Blue Team Academy podcast artwork

PODCAST · technology

Blue Team Academy

Um podcast para você quer proteger empresas e pessoas de ataques hackers

Publisher-supplied feed metadata · PodParley refreshed Apr 12, 2026 · Source feed

  1. 188

    5 Blue Team Jobs for IT Pros (You Don't Have to Restart)

    Cybersecurity is not an entry-level field. It's a specialization — and that single distinction changes how an experienced IT professional should approach the move.This is a mapping exercise: five defensive security roles that take a lateral pivot from an IT background instead of a restart, what each one actually does day to day, which IT experience feeds it, and the honest gap you'd still have to close for each.No guaranteed timelines, no salary fantasies. Including the part where the U.S. Bureau of Labor Statistics just revised its growth projection down.CHAPTERS00:00 The advice that costs IT pros years00:36 Why cybersecurity is a specialization, not an entry-level field02:56 The three-question pivot test: overlap, adjacency, proof04:13 1. Security Engineer (Infrastructure / Cloud)06:14 2. Identity and Access Management Engineer08:20 3. Network Security Engineer10:33 4. Vulnerability Management Specialist13:00 5. Tier 2 SOC & Incident Response Analyst15:18 What the job market actually says (BLS, August 2026 update)17:06 Make your resume say what your work already was18:44 How to choose: Inventory, Threats, Controls, Scale20:00 Where to go nextTHE WRITTEN VERSIONAll five roles, plus the resume translation table:https://blueteam-academy.com/blog/blue-team-jobs-it-professionals/KEEP IT SAFE — OUR NEWSLETTEROne breakdown a week for IT professionals making this exact move:https://www2.blueteam-academy.com/keep-it-safe-signupFROM IT TO CYBERSECURITYThe program where we teach the Threat & Control Method — Inventory, Threats, Controls, Scale — as a repeatable decision process rather than a tool list: https://www2.blueteam-academy.com/from-it-to-cybersecurity/SOURCESU.S. Bureau of Labor Statistics, Occupational Outlook Handbook, InformationSecurity Analysts (last modified 27 August 2026): 21% projected growth 2025–35,~14,100 annual openings, $129,180 median annual wage (May 2025), 192,900 jobs (2025).https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htmBlue Team Academy is a program for IT professionals moving into defensive cybersecurity. Konnio Technology LLC.#BlueTeam #CybersecurityCareers #ITCareers

  2. 187

    How to Prepare for a Cybersecurity Job Interview (From IT)

    Cybersecurity interviews don't test what you already know from IT — they test how you think. This video walks through all three interview rounds, the four kinds of questions you'll actually face, and one repeatable way to structure your answers that works across every single one of them.Based on our full written guide: https://blueteam-academy.com/blog/cybersecurity-job-interview-prep/00:00 Intro00:39 Why Cybersecurity Interviews Are Different02:39 The HR Screening Call04:49 The Technical Round: Research & Frameworks08:31 The Four Question Buckets11:21 How to Answer a Scenario Question13:33 SOC vs GRC vs IAM vs Cloud Security15:11 Portfolio, Home Lab, or Certifications?17:18 The Manager Round & Handling "I Don't Know"20:19 Mistakes That Sink Candidates + What to Ask the Interviewer22:18 After the Interview + Key TakeawaysSources referenced in this video:ISC2, 2025 Cybersecurity Workforce Study — https://www.isc2.org/Insights/2025/12/2025-ISC2-Cybersecurity-Workforce-StudyWant a structured way to turn your IT experience into a cybersecurity career? Link in the pinned comment.For more breakdowns like this one, the Keep IT Safe newsletter is there too.#CyberSecurity #BlueTeam #ITCareer #SOCAnalyst #CyberSecurityJobs

  3. 186

    8 Tools Real Blue Teams Actually Run in 2026

    If someone on your team clicks a phishing email tonight, the tools your SOC already has running decide whether you catch it in minutes — or read about it in a breach report six months from now.In this episode: the 8 core tool categories every blue team runs — SIEM, EDR, network detection, vulnerability management, SOAR, threat intelligence, forensics, and free open-source practice tools — the specific products that show up most in real SOC analyst job postings, and how to start building hands-on skill with them before you have a job title that says "security."Full written breakdown: https://blueteam-academy.com/blog/top-cybersecurity-tools-blue-teams/Watch the video version: https://blueteam-academy.com/videos/top-cybersecurity-tools-blue-teams-2/Ready to move from IT into cybersecurity? https://www2.blueteam-academy.com/from-it-to-cybersecurity/Get the next episode before it's old news — Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signupTIMESTAMPS00:00 Why the tools you run decide the outcome01:15 The 8 core tool categories02:15 SIEM & log analytics03:16 EDR & XDR04:56 Network detection05:57 Vulnerability management06:50 SOAR & automation07:51 Threat intelligence09:40 Forensics & incident response10:19 Free tools to build a SOC on your own laptop11:11 The mistake most teams — and learners — make12:20 How to build hireable skill with this stack

