Blue Security

Blue Security

By Andy Jaw & Adam BrewerTechnology
Download on the App Store

Blue Security episodes

  • Our thoughts on Fireeye, Solarwinds, and Sunburst

    This week, Adam and Andy give you their thoughts on the Fireeye and Solarwinds breach. They also give defenders advice on immediate steps to help strengthen their organizations as well as some future insights on the direction security may be heading in terms on identity and device management. Finally, they give some thoughts on why it is important for security, business, and technical teams need to work as one cohesive unit in order to make security programs successful.

    Documentation:

    Unauthorized Access of FireEye Red Team Tools

    Check Point Response to FireEye Red Team Tools Leak

    CISA Updates Alert and Releases Supplemental Guidance on Emergency Directive for SolarWinds Orion Compromise

    Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor

    "The Chat" by Gavin Ashton

    Becoming resilient by understanding cybersecurity risks: Part 2

    Detecting Abuse of Authentication Mechanisms by the NSA

    Protecting Microsoft 365 from on-premises attacks

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    35 min
  • Passwordless Authentication

    Passwordless authentication is one of those rare features that strengthens security while making it easier for users to sign in. This week, Adam and Andy breakdown passwordless authentication options for enterprises in Windows, Azure AD, and other third party IDP's. They also address concerns about privacy when it comes to biometric data.

    Documentation:

    Windows Hello for Business

    Plan a passwordless authentication deployment in Azure Active Directory

    Passwordless authentication options for Azure Active Directory

    Factor Sequencing for Okta

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    39 min
  • Conditional Access

    This is it! Adam and Andy are finally diving into conditional access. They give an overview on what conditional access is including different types of conditional access like user, sign-in, and device based. Stick around until the end where Adam gives a great overview on a new feature for Azure AD authentications called Continuous Access Evaluation that changes the duration authentication tokens and how they are evaluated.

    Documentation:

    Advancing Password Spray Attack Detection

    Continuous Access Evaluation in Azure AD is now in public preview!

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    35 min
  • Work from Home - Tips and Tricks

    On this week's episode, Andy and Adam give you their tips and tricks for working from home. Having been in mature work from home company cultures, they have insights on what it was like pre and post pandemic. Enjoy!

    Documentation:

    Rework by Jason Fried and David Heinemeier Hansson

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    27 min
  • Our thoughts on Chris Krebs, Infosec Job Security, and Infosec Qualifications

    On this week's episode, Andy and Adam give their thoughts on the firing of Chris Krebs, former director of CISA. They also talk about their opinions on whether a CISO should be fired after a cybersecurity breach. Finally, they discuss if people need to have technical degrees and what qualifications are required to be in infosec.

    Documentation:

    CISA's Statement on the Nov 3rd Election

    IT Director fired after ransomware attack

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    25 min
  • Active Directory Security with Special Guest Morgan Patzwald

    This week, Morgan joins Adam and Andy on the podcast to discuss on-prem Active Directory security. They dive into administrator privileges, best practice for account creation, GPO's, and server admins. They also discuss the concept of Privileged Access Workstations (PAW).

    Documentation:

    Securing Privileged Access

    Privileged Access Workstations

    Morgan Patzwald

    Twitter: @morgancpatz

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    37 min
  • Single-Sign On (SSO) and Self-Service Password Reset (SSPR)

    This week, Adam and Andy go over why you should think about using an Identity Provider (IDP) to onboard your SaaS apps to use SSO. They also talk about why it's really important to think about what IDP to go with prior to making a decision. Finally, they talk about SSPR and why it's important to implement this feature in your organization.

    Documentation:

    Azure AD SSO options

    Enable Azure SSPR

    Enable Okta SSPR

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    32 min
  • How did we get into information security and career progression advice

    This week, Adam and Andy bring you a bonus episode where they talk about how they got into information security and offer advice on career progression in IT and cybersecurity.

    Documentation:

    Free Microsoft Developer's Environment

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    44 min
  • Ransomware protection - Part 4 - Windows 10 Security, Network Segmentation, Detection and Recovery

    This week, Adam and Andy wrap up the ransomware series by first going over controlled folder access in Windows 10 security and Onedrive for Business Known Folder Move. They discuss network segmentation and go into tools and process for detection and incident response. Finally, they conclude with tips on business continuity and disaster recovery when it comes to ransomware and cybersecurity.

    Documentation:

    Controlled Folder Access

    Onedrive for Business Known Folder Move

    Azure ATP/Microsoft Defender for Identity

    Ransomware Decryptors

    Maersk NotPetya Blog

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    30 min
  • Ransomware Protection - Part 3 - Admin Rights, Email Protection, Phishing Training

    This week, Adam and Andy continue the conversation on techniques and tools to protect your organization from ransomware. They dive into the concept of least privileged access and administrative rights, email protection solutions, and phishing/cybersecurity training program concepts for your company.

    Documentation:

    Exchange Online Protection Overview

    https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/exchange-online-protection-overview?view=o365-worldwide

    Office 365 ATP

    https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/office-365-atp?view=o365-worldwide

    Andy Jaw

    Twitter: @ajawzero

    LinkedIn: https://www.linkedin.com/in/andyjaw/

    Adam Brewer

    Twitter: @ajbrewer

    LinkedIn: https://www.linkedin.com/in/adamjbrewer/

    34 min

About Blue Security

From the publisher's feed

A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.

More shows like Blue Security

Acquired by Ben Gilbert and David Rosenthal

Acquired

4,836 Listeners

Pivot by New York Magazine

Pivot

9,613 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

WSJ Tech News Briefing by The Wall Street Journal

WSJ Tech News Briefing

1,644 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

374 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

650 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,027 Listeners

Smashing Security by Graham Cluley

Smashing Security

317 Listeners

Microsoft Cloud IT Pro Podcast by Ben Stegink, Scott Hoag

Microsoft Cloud IT Pro Podcast

65 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

The Azure Security Podcast by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos

The Azure Security Podcast

25 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

137 Listeners

Entra.Chat by Merill Fernando

Entra.Chat

6 Listeners