are most important? Answers to these questions and more are in this week's episode of Blueprint! This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Securi...
Blueprint Live at the SANS Blue Team Summit 2023
June 22, 2023

Blueprint Live at the SANS Blue Team Summit 2023

Click here to send us your ideas and feedback on Blueprint! In this special live recording from the SANS Blue Team Summit 2023, Kathryn Knerler, Ingrid Parker, and Carson Zimmerman joined John Hubbard they share their insights and expertise with attendees by answering their pressing questions. From discussing the most effective strategies for building a successful SOC to sharing tips on how to stay ahead of emerging cyber threats, our guests provide invaluable advice for those who work in a s...
Strategy 7: Select and Collect the Right Data
7
June 19, 2023

Strategy 7: Select and Collect the Right Data

Click here to send us your ideas and feedback on Blueprint! There's no denying that the average security team is completely overwhelmed with options for data to collect. With a deluge of endpoint, network, and cloud data sources to collect, how to do we identify and collect the most useful data sources? That's the topic of this episode. Join Kathryn, Ingrid, Carson, and John in this episode for a discussion on tactical data collection that will ensure your team doesn't miss the signs of an im...
Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence
6
June 12, 2023

Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence

Click here to send us your ideas and feedback on Blueprint! Every security team has limited budget and time, how do you know where to focus? Cyber Threat Intelligence provides those answers! In this episode, Ingrid, Carson and Kathryn describe how we can use CTI to focus our defensive efforts to understand our most likely attacks and attackers and move towards prioritizing what truly matters. This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a W...
Strategy 5: Prioritize Incident Response
5
June 5, 2023

Strategy 5: Prioritize Incident Response

Click here to send us your ideas and feedback on Blueprint! No security team is perfect, so in this episode, authors Carson, Ingrid, and Kathryn discuss what it takes to prepare for fast, effective incident response capability. Covering preparation, planning and execution, Strategy 5 will teach your team how to jump into action at the earliest sign of problems. This special season of the Blueprint Podcast is taking a deep dive into MITRE’s 11 Strategies of a World-Class Cyber Security Operat...
Strategy 4: Hire AND Grow Quality Staff
4
May 29, 2023

Strategy 4: Hire AND Grow Quality Staff

Click here to send us your ideas and feedback on Blueprint! In this episode we dive deep on the "People" factor of the SOC. Who should you hire, what skills should you hire for, what backgrounds are most likely to lead to success for your team? We also get into what happens after the hire - training, growth, and supporting your team in their skill and career development. This one is a must-listen for all the managers out there. We're all trying to build the highest skilled, most supportive te...
Strategy 3: Build a SOC Structure to Match Your Organizational Needs
3
May 22, 2023

Strategy 3: Build a SOC Structure to Match Your Organizational Needs

Click here to send us your ideas and feedback on Blueprint! In this episode we discuss how to decide on the right org structure and capabilities of your SOC. This includes questions like tiered vs. tierless models, which capabilities the SOC should focus on, centralized vs. distributed SOCs, outsourcing of duties and staff augmentation considerations, and also where the SOC might sit in the larger chart of your organization. Every SOC needs to be tailored to best meet the mission, and chapter...
Strategy 2: Give the SOC the Authority to Do Its Job
2
May 15, 2023

Strategy 2: Give the SOC the Authority to Do Its Job

Click here to send us your ideas and feedback on Blueprint! Though a SOC is responsible for protecting your organization's assets, it is not the owner of those systems. If the SOC is not established with a clear charter and authority to act, it may quickly become difficult to be effective. Who should the SOC report to, what should be in a SOC charter, and how can we make these tough decisions? Those are the questions covered in this episode of our special "11 Strategies" season. This episode ...
Strategy 1: Know What You Are Protecting and Why
1
May 8, 2023

Strategy 1: Know What You Are Protecting and Why

Click here to send us your ideas and feedback on Blueprint! As the saying goes, "If you don't know where you're going, any road will take you there!" - an approach that is disastrous to a SOC. In order to succeed, the SOC must have a clear understanding of where they are going, how they're going to get there, and why. In this episode of our "11 Strategies" season we discuss chapter 1 of the book - "Know What You're Protecting and Why". Understanding your organization and the environment the S...
11 Strategies of a World-Class Security Operations Center: Fundamentals
May 8, 2023

11 Strategies of a World-Class Security Operations Center: Fundamentals

Click here to send us your ideas and feedback on Blueprint! Welcome to a brand new season of Blueprint! In this intro episode we discuss "Fundamentals" chapter of the "11 Strategies of a World Class Cybersecurity Operations Center" with the authors. We get into the motivation behind updating the book and why its lessons are more important than ever in 2023. This chapter includes discussion of the functions of a SOC, basics of workflow, CTI and contextual data sources, and why ops tempo and sp...
Get Ready, A Very Special Season 4 Is On the Way!
May 1, 2023

Get Ready, A Very Special Season 4 Is On the Way!

Click here to send us your ideas and feedback on Blueprint! Hello Blueprint listeners! We’re excited to announce that the release of season 4 of Blueprint is just around the corner, and we’ve got something very special cooked up for you. We’ve teamed up with the authors of MITRE’s “11 Strategies of a World-Class Cybersecurity Operations Center” and over the next few months, we’ll be releasing episodes walking through each chapter with all 3 authors! We’ll be deep diving into what makes a SOC ...
Send a Voicemail