  4. 185

    WannaCry Explained: How One Worm Took Down the NHS in a Day

    One piece of malware. No phishing. No user clicking anything. And on May 12, 2017, WannaCry took the UK's National Health Service offline in a single afternoon — 19,000 appointments cancelled, MRI scanners locked out, ambulances diverted.In this Breach File we walk through exactly what happened: the 59-day gap between the Microsoft patch and detonation, how the Shadow Brokers' leak of EternalBlue armed Lazarus Group to build a self-propagating cryptoworm, and how the kernel memory corruption in SMBv1 actually worked — no jargon, no glossing.Then we run it through the Threat and Control Method: Inventory, Threats, Controls, Scale — the same four-step loop we teach at Blue Team Academy for turning IT experience into blue team judgment.If you already work in IT — sysadmin, network engineer, help desk, cloud, ops — WannaCry is the clearest existing worked example of how the environments you already run get turned into weapons, and how ordinary IT hygiene applied with a defender's intent would have stopped almost all of it.━━━━━━━━━━━━━━━━━━━━━━━━━━CHAPTERS━━━━━━━━━━━━━━━━━━━━━━━━━━00:00 The Attack That Needed No Clicks00:24 Why WannaCry Still Matters01:18 Timeline of an Epidemic03:33 Lazarus Group and the Nation-State Threat05:21 How EternalBlue Actually Worked09:10 The $4 Billion Human Cost10:24 The Defense — Inventory, Threats, Controls, Scale15:11 Why This Isn't History16:03 Cybersecurity Is Not Rocket Science━━━━━━━━━━━━━━━━━━━━━━━━━━READ THE FULL BREACH FILE━━━━━━━━━━━━━━━━━━━━━━━━━━Full written breakdown with sources and code samples:https://blueteam-academy.com/breaches/wannacry-ransomware-attack-eternalblue-cryptoworm/━━━━━━━━━━━━━━━━━━━━━━━━━━BLUE TEAM ACADEMY━━━━━━━━━━━━━━━━━━━━━━━━━━We help experienced IT professionals move into defensive cybersecurity — without starting over. We teach the Threat and Control Method: a repeatable four-step decision process (Inventory → Threats → Controls → Scale) applied to real incidents like this one.Learn more: https://www2.blueteam-academy.com/from-it-to-cybersecurity/Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signupBlog: https://blueteam-academy.com/blogInstagram: @blueteamacad━━━━━━━━━━━━━━━━━━━━━━━━━━SOURCES━━━━━━━━━━━━━━━━━━━━━━━━━━- Microsoft Security Bulletin MS17-010 (March 14, 2017)- CISA/US-CERT Alert TA17-132A — WannaCry indicators- U.S. Department of Justice indictment of Park Jin Hyok (September 6, 2018)- UK National Audit Office — "Investigation: WannaCry cyber attack and the NHS" (October 2017)- Europol statement, May 2017 — 200,000 systems / 150 countries- MITRE ATT&CK — EternalBlue / T1210━━━━━━━━━━━━━━━━━━━━━━━━━━#Cybersecurity #BlueTeam #WannaCry #Ransomware #EternalBlue

  5. 184

    Break Into Cybersecurity Without Quitting Your IT Job

    You want to move into cybersecurity, but can't afford to quit your IT job. Here's the 5-step path most career advice never tells you about.The standard advice — quit, bootcamp, grind, take a $40k entry-level role — is wrong for anyone with real financial obligations. There's a better path. It runs THROUGH your current IT job, not around it.In this video, we walk through the exact 5-step transition that IT professionals use to move into defensive cybersecurity while keeping their paycheck, protecting their family, and building real security experience along the way.━━━━━━━━━━━━━━━━━━━━━━━━━━━📩 GET THE PATH IN YOUR INBOXEvery week, our Keep IT Safe newsletter breaks down real breaches, defensive techniques, and career moves for IT pros making the jump to cybersecurity.→ https://www2.blueteam-academy.com/keep-it-safe-signup🎯 MAKE THE TRANSITION DELIBERATEThe Blue Team Academy program walks you through the Threat & Control Method end to end — templates, walkthroughs, and the decision criteria we couldn't fit into 13 minutes.→ https://www2.blueteam-academy.com/from-it-to-cybersecurity/📖 READ THE FULL ARTICLE→ https://blueteam-academy.com/blog/transition-to-cybersecurity-without-quitting-your-job/━━━━━━━━━━━━━━━━━━━━━━━━━━━⏱ CHAPTERS00:00 — The sentence that stops most transitions00:40 — The real numbers (BLS, ISC2, CyberSeek)02:05 — Step 1: Turn your IT role into unpaid security experience04:35 — Step 2: The Threat & Control Method07:15 — Step 3: A sustainable study routine09:15 — Step 4: Aim for the internal lateral move first11:15 — Step 5: Show your work in public12:35 — The bottom line━━━━━━━━━━━━━━━━━━━━━━━━━━━📚 SOURCES- U.S. Bureau of Labor Statistics — Occupational Outlook Handbook, Information Security Analysts https://www.bls.gov/ooh/computer-and-information-technology/information-security-analysts.htm- ISC2 Cybersecurity Workforce Study 2024 https://www.isc2.org/research- CyberSeek — Cybersecurity Career Pathway https://www.cyberseek.org/━━━━━━━━━━━━━━━━━━━━━━━━━━━🔗 RELATED- The Threat & Control Method explained https://blueteam-academy.com/blog/threat-and-control-method/- The full blue team career path for IT professionals https://blueteam-academy.com/blog/cybersecurity-career-path/━━━━━━━━━━━━━━━━━━━━━━━━━━━About Blue Team AcademyBlue Team Academy trains experienced IT professionals to move into defensive cybersecurity — without starting over. We teach the Threat & Control Method: a repeatable framework for turning IT experience into blue team decision-making.#Cybersecurity #ITCareer #BlueTeam

  6. 183

    Everyone Explains the Dark Web. Nobody Teaches You to Monitor It.

    Search "dark web" and you get the same spooky iceberg explainer a thousand times over. Useless if you already run infrastructure. This is the one nobody makes: how a blue team actually does dark web monitoring — how you watch for your company's leaked credentials, catch Tor traffic leaving your own network, and turn a scary alert into a defensible plan.Built for the IT pro moving into defense: sysadmins, network engineers, help desk, cloud, and infrastructure folks. Most of what makes dark web monitoring work isn't hacker magic — it's the network and endpoint fundamentals you already touch every day, pointed in a new direction.⏱️ CHAPTERS0:00 Your login might already be for sale0:50 Who this is for1:30 Surface, deep, and dark web — the version a defender needs3:20 Why you can't just Google your leaked data5:20 The 4 signals real monitoring watches for7:50 Detecting the dark web on your OWN network10:20 DIY vs. professional monitoring — the honest answer11:50 Turn the alert into a plan: Inventory → Threats → Controls → Scale14:10 You're not starting from zero📩 KEEP IT SAFE — our free weekly newsletterOne practical, no-hype breakdown like this for IT pros moving into defense, every week:https://www2.blueteam-academy.com/keep-it-safe-signup🎓 TRAIN WITH BLUE TEAM ACADEMYLearn the full Threat & Control Method — the decision process a working defender uses, taught for people coming from IT:https://www2.blueteam-academy.com/from-it-to-cybersecurity/📖 READ THE FULL BREAKDOWNhttps://blueteam-academy.com/blog/dark-web-monitoring-blue-team/🔗 SOURCES & REFERENCES- MITRE ATT&CK — Valid Accounts (T1078): https://attack.mitre.org/techniques/T1078/- MITRE ATT&CK — Multi-Factor Authentication (M1032): https://attack.mitre.org/mitigations/M1032/- MITRE ATT&CK — Account Use Policies (M1036): https://attack.mitre.org/mitigations/M1036/- NIST SP 800-53 Rev. 5 — IA-2, AC-17- Deep/dark web size estimates: Trend Micro (2026)Subscribe / follow Blue Team Academy for a new breakdown each week. That's the whole ask.#DarkWebMonitoring #BlueTeam #CyberSecurity

