Andy Jaw & Adam Brewer

Blue Security

A podcast for information security defenders (blue team) on best practices, tools, and implementation for enterprise security.

Author

Andy Jaw & Adam Brewer

Category

Technology

Podcast website

bluesecuritypod.com

Latest episode

Jul 7, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Audits and Data/AI Security with Special Guests Carley Salmon and Megan Maley 18.12.2023

On this episode, Adam and Andy talk with Carley and Megan, about compliance, auditing, and data protection in the cybersecurity industry. They emphasize the importance of understanding compliance frameworks and preparing for audits with the help of partners or consultants. They also highlight the need for continuous monitoring and a shift away from checkbox security. The conversation touches on th...

CNAPP - Defender for Cloud Overview 11.12.2023

This episode of the Blue Security Podcast discusses the Cloud Native Application Protection Platform (CNAPP) and Microsoft's Defender for Cloud. The hosts provide an overview of CNAPP and its various components, including DevSecOps, security posture management, and cloud workload protection platform. They highlight the ease of deployment and the pay-as-you-go pricing model of Defender for Clou...

MeridianLink extortion, Plastic Surgery office breached, AI voice clones 04.12.2023

On this week's episode, Adam and Andy talk about a ransomware gang making an SEC complaint against their victim, a medical office breach, and AI voice clones. ------------------------------------------- Youtube Video Link: ⁠ https://youtu.be/iGgp8SurXM8 ⁠⁠⁠⁠⁠⁠⁠ ⁠ ------------------------------------------- Documentation: https://www.bleepingcomputer.com/news/security/ransomware-gang-files-sec-...

Microsoft Ignite 2023 - Part 2 04.12.2023

On this week's episode, Adam and Andy talk about more things on security from Microsoft Ignite. From canary capabilities in MDE to Automatic Conditional Access Policies, there are a TON of really amazing announcements. Tune in to hear the 2nd half of Ignite news! ------------------------------------------- Youtube Video Link: https://youtu.be/Pl010QG_n5I ⁠⁠⁠⁠⁠ ⁠ -------------------------------...

Microsoft Ignite 2023 - Part 1 20.11.2023

On this week's episode, Adam and Andy talk about all the security announcements from Microsoft Ignite 2023. There were SO many that this will be part 1 with another episode being released in the following week. Listen in to some of the amazing advancements with Copilot, generative AI, and security within the Microsoft portfolio! ------------------------------------------- Youtube Video Link: ⁠...

Okta Breach Follow-up and Passkeys 13.11.2023

On this week's episode, Andy and Adam talk about the follow up investigation from Okta about their support system breach along with some lessons that listeners can take away. They also talk about passkeys going mainstream and what that means for the future of passwordless. ------------------------------------------- Youtube Video Link: ⁠ https://youtu.be/5Cz07OKHAII ---------------------------...

SEC charges Solarwinds CISO & Backing up and Archiving M365 data 12.11.2023

On this week's episode, Andy and Adam talk about the SEC charging the Solarwinds CISO with fraud and the implications on the overall security leadership community. They also talk about some questions that came up about backing up and restoring M365 data and a new capability coming out in public preview very soon! ------------------------------------------- Youtube Video Link: https://youtu.be/...

23andMe, Okta breach, MDE Automatic Attack Disruption 30.10.2023

On this week's episode, Andy and Adam talk about the 23andMe and Okta breach that happened recently along with some recommendations on how organizations can try and prevent similar attacks in the future. They also talk about a revolutionary new feature in Microsoft Defender for Endpoint called Automatic Attack Disruption. They talk about how it works and how organizations can take advantage of...

Entra Web-sign in, MDE Device Control, Imposter Syndrome 23.10.2023

On this week's episode, Andy and Adam talk about some new features with Entra Web Sign-in and Microsoft Defender for Endpoint Device Control. They also talk about what every infosec professional goes through: imposter syndrome. ------------------------------------------- Youtube Video Link:  https://youtu.be/AiU8tjl_oPA ------------------------------------------- Documentation: https://learn.m...

Conditional Access Gap Analysis 19.10.2023

On this week's episode, Andy and Adam talk about how to think about your conditional access policy design to avoid some common gaps that attackers can take advantage of. ------------------------------------------- Youtube Video Link:  https://youtu.be/ULO9oRqJaV4⁠⁠⁠⁠ ------------------------------------------- Documentation: https://danielchronlund.com/2022/01/07/the-attackers-guide-to-azure-a...

Unpopular Cybersecurity Opinions 09.10.2023

On this week's episode, Andy and Adam talk about a fun Twitter/X thread where cybersecurity professionals expressed some "unpopular opinions." ------------------------------------------- Youtube Video Link:  ⁠ https://youtu.be/qEV3zbskXX8 ------------------------------------------- Documentation: https://x.com/merill/status/1700615539452965327?s=20 https://x.com/wdormann/status/17028...

JCI Ransomware, Ransomware Negotiations, CISA guidance 02.10.2023

On this week's episode, Andy and Adam talk about Johnson Controls' ransomware attack and some implications on national security. They also talk about some lessons learned from ransomware negotiations and CISA's new campaign, Secure Your World. ------------------------------------------- Youtube Video Link:  https://youtu.be/bslx3jol8tg ------------------------------------------- Docume...

