- 222
- 20 027
Blue Security Podcast
United States
เข้าร่วมเมื่อ 24 ม.ค. 2021
A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.
Blue Security Podcast - 2024-11-26 - Cybersecurity Maturity Model Cert. (CMMC), guest Justin Orcutt
Summary
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer welcome Justin Orcutt from Microsoft to discuss the Cybersecurity Maturity Model Certification (CMMC). The conversation covers the history and requirements of CMMC, the steps companies need to take to prepare for audits, and the importance of continuous monitoring. Justin shares insights on the anxiety surrounding CMMC compliance, the tools available for tracking progress, and the broader implications of CMMC for various industries beyond defense contracting. He emphasizes the need for organizations to understand their data security requirements and engage with communities for support.
----------------------------------------------------
Audio Podcast Link: creators.spotify.com/pod/show/blue-security-podcast/episodes/CMMC-with-Special-Guest-Justin-Orcutt-e2qrhrb
----------------------------------------------------
Documentation:
www.defense.gov/News/Releases/Release/Article/3932947/cybersecurity-maturity-model-certification-program-final-rule-published/
Justin Orcutt: www.linkedin.com/in/justinorcutt/
----------------------------------------------------
Contact Us:
Website: bluesecuritypod.com
Bluesky: bsky.app/profile/bluesecuritypod.com
LinkedIn: www.linkedin.com/company/bluesecpod
TH-cam: th-cam.com/users/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: bsky.app/profile/ajawzero.com
LinkedIn: www.linkedin.com/in/andyjaw/
Email: andy@bluesecuritypod.com
----------------------------------------------------
Adam Brewer
Twitter: ajbrewer
LinkedIn: www.linkedin.com/in/adamjbrewer/
Email: adam@bluesecuritypod.com
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer welcome Justin Orcutt from Microsoft to discuss the Cybersecurity Maturity Model Certification (CMMC). The conversation covers the history and requirements of CMMC, the steps companies need to take to prepare for audits, and the importance of continuous monitoring. Justin shares insights on the anxiety surrounding CMMC compliance, the tools available for tracking progress, and the broader implications of CMMC for various industries beyond defense contracting. He emphasizes the need for organizations to understand their data security requirements and engage with communities for support.
----------------------------------------------------
Audio Podcast Link: creators.spotify.com/pod/show/blue-security-podcast/episodes/CMMC-with-Special-Guest-Justin-Orcutt-e2qrhrb
----------------------------------------------------
Documentation:
www.defense.gov/News/Releases/Release/Article/3932947/cybersecurity-maturity-model-certification-program-final-rule-published/
Justin Orcutt: www.linkedin.com/in/justinorcutt/
----------------------------------------------------
Contact Us:
Website: bluesecuritypod.com
Bluesky: bsky.app/profile/bluesecuritypod.com
LinkedIn: www.linkedin.com/company/bluesecpod
TH-cam: th-cam.com/users/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: bsky.app/profile/ajawzero.com
LinkedIn: www.linkedin.com/in/andyjaw/
Email: andy@bluesecuritypod.com
----------------------------------------------------
Adam Brewer
Twitter: ajbrewer
LinkedIn: www.linkedin.com/in/adamjbrewer/
Email: adam@bluesecuritypod.com
มุมมอง: 18
วีดีโอ
Blue Security Podcast - 2024-11-19 - T-Mobile Breach, Sophos Hacks Back, Bluesky Surges
มุมมอง 51วันที่ผ่านมา
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the recent T-Mobile breach attributed to Chinese state-sponsored hackers, emphasizing the importance of parsing corporate statements. They delve into the implications of cybersecurity threats, referencing a Sophos report detailing a five-year cat-and-mouse game with Chinese attackers. The conversation s...
Blue Security Podcast - 2024-11-12 - Securing Contingent Workers
มุมมอง 5414 วันที่ผ่านมา
Summary In this episode, Andy and Adam discuss the challenges and strategies for securing seasonal and contingent workers using a Zero Trust approach. They emphasize the importance of managed devices, the complexities of hybrid domain joins, and explore alternative solutions such as cloud-based services. The conversation also touches on the significance of security policies and the need for exc...