  7. 182

    Help Desk to SOC Analyst: You're Missing 1 Pillar, Not 3

    You're not starting from zero. If you work help desk, sysadmin, or IT support, you already run the exact same loop a SOC analyst runs — monitor, triage, investigate, document, escalate. This video breaks down the one real skill gap, what the alert queue actually looks like day to day, and a four-step plan to close the gap without wasting a year on the wrong certifications.📖 Full written breakdown, sources, and the Threat & Control Method: https://blueteam-academy.com/blog/help-desk-to-soc-analyst/📩 Get this kind of breakdown every week — the Keep IT Safe newsletter: https://www2.blueteam-academy.com/keep-it-safe-signup🎓 Ready to build the whole decision process, not just the SOC piece? https://www2.blueteam-academy.com/from-it-to-cybersecurity/TIMESTAMPS 00:00 They called the help desk, not the firewall 01:35 The claim: you're missing 1 pillar, not 3 02:32 Help desk vs SOC — the job posting comparison 03:39 Why the queue is drowning (2,000-4,500 alerts/day) 05:05 What a real alert looks like (+ the Target lesson) 06:44 The three pillars — and the one you're missing 08:02 The Threat & Control Method, applied to your career 09:56 The tools trap (and what to study instead) 11:32 The honest US salary and market numbers 14:15 You're not starting from zeroSOURCES CITED U.S. Bureau of Labor Statistics, Occupational Outlook Handbook (2024-34 projections) · ISC2 2025 Cybersecurity Workforce Study · FBI public advisory on help-desk social engineering (2025) · Tines Voice of the SOC research#BlueTeam #SOCAnalyst #Cybersecurity #ITCareer #CareerChange

  8. 181

    Zero Trust Explained for IT Pros (No Vendor Hype)

    Zero Trust for IT professionals — what it actually is, minus the vendor hype. NIST SP 800-207 in plain language, the six myths worth clearing up, and why your AD, MFA, and endpoint work already counts as a head start.Zero Trust is simultaneously the most oversold phrase in cybersecurity and one of the most useful ideas in it. If you already run infrastructure — sysadmin, network, cloud, ops — this breaks down the architecture using the systems you administer every day, then shows you where to actually start.No product pitch. No fear-mongering. Just the reasoning a blue team defender uses, explained simply.━━━━━━━━━━━━━━━━━━━━CHAPTERS━━━━━━━━━━━━━━━━━━━━0:00 The most oversold phrase in cybersecurity0:35 The moat dried up: why the perimeter stopped mattering1:45 What Zero Trust actually is (never trust, always verify)3:00 Where the term came from: Kindervag & Forrester, 20104:00 The architecture in plain English: NIST SP 800-2075:45 What Zero Trust is NOT: 6 myths7:15 A tale of two networks: the same attack, two outcomes9:15 Why IT pros are already halfway there10:15 How to actually start: Inventory → Threats → Controls → Scale11:15 The real shift (and where to go next)━━━━━━━━━━━━━━━━━━━━READ THE FULL BREAKDOWN━━━━━━━━━━━━━━━━━━━━Every source linked, written for reference:https://blueteam-academy.com/blog/zero-trust-it-professionals/━━━━━━━━━━━━━━━━━━━━GO DEEPER━━━━━━━━━━━━━━━━━━━━The decision process behind this video — Inventory → Threats → Controls → Scale — is what we teach. Learn to reason through any environment, not memorize tools:https://www2.blueteam-academy.com/from-it-to-cybersecurity/Get Keep IT Safe — practical defensive security breakdowns for IT professionals, in your inbox:https://www2.blueteam-academy.com/keep-it-safe-signup━━━━━━━━━━━━━━━━━━━━SOURCES━━━━━━━━━━━━━━━━━━━━- NIST SP 800-207, Zero Trust Architecture (2020): https://csrc.nist.gov/pubs/sp/800/207/final- NIST SP 1800-35, Implementing a Zero Trust Architecture (2025): https://csrc.nist.gov/pubs/sp/1800/35/final- CISA Zero Trust Maturity Model 2.0: https://www.cisa.gov/zero-trust-maturity-model- Forrester — "No More Chewy Centers," John Kindervag (2010)━━━━━━━━━━━━━━━━━━━━CONNECT━━━━━━━━━━━━━━━━━━━━LinkedIn: https://www.linkedin.com/showcase/blue-team-academyInstagram: https://www.instagram.com/blueteamacadX: https://x.com/BlueTeamAcadCybersecurity is not rocket science.#ZeroTrust #CyberSecurity #BlueTeam

  9. 180

    Cybersecurity Career Path for IT Pros (2026): Roles, Salaries & What Gets You Hired