MITRE Engenuity ATT&CK Evaluations and Insider Risk 26.09.2023

On this week's episode, Andy and Adam talk about the results of the MITRE Engenuity ATT&CK Evaluations and how to interpret them. They also talk about the rising costs of insider risk and some things you can do to combat insider risk. ------------------------------------------- Youtube Video Link:  ⁠⁠⁠ https://youtu.be/FF1ZD73X5nA ------------------------------------------- Documentation:...

MGM Resorts Security Incident 18.09.2023

On this week's episode, Andy and Adam talk about the security incident impacting MGM Resorts. They discuss the attack vector of social engineering and ways that you can help protect your helpdesk and users from this type of attack. ------------------------------------------- Youtube Video Link:  https://youtu.be/2UvrVA7u4VA⁠ ------------------------------------------- Documentation: https://ww...

Apple 0-day's, Storm-0558 follow up, MFST Conditional Access Dashboard 11.09.2023

On this week's episode, Andy and Adam talk about Apple's no-click zero day, the technical findings of the follow up investigation on Storm-0558, and the new Microsoft Conditional Access Dashboard and Templates. ------------------------------------------- Youtube Video Link:  https://youtu.be/BmHqNkQQx8I ------------------------------------------- Documentation: https://citizenlab.ca/2023/0...

Data Security in Microsoft 365 04.09.2023

On this week's episode, Andy and Adam talk about data security in Microsoft 365. They talk about data discovery, data classification, and some of the tools like sensitivity and retention labels to help keep your data security within M365. ------------------------------------------- Youtube Video Link: ⁠⁠⁠⁠⁠⁠ https://youtu.be/rZErX9s03zM ------------------------------------------- Documentation...

Side channel attack, White House cybersecurity workforce plan, IBM Cost of a Data Breach 28.08.2023

On this week's episode, Andy and Adam catch up some worthy infosec news including a new side channel attack, the White House cybersecurity workforce plan, and IBM's Cost of a Data Breach report. ------------------------------------------- Youtube Video Link: ⁠⁠⁠⁠⁠⁠ https://youtu.be/CkQ19CGiEeE ------------------------------------------- Documentation: https://www.bleepingcomputer.com/news/...

Red Teaming with Special Guest 23P 21.08.2023

On this week's episode, Andy and Adam talk with Michael Belton and Dave Falkenstein from 23p, a Madison, Wisconsin based red-teaming company about pentesting, purple teaming, and start out in red-teaming. ------------------------------------------- Youtube Video Link:  https://youtu.be/msWQ0mH-fUQ⁠⁠⁠⁠⁠⁠ ------------------------------------------- Documentation: https://www.23p.com/ http://www....

Securing Entra External Identities 14.08.2023

On this week's episode, Andy and Adam talk about securing Entra external identities. They talk about B2B and B2C as well as a few other lesser known features of external identities like direct connect and multi-tenant synchronization. ------------------------------------------- Youtube Video Link:  ⁠⁠⁠ https://youtu.be/V1_RIGQKUYI ------------------------------------------- Documentation: ⁠htt...

Educating Defenders with Special Guest Howard Friedman, Ascent Solutions 07.08.2023

On this week's episode, Andy and Adam welcome guest Howard Friedman of Ascent Solutions to the program. Howard helps educate our audience of security defenders on the why, when, and how to engage with partners. ------------------------------------------- Youtube Video Link:  ⁠⁠https://youtu.be/Q3GgxefbbnQ ------------------------------------------- Documentation: https://www.meetascent.com/ ht...

New SEC and FCC rules, and Samsung device security 31.07.2023

On this week's episode, Adam and Andy talk about some new SEC and FCC rules as well as some news on Samsung device security. ------------------------------------------- Youtube Video Link:  ⁠⁠⁠⁠⁠ ⁠ https://youtu.be/_N7WBSuDW9s ------------------------------------------- Documentation: https://www.sec.gov/news/press-release/2023-139 https://www.theverge.com/2023/7/11/23791183/fcc-sim-swapping-p...

Expanded M365 audit logs, Threads, new Entra features 24.07.2023

On this week's episode, Adam and Andy follow up on Storm-0558 and how Microsoft is expanding cloud logging as a result of the threat actor. They also chat about Threads, Meta's new Twitter clone, and some new Entra features that will help orgs be more secure. ------------------------------------------- Youtube Video Link:  https://youtu.be/6NGvpcxrWC0 --------------------------------------...

Storm-0558 - Attack on Exchange Online 17.07.2023

On this week's episode, Adam and Andy talk Storm-0558, the China-based actor, that compromised Exchange Online. They go through the attack chain and CISA's guidance on how you can better protect your organization going forword. ------------------------------------------- Youtube Video Link: https://youtu.be/N7dRPCCU25A⁠⁠⁠⁠⁠⁠⁠⁠ ------------------------------------------- Documentation: http...

Common M365 Misconfigurations 10.07.2023

On this week's episode, Adam and Andy talk through Trimarc Security's blog on M365 security misconfigurations. Surprisingly, there are a few that are still being seen through security assessments like missing MFA and legacy authentication. Listen in to hear the top misconfigurations for M365! ------------------------------------------- Youtube Video Link: ⁠ ⁠⁠⁠ ⁠ https://youtu.be/30luEGO-N...

What's new with Intune and Entra 03.07.2023

On this week's episode, Adam and Andy talk about some new features in Intune and Entra. There are some great features that are in public preview and general availability that admins should be aware of like MAM for Windows and Authentication Strengths. ------------------------------------------- Youtube Video Link: ⁠ ⁠ https://youtu.be/gssZWlnP3to ------------------------------------------- Doc...

Listen to the Blue Security podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.