Blue Security Podcast - 2024-11-05 - Offboarding Users
มุมมอง 4121 วันที่ผ่านมา
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss the critical steps involved in offboarding employees, particularly focusing on Microsoft 365 environments. They cover essential practices such as blocking user sign-ins, managing mailbox contents, device management, and ensuring data protection. The conversation emphasizes the importance of modernizing device m...
Blue Security Podcast - 2024-10-29 - AD Security Guide, MDE Safe Deployment, macOS Entra SSO
มุมมอง 69หลายเดือนก่อน
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer discuss critical cybersecurity insights, focusing on Active Directory security techniques, the implications of recent incidents involving Microsoft Defender for Endpoint, and the introduction of passwordless solutions for Apple devices. They emphasize the importance of foundational knowledge in cybersecurity, t...
Blue Security Podcast - 2024-10-22 - Microsoft Digital Defense Report '24
มุมมอง 93หลายเดือนก่อน
Summary In this episode, Andy and Adam discuss Microsoft's 2024 Digital Defense Report, which highlights the evolving cyber threat landscape, the rise of ransomware, identity attacks, and DDoS attacks. They emphasize the importance of centering organizations around security, the shift towards passwordless authentication, and the impact of AI on cybersecurity. The conversation provides actionabl...
Blue Security Podcast - 2024-10-15 - Microsoft Secure Future Initiative Update
มุมมอง 90หลายเดือนก่อน
Summary In this episode, Andy Jaw and Adam Brewer discuss Microsoft's Secure Future Initiative (SFI), which emphasizes security by design, default, and operations. They explore the initiative's six key security pillars, the impact of recent cyber incidents, and the ongoing progress in enhancing security measures across Microsoft. The conversation highlights the importance of employee accountabi...
Blue Security Podcast - 2024-10-08 - Let's Talk About Passwords!
มุมมอง 114หลายเดือนก่อน
Summary In this episode of the BlueScarity Podcast, hosts Andy Jaw and Adam Brewer discuss the evolution of password guidelines, focusing on the recent updates from NIST and Microsoft. They explore the implications of these changes, emphasizing the importance of understanding human behavior in password security and the need for organizations to adopt passwordless solutions. The conversation hig...
Blue Security Podcast - 2024-10-01 - Protect Against Token Theft
มุมมอง 1132 หลายเดือนก่อน
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into the critical topic of token theft in identity management. They discuss the importance of multi-factor authentication (MFA) as a primary defense against identity attacks, the nature of tokens, and how attackers exploit vulnerabilities to steal these tokens. The conversation highlights the introduction of toke...
Blue Security Podcast - 2024-09-24 - BSP Turns 4, WSUS Deprecated, macOS Firewall Woes
มุมมอง 762 หลายเดือนก่อน
Summary In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer celebrate four years of podcasting, reflecting on their journey and the importance of providing actionable insights to their audience. They discuss the significance of education in technology, particularly in relation to Microsoft products and the recent deprecation of WSUS. The conversation also covers the imp...
Blue Security Podcast - 2024-09-17 - Cloud Security: Containers 101 & Defender for Containers
มุมมอง 582 หลายเดือนก่อน
In this episode of the Blue Security Podcast, hosts Andy Jaw and Adam Brewer delve into the world of containers, exploring their functionality, differences from virtual machines, and the importance of securing them. They discuss key tools like Docker and Kubernetes, and introduce Microsoft's Defender for Containers as a solution for managing security in containerized environments. The conversat...
Blue Security Podcast - 2024-09-10 - IBM Cost of a Data Breach Report
มุมมอง 592 หลายเดือนก่อน
Summary In this episode, Andy and Adam discuss the key findings from IBM's report on the costs of a data breach in 2024. They cover topics such as the increase in the cost of data breaches, the use of security AI and automation, the cyber skills shortage, the challenges of shadow data, and the importance of insider risk management. They also highlight the need for password protection, fish-resi...
Blue Security Podcast - 2024-09-03 - Entra Suite Overview
มุมมอง 652 หลายเดือนก่อน
Summary In this episode of the Blue Security Podcast, Andy and Adam discuss Entra Suite, a new package from Microsoft that includes various Entra products and solutions. They provide an overview of each component, including Entra Private Access, Entra Internet Access, Entra ID Governance, Entra ID Protection, and Entra Verified ID. They highlight the benefits and use cases of each component and...
Blue Security Podcast - 2024-08-27 - Where Do You Find Training?