    The cybersecurity career path, mapped for people already in IT: the roles, salaries, certs, and the one skill that actually gets you hired.If you already work in IT — help desk, sysadmin, networking, cloud, ops — you're not starting from zero. This is the full cybersecurity career path for IT professionals: which entry-level security roles fit your background, how to pick between blue team, offensive, and GRC, what the work really pays in 2026 (with real BLS and CyberSeek data), the certifications that matter and the order to stack them, and the way of thinking that separates people who *have* certs from people who get hired.No bootcamp hype. No guaranteed-job promises. Just the map.Because cybersecurity is not rocket science — and if you already work in IT, you're closer to it than anyone's told you.⏱️ CHAPTERS00:00 Why the cybersecurity career path feels impossible00:36 3 things every IT pro needs to hear first02:03 Where your path starts: entry-level security roles04:36 Blue team vs offensive vs GRC — pick a lane06:39 Cybersecurity salaries in 2026 (real BLS data)08:26 Certifications, stacked in the right order10:16 Why passing the exam isn't the job11:58 How a defender actually thinks15:13 Your 12–24 month roadmap17:40 The one skill that gets you hired📘 READ THE FULL GUIDEThe complete written breakdown, with every source linked:https://blueteam-academy.com/blog/cybersecurity-career-path/🎯 READY TO WALK THE PATH?Blue Team Academy is training built around the Threat & Control Method — you learn to think, decide, and act like a defender, not memorize tools you'll forget:https://www2.blueteam-academy.com/from-it-to-cybersecurity/📩 NOT READY YET? START WITH THE NEWSLETTERKeep IT Safe breaks down the IT-to-cyber transition one practical idea at a time — no hype, no spam:https://www2.blueteam-academy.com/keep-it-safe-signup🔍 SOURCES- U.S. Bureau of Labor Statistics — Information Security Analysts (median wage $124,910, May 2024; 29% projected growth 2024–2034)- CyberSeek — cybersecurity role taxonomy & certification demand- NICE Framework (CISA/NICCS)#Cybersecurity #CybersecurityCareer #BlueTeam

  10. 179

    The 4-Phase Method to Defend Any IT Environment (Threat & Control)

    Every IT professional has been handed the same impossible question: "Take a look at our security — what should we be worried about?" Most freeze. Not because they lack skill, but because they lack a framework.The Threat and Control Method is a four-phase decision process for defending any IT environment against cyber threats: Inventory, Threats, Controls, Scale. It moves in a deliberate order, produces specific outputs, and gives IT professionals a repeatable way to reason about security — without replacing NIST, ISO, or any established framework.In this video, we walk through the full shape of the method: where it came from, what it is (and what it is not), and how each of the four phases works. If you have been trying to break into cybersecurity from an IT background and every course you try teaches tools instead of thinking, this one is for you.▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬🎯 CHAPTERS0:00 The message every IT pro dreads1:15 Why cybersecurity training keeps failing you2:45 What the Threat and Control Method actually is4:15 What the method is NOT5:45 Where the method came from (2010, CA Technologies)7:30 Phase 1: Inventory9:00 Phase 2: Threats10:30 Phase 3: Controls11:45 Phase 4: Scale12:45 Why the order is not optional13:30 What this changes for an IT professional14:15 What to do next▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬🔗 RESOURCES📘 Read the full breakdown on the blog:https://blueteam-academy.com/blog/threat-and-control-method/🎓 Ready to actually run the method? See how the course works:https://www2.blueteam-academy.com/from-it-to-cybersecurity/📬 Keep IT Safe — our weekly newsletter for IT professionals moving into cybersecurity:https://www2.blueteam-academy.com/keep-it-safe-signup▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬🔎 RELATED READINGWhat is Cybersecurity? How IT Pros Can Transition to Securityhttps://blueteam-academy.com/blog/what-is-cybersecurity-how-it-pros-can-transition-to-security/The Cybersecurity Career Path, Mapped for People Who Already Work in IThttps://blueteam-academy.com/blog/cybersecurity-career-path/Equifax Breach Explained: What Every Defender Should Learn From Ithttps://blueteam-academy.com/breaches/equifax-data-breach-explained/▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬📱 CONNECTLinkedIn: https://www.linkedin.com/showcase/blue-team-academyInstagram: https://www.instagram.com/blueteamacad/X: https://x.com/BlueTeamAcadFacebook: https://www.facebook.com/blueteamacad▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬Blue Team Academy helps IT professionals move into cybersecurity without starting over. If you have IT experience and you want to defend real environments — this channel is for you.Cybersecurity is not rocket science.#Cybersecurity #ITCareer #BlueTeam #CyberSecurityTraining #ITtoCyber

  11. 178

    Container Security Is More Than Image Scanning (What Most Guides Miss)

    Your image scanner says your containers are secure. It's telling you about one layer of a system that has at least four. Here's what container security actually looks like — the real OWASP risk landscape, the 2018 Tesla Kubernetes breach that turned every abstract risk into a headline, and a repeatable way to reason through it all.If you already work in IT, DevOps, or cloud, you're closer to understanding this than you think. A container is a process on a Linux host. A Kubernetes cluster is a distributed system with a network, an API, identities, and permissions. You've been defending that shape of infrastructure your whole career — cloud-native just renamed the parts.In this video:▸ Why "we scanned the images" is a dangerously incomplete answer▸ The 3 lifecycle phases of real container security — Build, Deploy, Run▸ The OWASP Docker Top 10 vs. OWASP Kubernetes Top 10 (they're not the same list, and most articles get this wrong)▸ The 2018 Tesla Kubernetes breach, mapped onto real K-numbers — exposed dashboard (K06) → hardcoded AWS keys (K08) → cryptojacking (K01)▸ How to apply the Threat & Control Method (Inventory → Threats → Controls → Scale) to a real container environment tomorrow morning📖 FULL ARTICLE (with the OWASP list, links, and sources):https://blueteam-academy.com/blog/container-cybersecurity-beyond-image-scanning/🧭 IF YOU'RE AN IT PRO EYEING A MOVE INTO CYBERSECURITY:Blue Team Academy is built for experienced IT professionals — sysadmins, network engineers, cloud/DevOps folks — who don't want to start over. We teach the reasoning behind defense, not another pile of tools to memorize.▸ See what's inside: https://www2.blueteam-academy.com/from-it-to-cybersecurity/▸ Free weekly newsletter, Keep IT Safe: https://www2.blueteam-academy.com/keep-it-safe-signup⏱️ CHAPTERS0:00 The scanner problem0:25 What this video covers0:55 You're not starting from zero1:55 The 3 phases: Build, Deploy, Run3:10 OWASP has TWO container lists (and they're different)5:00 The 2018 Tesla Kubernetes breach7:15 Tools are just shopping lists8:05 The Threat & Control Method applied to containers10:15 The takeaway11:00 Where to go next🔗 REFERENCES▸ OWASP Kubernetes Top 10: https://owasp.org/www-project-kubernetes-top-ten/▸ OWASP Docker Top 10: https://owasp.org/www-project-docker-top-10/▸ RedLock report on the Tesla breach (via CNBC): https://www.cnbc.com/2018/02/21/hackers-hijack-teslas-cloud-system-to-mine-cryptocurrency-redlock.html▸ Threat & Control Method (full breakdown): https://blueteam-academy.com/blog/threat-and-control-method/👉 SUBSCRIBE for real breach breakdowns and defensive-security reasoning for IT pros: https://www2.blueteam-academy.com/keep-it-safe-signup━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ABOUT BLUE TEAM ACADEMYBlue Team Academy helps experienced IT professionals move into cybersecurity without starting over. Your IT background isn't a gap to close — it's an unfair advantage. We teach the Threat & Control Method: a repeatable way to think, decide, and act like a defender.Because cybersecurity is not rocket science.#ContainerSecurity #KubernetesSecurity #Cybersecurity

