Welcome to the Blueprint Podcast!
Blueprint: Build the Best in Cyber Defense
Blueprint: Build the Best in Cyber Defense
Real conversations with the people building and running security operations. Practical insights from practitioners defending actual networks, not surface-level trends.Blueprint brings you in-depth discussions on detection engineering, SOC operations, incident response, and the tools and techniques that matter. Hosted by John Hubbard, SANS Cyber Defense Curriculum Lead, and brought to you by the SANS Institute.
Choose your favorite podcast player
Blueprint: Build the Best in Cyber Defense

Blueprint: The Podcast for Cybersecurity Operations Practitioners and Leaders

Real conversations with the people building and running security operations. Practical insights from practitioners defending actual networks, not surface-level trends.
Blueprint brings you in-depth discussions on detection engineering, SOC operations, incident response, and the tools and techniques that matter. Hosted by John Hubbard, SANS Cyber Defense Curriculum Lead, and brought to you by the SANS Institute.

About the Host

John Hubbard Profile Photo
John Hubbard

SANS Cyber Defense Curriculum Lead | Sr. Instructor

John Hubbard teaches people how to defend networks and leads curriculum strategy at SANS Institute, where he authors and manages multiple cybersecurity courses including SEC450 (SOC Analyst Training - Applied Skills for Cyber Defense Operations) and LDR551 (Building and Leading Security Operations Centers).
With a background in computer engineering and years of hands-on security work, John brings a systems-thinking approach to security, teaching, and podcasting. He's obsessed with translating complex security concepts into frameworks that actually make sense—whether that's improving security operations through security metrics, threat modeling, security data engineering, or leading a world-class cybersecurity team.
Blueprint cuts through the noise to explore what actually matters in cybersecurity: the people, processes, and decisions that make or break security programs. Real conversations with practitioners who've been in the trenches.

Recent Episodes

Preventing Silent Failures with Nir Loya Dahan
11
June 18, 2026

Preventing Silent Failures with Nir Loya Dahan

This episode is sponsored by Fig. This episode features a conversation with Nir Loya Dahan, Co-Founder and CPO at Fig, recorded at RSAC 2026. Our discussion covers telemetry health and SOC infrastructure resilience: what breaks in a log pipeline, why silent failures are so hard to catch, and how detection teams can build more confidence in their data foundation. Resources: Nir's Email: nir@fig.security Fig Website: https://www.fig.security Contact, Courses, and More: For feedback, reviews, gu...
The 2 AM Call: A Ransomware Negotiator's Playbook with Wade Gettle
10
Feb. 9, 2026

The 2 AM Call: A Ransomware Negotiator's Playbook with Wade Gettle

What happens after you discover ransomware? You have to talk to the attackers. And that conversation can make or break your entire response. In this episode, Wade Gettle, a professional ransomware negotiator, pulls back the curtain on the high-stakes world of threat actor negotiations. Wade is the person who gets the call at 2 AM when organizations are facing their worst moment, and he's handled negotiations across every scenario imaginable. You'll learn: What actually happens in the first 72 ho
Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam
9
Jan. 5, 2026

Infiltration Alert! How to Catch Fake IT Employees in Your Network with Zak Stufflebeam

Click here to send us your ideas and feedback on Blueprint! This episode is a big one! We kick off 2026 with a critical lessons learned on how to detect and prevent the threat of fake IT workers infiltrating your organization through the story of a REAL compromise. In this episode, repeat guest Zak Stufflebeam shares a detailed case study involving a major investigation of multiple counterfeit IT employees within a company. The episode provides valuable insights and actionable detection tacti...
Leading by Example: Confidence and Responsibility in Cybersecurity with Zak Stufflebeam
8
Aug. 19, 2025

Leading by Example: Confidence and Responsibility in Cybersecurity with Zak Stufflebeam

Click here to send us your ideas and feedback on Blueprint! In this episode, we sit down with Zak Stufflebeam, Director of Cybersecurity at a publicly traded insurance company. Zak shares his unique journey from the military to leading security operations, emphasizing essential leadership principles learned along the way. From his early days in basic training to leading complex cybersecurity teams, Zak’s story is one of perseverance, adaptability, and unwavering commitment. He delves into vit...
From the SANS Cyber Leaders Podcast: Fighting Back with John Hubbard
June 27, 2025

From the SANS Cyber Leaders Podcast: Fighting Back with John Hubbard

Click here to send us your ideas and feedback on Blueprint! This podcast episode is from the SANS Cyber Leaders Podcast. The episode features Blueprint host John Hubbard, where he talks with hosts James Lyne and Ciaran Martin on the ever-changing threat landscape and how SOC teams can stay ahead. John shares his expertise on spotting threats early, how to test your defences before the real attackers show up, and why he’s on a mission to simplify cybersecurity operations for the next generatio...
Redefining Security Operations: Lessons in AI Integration with James Spiteri
7
June 12, 2025

Redefining Security Operations: Lessons in AI Integration with James Spiteri

Click here to send us your ideas and feedback on Blueprint! In this episode of Blueprint, host John Hubbard sits down with James Spiteri from Elastic to explore the transformative power of AI on the SOC. They delve into how advanced AI technologies, such as agentic AI models, MCP protocol, and automation, are reshaping the SOC landscape. Discover how AI enhances SOC efficiency, reduces mundane tasks, and integrates context-aware capabilities. Learn about the real-world applications, from auto...
Send a Voicemail