มุมมอง 653 หลายเดือนก่อน
In this episode, Andy and Adam discuss various resources and methods for getting training and learning about Microsoft and other technology solutions. They cover topics such as official documentation, certification tracks, Ninja training, Microsoft Mechanics, the Tech Community, customer connection programs, building a personal lab, and the importance of having a supportive network. Takeaways -...
Blue Security Podcast - 2024-08-20 - Trump Campaign + NPD Hacked, Microsoft Admin MFA
มุมมอง 553 หลายเดือนก่อน
In this episode of the Blue Security Podcast, Andy and Adam discuss several cybersecurity news stories. They cover the hack of the Trump campaign's emails by Iranian hackers, the breach of the National Public Data records, and Microsoft's new requirement for admins to enable multi-factor authentication (MFA). They also touch on the importance of data privacy and the need for companies to be res...
Blue Security Podcast - 2024-08-13 - Defender for Storage
มุมมอง 493 หลายเดือนก่อน
Blue Security Podcast - 2024-08-13 - Defender for Storage
Blue Security Podcast - 2024-08-06 - Windows Autopilot and Microsoft Intune updates
มุมมอง 2723 หลายเดือนก่อน
Blue Security Podcast - 2024-08-06 - Windows Autopilot and Microsoft Intune updates
Blue Security Podcast - 2024-07-30 - Cloud Security Posture Management
มุมมอง 554 หลายเดือนก่อน
Blue Security Podcast - 2024-07-30 - Cloud Security Posture Management
Blue Security Podcast - 2024-07-22 - CrowdStrike Major Incident
มุมมอง 1984 หลายเดือนก่อน
Blue Security Podcast - 2024-07-22 - CrowdStrike Major Incident
Blue Security Podcast - 2024-07-16 - Cybersecurity is Full?
มุมมอง 2914 หลายเดือนก่อน
Blue Security Podcast - 2024-07-16 - Cybersecurity is Full?
Blue Security Podcast - 2024-07-09 - Defender for Servers
มุมมอง 944 หลายเดือนก่อน
Blue Security Podcast - 2024-07-09 - Defender for Servers
Blue Security Podcast - 2024-07-02 - Exchange Online Protection Configuration
มุมมอง 874 หลายเดือนก่อน
Blue Security Podcast - 2024-07-02 - Exchange Online Protection Configuration
Blue Security Podcast - 2024-06-25 - Kaspersky Ban, and A Tale of Two Hacks
มุมมอง 2225 หลายเดือนก่อน
Blue Security Podcast - 2024-06-25 - Kaspersky Ban, and A Tale of Two Hacks
Blue Security Podcast - 2024-06-18 - Snowflake, Findlay Auto Ransomware, Olympics
มุมมอง 715 หลายเดือนก่อน
Blue Security Podcast - 2024-06-18 - Snowflake, Findlay Auto Ransomware, Olympics
Blue Security Podcast - 2024-06-11 - Microsoft Recall, Windows Hello Enhanced Sign-in Security
มุมมอง 945 หลายเดือนก่อน
Blue Security Podcast - 2024-06-11 - Microsoft Recall, Windows Hello Enhanced Sign-in Security
Blue Security Podcast - 2024-06-04 - Ticketmaster Breach, Slack AI, Microsoft Recall
มุมมอง 485 หลายเดือนก่อน
Blue Security Podcast - 2024-06-04 - Ticketmaster Breach, Slack AI, Microsoft Recall
Blue Security Podcast - 2024-05-28 - Microsoft Build 2024 recap
มุมมอง 356 หลายเดือนก่อน
Blue Security Podcast - 2024-05-28 - Microsoft Build 2024 recap
Blue Security Podcast - 2024-05-21 - Entra Private Access, Endpoint Privilege Management
มุมมอง 676 หลายเดือนก่อน
Blue Security Podcast - 2024-05-21 - Entra Private Access, Endpoint Privilege Management
Blue Security Podcast - 2024-05-14 - MSRC Transparency, USB Threats
มุมมอง 466 หลายเดือนก่อน
Blue Security Podcast - 2024-05-14 - MSRC Transparency, USB Threats
Blue Security Podcast - 2024-05-07 - 2024 Verizon Data Breach Report
มุมมอง 1406 หลายเดือนก่อน
Blue Security Podcast - 2024-05-07 - 2024 Verizon Data Breach Report
Hello TH-cam Star- I have watched all your videos. Your videos are very nice but there is some problem with your channel. Your channel is not optimized properly and your channel SEO score is very low due to which your channel is not getting good views. If you solve your channel problems, you will get many Subscriber views on your channel. Have a Good
Thanks guys!