  12. 177

    The MGM Breach Wasn't a Hack. It Was a Ten-Minute Phone Call

    On Friday, September 8, 2023, someone picked up a phone and called the MGM Resorts IT helpdesk. Ten minutes later, they had Super Admin over one of the biggest identity platforms in the hospitality industry — and MGM was on its way to a $100 million disclosure.This is a Breach Files breakdown of the MGM cyberattack: how Scattered Spider used LinkedIn recon and a vishing call to bypass identity verification, how they turned Okta inbound federation into a permanent backdoor, why MGM's incident response made the damage worse, and what any IT professional can do this week to make sure their own environment isn't the next headline.We walk the whole breach through the Threat & Control Method — Inventory, Threats, Controls, Scale — and end with three concrete audit questions you can take back to work tomorrow.────────────CHAPTERS00:00 The 10-minute phone call00:20 Not a hack. A logon.00:50 Who called MGM02:30 Okta was Tier 004:30 The response that made it worse06:00 The bill: $100M, $45M, 6 TB07:15 The Threat & Control Method09:30 What this means for you10:45 The bottom line────────────Read the full written breakdown:https://blueteam-academy.com/breaches/mgm-cyberattack-anatomy-ten-minute-breach/The Threat & Control Method explained:https://blueteam-academy.com/blog/threat-and-control-method/The Equifax Breach Files (first in the series):https://blueteam-academy.com/breaches/equifax-data-breach-explained/Thinking about moving from IT to cybersecurity? Start here:https://www2.blueteam-academy.com/from-it-to-cybersecurity/Sign up for the Keep IT Safe newsletter (weekly, no fluff):https://www2.blueteam-academy.com/keep-it-safe-signup────────────SOURCES- CISA Advisory AA23-320a — Scattered Spider: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-320a- Okta Security — Cross-tenant impersonation prevention: https://sec.okta.com/articles/2023/08/cross-tenant-impersonation-prevention-and-detection/- MGM Resorts International — Form 8-K, SEC filing, October 2023- CyberArk — The MGM Resorts Attack: Initial Analysis- U.S. District Court, District of Nevada — In re MGM Resorts International Data Breach Litigation────────────FOLLOW BLUE TEAM ACADEMYInstagram: @blueteamacadLinkedIn: /showcase/blue-team-academyX: @BlueTeamAcadThreads: @blueteamacadCybersecurity is not rocket science.#MGMbreach #MGMcyberattack #ScatteredSpider #cybersecurity #ITtoCyber #blueteam #breachfiles

  13. 176

    Cybersecurity Awareness Training: Why It Scales (& Why It Usually Doesn't)

    Cybersecurity awareness isn't a compliance checkbox—it's a security control that scales.Most organizations treat employee training like a box to check. Annual PowerPoint. Forgotten by February. Meanwhile, sophisticated threat actors are running contextual phishing, supply chain attacks, and AI-powered social engineering.In this video, we break down:✓ Why awareness training actually matters (data-driven)✓ Where most organizations fail (and how to avoid it)✓ The SANS Security Awareness Maturity Model (Stage 2 vs. Stage 5)✓ The NIST Phish Scale (measuring simulation difficulty)✓ Real metrics that tie awareness to business impact✓ How psychological safety (not punishment) changes behavior✓ Why IT professionals have an unfair advantage in building thisThe bottom line: If you've spent years in IT—managing Active Directory, troubleshooting networks, keeping systems running—you already know what "normal" looks like. That operational intuition translates directly into building effective security awareness programs that actually reduce risk.TIMESTAMPS:0:00 – Hook: What most organizations get wrong0:30 – Why IT pros have an unfair advantage2:00 – Awareness vs. Training (the distinction matters)3:30 – The threat landscape (data that matters)5:30 – Regulatory reality: GDPR, HIPAA, NIS2, and why fines are escalating6:30 – The Threat & Control Method applied to awareness - Inventory: Who are your users? - Threats: What's actually targeting you? - Controls: Design for human behavior - Scale: SANS maturity stages8:15 – Five ways awareness programs fail (and how to fix them) - The checkbox trap - One-size-fits-all training - Missing the psychology - Punitive cultures - Measuring the wrong metrics9:45 – The Human Firewall: Your distributed detection system10:45 – Frameworks that work (NIST Phish Scale + metrics)11:45 – Execution: What actually sticks12:15 – The close━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━📖 READ THE FULL ARTICLE:https://blueteam-academy.com/blog/cybersecurity-awareness-training/Full breakdown of frameworks, metrics, and execution steps.━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━🎓 KEY RESOURCES:- SANS Security Awareness Maturity Model: https://www.sans.org/information-security/research/- NIST Phish Scale: https://pages.nist.gov/phish-scale/- Verizon Data Breach Investigations Report: https://www.verizon.com/business/resources/reports/dbir/- ISC2 Cybersecurity Workforce Study: https://www.isc2.org/━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━📬 STAY CONNECTED:Follow Blue Team Academy for weekly insights on:- How IT professionals transition into cybersecurity- Security frameworks and practical applications- Why operational experience is your unfair advantageSubscribe & turn on notifications for new uploads.🔗 RELATED CONTENT:- What is Cybersecurity? How IT Pros Can Transition: [LINK]- Cybersecurity Jobs for IT Professionals: [LINK]- The Threat & Control Method Explained: [LINK]━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━📧 NEWSLETTER:For in-depth insights on IT-to-cybersecurity transitions, job market analysis, and security frameworks delivered weekly:→ Keep IT Safe Newsletter: https://www2.blueteam-academy.com/keep-it-safe-signup━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━🎯 ABOUT BLUE TEAM ACADEMY:We help IT professionals transition into cybersecurity without starting from zero.Your years of experience managing infrastructure, troubleshooting systems, and understanding operational complexity aren't a liability—they're your unfair advantage.Learn the frameworks, build the skills, and position your IT background as the asset it actually is.→ Start your transition: https://www2.blueteam-academy.com/from-it-to-cybersecurity/━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━#CybersecurityAwareness #AwarenessTraining #PhishingSimulation #SANSMaturityModel #HumanFirewall #SecurityTraining #BlueTeam #EmployeeSecurity #ITtoCyberCybersecurity is not rocket science.

  14. 175

    How to Get Into Cybersecurity From IT (The Path That Actually Works)

    Think you need to start over to break into cybersecurity? You don't. If you already work in IT, you're closer to a cybersecurity career than almost anyone else — and this video shows you exactly why.Most IT pros assume cybersecurity is a closed club that wants years of experience they don't have. The truth is the opposite: the field has a massive experience shortage, and the operational knowledge you use every day is exactly what security teams are desperate to hire.In this breakdown, we cover:- The real cybersecurity job market in 2026 — the numbers, not the hype- Why your IT background is an unfair advantage (with a real incident example)- Which cybersecurity role fits your current job — SOC, cloud, network, data, or AppSec- The mindset shift that separates IT thinking from security thinking- 4 concrete cybersecurity career pathways with realistic timelines and certs- The Threat & Control Method — a simple framework that makes you sound like a pro in interviewsThe market reality, sourced: the U.S. Bureau of Labor Statistics projects 29% job growth for information security analysts through 2034 (~16,000 openings a year), and ISC2 estimates 4.8 million cybersecurity positions sit unfilled worldwide. That gap isn't being closed by fresh graduates — it's being closed by experienced IT professionals who learn to defend the systems they already run.You're not starting from zero. You're starting from an advantage. Because cybersecurity is not rocket science.📖 Full written breakdown (roles, certs, step-by-step roadmap):https://blueteam-academy.com/blog/cybersecurity-jobs-for-it-pros-the-career-path-that-actually-works/🎯 Ready to make the move? Become a cyber pro:https://www2.blueteam-academy.com/from-it-to-cybersecurity/🔔 Follow Blue Team Academy for weekly, no-fluff guidance on the IT-to-cybersecurity transition:Instagram: @blueteamacadLinkedIn: https://linkedin.com/showcase/blue-team-academy⏱️ CHAPTERS0:00 The Email Every IT Pro Ignores0:20 Cybersecurity Isn't Closed to IT Pros1:10 The Cybersecurity Job Market in 2026 (BLS + ISC2 Data)2:30 Why Your IT Experience Is an Unfair Advantage4:00 Cybersecurity Roles: Where You Actually Fit5:30 The Security Mindset Shift7:00 4 Cybersecurity Career Pathways8:45 The Threat & Control Method (Your Interview Edge)10:30 Your First Step Into Cybersecurity#cybersecurity #cybersecuritycareer #cybersecurityjobs #ITtocyber #careerchange #keepitsafe

  15. 174

    Cybersecurity Breaches: Equifax

    In this video, I approach the Equifax breach. What happened to this company, where they failed, and how the threat actors have succeeded.I also compared our cybersecurity method, Threat & Control, and how we could improve it to maybe avoid similar attacks on our companies.

  16. 173

    What is Cybersecurity? How IT Pros Can Transition to Security

    Career transition seems to be an issue for most IT professionals, but transition to Cybersecurity may not look like a restart.Thinking of moving to cybersecurity? Check this out https://www2.blueteam-academy.com/from-it-to-cybersecurity/#whatiscybersecurity #cybersecurity

  17. 172

    What Are Cybersecurity Threats? | Blue Team Academy

    🛡️ Get ready for the digital battle! In this episode of Blue Team Academy, Fabio Sobiecki unravels the world of cybersecurity threats, from the most common dangers to the most sophisticated attacks. 🕵️‍♂️ Learn how to identify the different types of threats, such as hackers, malware and ransomware, and discover how to protect yourself against them. 🔒 In this video, you will discover: What are cybersecurity threats and how they can affect your personal and professional life The main types of threats and how they work Real cases of cyberattacks that impacted the world Practical tips to protect yourself against threats and avoid falling for scams How to turn knowledge about threats into a career opportunity in the information security field This video is for you if: You want to better understand the world of cybersecurity and protect yourself against threats You are an IT professional looking to improve your security knowledge You are thinking about pursuing a career in the information security field You want to stay up to date on the latest trends in cybersecurity Don't be a victim! Watch now and learn how to defend yourself against cyber threats! #cybersecurity #cyberthreats #informationsecurity #blueteamacademy #technology #dataprotection #hacker #malware #ransomware #podcast

  18. 171

    What is the Best Area of ​​Cybersecurity for You? | Blue Team Academy

    Are you lost in the vast world of cybersecurity, not knowing which path to take? 🤔 In this episode of Blue Team Academy, Fabio Sobiecki takes you on a complete tour of the main areas of cybersecurity, from incident response to governance and compliance. 🕵️‍♀️ Discover the advantages and challenges of each area, hear inspiring stories from professionals who have found their place in cybersecurity, and learn how to choose the specialization that best matches your talents and goals. 🚀 In this video, you will learn: - What are the most common areas of cybersecurity and what each of them does - The skills and knowledge required for each area - Tips for choosing the area that best suits you - How to build a successful career in cybersecurity, with tips on specialization, networking and mentoring This episode is for you if: - You are thinking about pursuing a career in cybersecurity, but don't know where to start - You already work in the area but want to explore other specializations - You are passionate about technology and want to make a difference by protecting the digital world - Don't waste time! Watch now and find out which area of ​​cybersecurity is best for you! #cybersecurity #career #specialization #blueteamacademy #podcast #technology #informationsecurity #itprofessional #ethicalhacker #securedevelopment