Thanks guys!
Thanks guys, CAE for everything forever :)
Thanks as usual guys, I always look forward to Tuesdays :)
I have little understanding of the tech/IT world. This video was still helpful nevertheless.
Thank you guys! I use this product and it's really powerful. Our dev team has work cut out for them for months to come😅
You guys are the best, you are highly appreciated. Thank you!!
Indian Railways ran unaffected with daily passengers count 28M due to the fact that they use unix based system.
I think there is some truth to the idea that there is an oversaturation in the market. A great example was given to me when I recently interviewed for role for which I was well qualified. I have a number of bootcamp certificates from University of Michigan, CompTIA Security + (2024), CCNA (renewed 2023), Microsoft SC-200 (renewed in 2023 azure security), google IT professional certification, and a couple more vague certs, along with 3 years of experience in enterprise support and 2.5 years managing network infrastructure for a local small business (including hosting and building their website within security best practices). I always interview quite well, and bring my best in professional behavior and knowledge to the table. I was told that another candidate was filling the role, and informed by my recruiter that the reason they hired the other candidate was that he was "younger, more green, and cost less money" The pay scale was 56,000 - 62,000 which is relatively low though I wanted the position so that I could finally break into "security". I asked for 60,000 which only $1,000 per year more than I make in help desk. The other guy apparently was willing to work for 55k
Cyber is also taxing us on the body. Most people I work with are sedentary and alcoholics. There was this guy in /r/netsecstudents passing this site around. He posted his resume in another post with a bunch of consulting experience and still being employed. It was kind of fucked up
Been following the podcast on Spotify for a while now. But I have to write a comment here and praise it. By far the best technical podcast that always manages to give you something you can use in the real world. Many thanks for this and best regards from Germany!
Thank you for listening!
Only 4 likes... ok, I'm a bit late but 2 years later, I still find your video very usefull, thanks for your work guys.
i am just now seeing this and using this feature. great job guys. you helped my understanding alot.
Did you like it?
I agree! This is how companies are getting raided for trade secrets and cash. Then we wonder how the competition suddenly appeared.
As domain admins Need to use jumpbox? Or RSAT will do.? What you mean to have Server access but not DC access?
I WANT entra-joined only. But getting a fully functional workstation that is like-for-like seems a bit unsurmountable at this point. Had to build out on-prem Intune Certificate Connector for Global Protect VPN, and getting that to work was not easy. And there are many different ways to deploy VPN App (Win32/wintune format/UWP) and Configuration Profiles (poorly documented on Palo Alto's side and Microsoft side), which one to use and configure? And drive mappings (yeah, we still have folks using lots of department-specific drive mappings for the last 20 years, some of it very sensitive), and there are multiple solutions out there for that but nothing that reliable. Even setting workstation background is a complete redesign (used to use a file share, but now have to come up with Azure blob storage, and it's too complex for the Marketing layperson that used to just drop a couple picture files in a local file share). Co-Management with our MECM is difficult, as we don't allow on-prem admin accounts to replicate to Entra (security reasons), and thus have difficulty with setting up roles in Entra AND MECM at the same time, and (again, for security), and we haven't built out CMG. This is going to take sooo many iterations that it is daunting.
I’m commenting myself
Just found this one - amazing content !!!
Great video! I appreciate the deeper dive into the technical aspect of the technology. Definitely going to check out more of your podcasts. Liked & Subscribed!
Love this channel, thank you both!
great coverage 🙏 I believe Microsoft really has to step up their game, this is becoming a national security threat.
Very i formative and inspiring. Thank you, guys. Keep it up!
Corporatism is not Capitalism. They are diametrically opposed to each-other in more ways than not. People really need to relearn the difference between the two because the twist was intentionally introduced to protect corporate monopolies and power.
Great podcast. Wholistic view, which is rare to see in corporate IT.
I am waiting also for the Proton Pass features for the Free version.