  19. 170

    Breaking into Cybersecurity: Essential Skills to Launch Your Career

    Are you ready to kickstart your career in cybersecurity? In this episode of Blue Team Academy, we dive into the essential skills you need to break into the field. Whether you're just starting out or transitioning from another role, this episode will help you understand the key technical and non-technical skills that cybersecurity professionals rely on every day. 🎯 What You'll Learn in This Episode: Core technical skills: Networking, operating systems, and security concepts Why cybersecurity isn’t just about hacking and coding The diverse career opportunities in cybersecurity and how to leverage your skills Real-world examples of how cybersecurity skills can lead to success Where to start building your skills with practical resources and certifications 🔑 Get started on your cybersecurity journey today! 🔔 Subscribe to Blue Team Academy for more episodes on building a successful career in cybersecurity! 🔗 Resources Mentioned: TryHackMe - https://tryhackme.com/ CompTIA Security+ Certification - https://www.comptia.org/certifications/security 📱 Follow Us: Twitter: https://twitter.com/fabiosobiecki LinkedIn: https://www.linkedin.com/company/69264855/ Instagram: https://instagram.com/fabiosobiecki #Cybersecurity #CybersecuritySkills #CybersecurityCareers #BlueTeamAcademy

  20. 169

    Breaking into Cybersecurity: Jobs, Opportunities, and How to Get Started

    Welcome to another episode of the Blue Team Academy podcast! In this episode, we dive deep into the world of cybersecurity and explore everything you need to know about starting a career in this rapidly growing field. Whether you're a tech enthusiast, an IT professional looking to pivot, or just curious about what cybersecurity jobs are all about, this episode is for you. We'll discuss the various roles within cybersecurity, from Security Analysts and Penetration Testers to CISOs and Cybersecurity Consultants. You'll learn what these jobs entail, the skills required, and how you can leverage your existing experience to land a job in this exciting industry. We'll also clear up common misconceptions about cybersecurity jobs, provide real-world examples of how cybersecurity professionals make a difference, and offer practical advice on how to get started. Plus, we'll share the do's and don'ts of navigating your cybersecurity career to help you avoid common pitfalls and set yourself up for success. Don't miss this episode if you're serious about breaking into cybersecurity! Be sure to like, share, and subscribe for more insights and tips on building a successful career in cybersecurity. Timestamps: 00:00 - Introduction 01:05 - What Are Cybersecurity Jobs? 09:21 - Common Misconceptions: What Cybersecurity Jobs Are Not 15:41 - Using Cybersecurity as an Opportunity 23:24 - Real Cases About Cybersecurity Jobs 32:13 - How to Start in Cybersecurity 42:25 - Do’s and Don’ts in Cybersecurity 52:25 - Closing Thoughts and Invitation to Follow 🔗 Follow Us on Social Media: X: https://x.com/fabiosobiecki LinkedIn: https://www.linkedin.com/company/69264855/ Instagram: https://www.instagram.com/fabiosobiecki/ 🎧 Listen to the Full Podcast: https://podcasters.spotify.com/pod/show/blueteamacademy 👥 Join Our Cybersecurity Community: https://discord.gg/sWAv3ymZQq

  21. 168

    Trabalho Remoto em Cibersegurança: Desafios e Oportunidades para Profissionais Modernos

    Neste vídeo, exploramos os desafios e oportunidades do trabalho remoto em cibersegurança. Discutimos a importância da segurança da informação, a necessidade de usar dispositivos corporativos e a vantagem de usar VPNs. Também falamos sobre os benefícios do home office, como maior concentração e flexibilidade de horários, além das limitações do mercado de trabalho remoto para iniciantes na área. Se você quer entender como navegar nesse cenário, este vídeo é para você! Descrição No episódio de hoje do Blue Team Academy, vamos mergulhar no mundo do trabalho remoto em cibersegurança. Com a adoção massiva do home office após a pandemia de COVID-19, entender os desafios e oportunidades dessa modalidade se tornou essencial para os profissionais de segurança da informação. 📌 Pontos discutidos: O que é trabalho remoto em cibersegurança. Desafios do trabalho remoto, como acesso físico à infraestrutura e segurança de dados confidenciais. Vantagens do home office para cibersegurança, como maior concentração e flexibilidade de horários. Cuidados essenciais, como uso de dispositivos corporativos e VPN. Realidades do mercado de trabalho remoto em cibersegurança. Se você gostou deste conteúdo, não esqueça de se inscrever no canal e deixar seu like! E para ficar por dentro de mais novidades, cadastre-se na minha newsletter e baixe gratuitamente o ebook "Conquiste sua Vaga em Segurança da Informação". No ebook, você encontrará dicas valiosas para entrevistas, como encontrar um emprego na área e o que você deve estudar para se preparar para o mercado. Acesse o link: https://blueteam-academy.com.br

  22. 167

    Construindo Fortalezas Digitais: Como Se Tornar um Arquiteto de Segurança Sem Perder a Cabeça!