Unlike Bitwarden, it looks like Proton Pass will have restricted functionality as a "free" OSS password manager. When this comes out of beta, they're planning to paywall several as yet to be announced premium features. And knowing how Proton operates, they're NOT GENEROUS w/ their free tier... ex, free Email accts limited to 500mb which is UNUSABLE, it's HIGHLY LIKELY Proton Pass will implement equally unusable artificial limits. Think along the lines of... "Free accts limited to 5 credentials"; or "Can only be simultaneously logged in on a single device at a time"; or "Device-to-Device sync disabled for free accts", rendering multi-device login moot; or some other equally inane limitation to force premium account subscription to the full Proton Acct suite. OTOH Bitwarden's core suite of functionality is avail to the free tier. IMO BW's only major "core" features withheld are "YubiKey HW key 2FA authentication for Bitwarden acct sign-in's not allowed", and "Built-in 2FA TOTP generator for sites stored in BW disabled". You can still use software & SMS based 2FA to secure your BW acct, but YubiKey FIDO/U2F protocol is disabled for free accts. And the 2nd thing isn't an issue b/c Info Sec 101 (and the Lastpass breach) tells us NOT TO STORE our 2FA seeds with our Passwords. And no, I'm not a Proton hater. I subscribe to their premium VPN service. Hopefully someone will fork their OSS code & release a full featured PW manager to the community.
enjoyable and interesting
I enjoyed this episode.
Hello, I have a question about yubikey 5 nfc. I first want to say thank you so much providing this kinds of information. I recently got hacked and even though I had google Authenticator for the totp’s, I still got hacked, so after doing some research I found videos just like yours and now I see how easy it is to get the session token with evilginx to bypass 2fa. So I’m still a bit new at this, but… now I understand that hardware token is probably the best bet for me as a normal person with gmail and steam accounts and what not, so thank once again for knowledge. My question is that, would evilginx still be able to get the session token if I were to use the yubico Authenticator app for the totp with the yubikey in combination? I noticed that only big company’s support the actual key by itself, but I have steam accounts and ect aswell. I hope I asked the question correctly. Thanks you so much once again. 😊
Great Podcast. Very enlightening
When NAC podcast comes?
Please make a podcast for NAC ( NETWORK ACESS CONTROL)
Please make a podcast on NAC solution.
Missing the podcast this week gentlemen!
Sorry for the delay. The audio podcast was released on time but video took a while. We just published two episodes on the YT channel.
The provisioning of WHfB requires the MFA during enrollment. Can I enable the WHfB for accounts not having MFA registered ?
No, you must register MFA to use WHfB. This is because WHfB sends the MFA token for any SSO apps that you require MFA for.
Hey, I'm being electronically gang stalked. I don't know what to do. I've gotten desperate and started leaving comments about it in ao many different spaces.
Oh look, I am the first view and comment. Nice.
Awesome! Perfect video podcast! We are going to deploy CG over our company. You explained me in one video all stuff that I been looking for! Thank you!
REALLY GOOD SESSION, Diagram or ppt would be more beneficial
Very helpful, thank you!
Another great episode, thanks for sharing 🙌🏻
Regarding LOS to a DC during enrollment with hybrid cloud trust, should we deploy via GPO instead? What will happen if we deploy via Intune and they receive the reg change while off network? Then they sign-in later on still off network and get prompted to enroll? Will it fail/error?
You can deploy it either via GPO or Intune. If you're doing it via Intune (on Hybrid AAD Join devices), this needs to be a separate policy than the Intune WHfB build in policy. It has to be a custom config template. It also can only be received upon enrollment of Intune. If the device is already enrolled in Intune, it will not work. And since it's a configuration policy in Intune, you'll also need to have co-management turned on with configuration offloaded to Intune and not SCCM. The documentation has some additional details. docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-hybrid-cloud-trust
This was super helpful thank you!
Hey guys, love the podcast. Just some quick feedback, listened to the whole thing and at the very end the tidbit “win 10 enterprise only” was inserted. Maybe include that up front eh? Lots of orgs don’t have enterprise licensing. Keep up the good work and keep the episodes coming!
This information is fire!!!! Love it!
Great info, more orgs should implement this. Keep it up!
Woah learned a lot! Amazing podcast!! I love the topics discussed. I’ll be taking away some from this for my podcast. I’m a new fan and supporter, keep up the great work. I just uploaded a podcast on my channel too!
Wow! this is gold, thanks for this presentation.