    Bem-vindo a mais um episódio do Blue Team Academy! No vídeo de hoje, 'Construindo Fortalezas Digitais: Como se tornar um arquiteto de segurança sem perder a cabeça!', vamos explorar o fascinante mundo do Arquiteto de Segurança da Informação. Se você está buscando uma nova direção para sua carreira em segurança cibernética ou apenas quer entender mais sobre essa função crítica, este episódio é para você. Neste vídeo, você vai aprender: O que é um Arquiteto de Segurança da Informação e quais são suas principais responsabilidades. As habilidades técnicas e soft skills necessárias para se destacar nesta carreira. Por que esta pode ser uma oportunidade incrível para profissionais em início de carreira. Dicas valiosas para começar sua jornada e alcançar o sucesso como Arquiteto de Segurança. Não perca! Descubra como construir sua carreira e proteger os ativos digitais de qualquer organização sem perder a cabeça no processo. Gostou do conteúdo? Inscreva-se no nosso canal e ative as notificações para não perder nenhum episódio sobre segurança da informação. Quer ficar por dentro de todas as novidades? Inscreva-se na nossa newsletter e receba gratuitamente o e-book 'Conquiste sua vaga em Segurança da Informação'! Clique aqui para se inscrever: https://blueteam-academy.com.br/ Compartilhe suas dúvidas e experiências nos comentários abaixo. Adoraríamos ouvir sobre sua jornada na segurança cibernética! #ArquitetoDeSegurança #SegurançaDaInformação #CarreiraEmTI #BlueTeamAcademy #SegurançaCibernética

  23. 166

    Privacidade em Xeque: O Caso ProtonMail e a Prisão do Ativista Catalão

    Privacidade em xeque! No episódio de hoje do Blue Team Academy, mergulhamos no controverso caso do ProtonMail e a prisão de um ativista catalão. ProtonMail, conhecido por suas promessas de privacidade e segurança, enfrentou críticas após compartilhar dados de um usuário sob pedido da justiça. Entenda como um simples erro na configuração do e-mail de recuperação levou à localização e prisão do ativista, e explore as implicações deste incidente para a reputação do ProtonMail e para todos nós que valorizamos a privacidade online. Neste vídeo, você vai descobrir: O que é o ProtonMail e como ele promete proteger sua privacidade. Os detalhes do caso envolvendo o ativista catalão e a ação do ProtonMail. As implicações legais e as reações da comunidade de privacidade. Lições importantes sobre a configuração de segurança e políticas de privacidade. Não perca nenhuma atualização sobre segurança da informação! Inscreva-se na nossa newsletter e receba gratuitamente o e-book "Conquiste sua vaga em Segurança da Informação". Clique aqui para se inscrever: https://blueteam-academy.com.br Baixe o e-book gratuito agora e comece sua jornada na segurança da informação com o pé direito! #ProtonMail #PrivacidadeOnline #SegurançaDaInformação #BlueTeamAcademy

  24. 165

    Como hacker éticos não são presos por quebrarem a lei?

    Você já se perguntou por que hackers éticos não são presos, mesmo quando parecem 'quebrar a lei'? No episódio de hoje do Blue Team Academy, exploramos o fascinante mundo do hacking ético e como esses profissionais operam dentro dos limites legais para melhorar a segurança cibernética. Descubra o papel vital que os hackers éticos desempenham na proteção de sistemas e na prevenção de ataques cibernéticos, e como eles conseguem fazer isso sem enfrentar consequências legais. Neste vídeo, você aprenderá: O que é um Hacker Ético: Definimos claramente o que é ser um hacker ético e como eles diferem de hackers maliciosos. Legislação Relevante: Discutimos as leis que regulamentam a prática de hacking ético, incluindo detalhes sobre consentimento informado e contratos legais que permitem essas atividades. Casos Reais: Analisamos exemplos de hackers éticos que ajudaram empresas a descobrir e corrigir vulnerabilidades. Dicas para Aspirantes a Hackers Éticos: Orientação para aqueles que desejam seguir uma carreira em hacking ético, garantindo que suas atividades permaneçam dentro da lei. Se você está interessado em cibersegurança ou em uma carreira como hacker ético, este vídeo é imperdível. Não esqueça de clicar em 'Curtir' se você encontrar este vídeo útil, e inscreva-se em nosso canal para mais discussões informativas sobre segurança cibernética. Deixe suas perguntas ou experiências nos comentários abaixo; adoraríamos ouvir sobre suas interações com o mundo do hacking ético!

  25. 164

    Se sua empresa não está fazendo backup assim, pode estar errada

    Seja bem-vindo a mais um episódio do Blue Team Academy! Hoje, mergulhamos profundamente na essencial arte do backup de dados empresariais. Entender como proteger eficazmente os dados críticos da sua empresa é mais do que uma habilidade — é uma necessidade. Neste episódio, exploramos desde os fundamentos dos backups, passando pelas melhores práticas, até como implementar estratégias avançadas de backup que garantem a segurança e a disponibilidade dos seus dados em qualquer situação. Se você está buscando aprimorar suas habilidades em cibersegurança e deseja aprender a construir sistemas de backup robustos, este episódio é para você. Aproveite a Oportunidade para Crescer na Carreira de Segurança da Informação Está interessado em dar um grande salto na sua carreira de segurança da informação? Baixe gratuitamente o nosso e-book 'Conquiste sua vaga em Segurança da Informação'. Este recurso está repleto de insights valiosos, dicas práticas e estratégias para ajudar você a alcançar o sucesso no campo da cibersegurança. Clique aqui para baixar: https://blueteam-academy.com/ Não esqueça de se inscrever no canal e ativar as notificações para ficar por dentro dos nossos episódios semanais, repletos de informações valiosas que podem catapultar sua carreira em cibersegurança. Deixe seu like, comente suas dúvidas ou experiências com backups, e compartilhe o vídeo com colegas que também possam se beneficiar deste conhecimento. #BackupDeDados #SegurançaDaInformação #Cibersegurança #BlueTeamAcademy

  26. 163

    5 ferramentas hackers que também podem rodar no seu Windows

    Descubra as cinco principais ferramentas de segurança cibernética que todo profissional deve dominar! Este vídeo apresenta um guia prático sobre como utilizar o NMAP, Nessus, WireShark, Metasploit e Burp Suite para fortalecer sua defesa cibernética. Com demonstrações passo a passo, você aprenderá como essas ferramentas podem ajudar a identificar vulnerabilidades, monitorar redes e realizar testes de penetração eficazes. Não perca as dicas valiosas que facilitarão seu trabalho em segurança da informação. Quer aprofundar seus conhecimentos em segurança da informação e melhorar suas chances no mercado de trabalho? Baixe gratuitamente o ebook "Conquiste sua Vaga em Segurança da Informação" e obtenha dicas exclusivas sobre entrevistas, descoberta de empregos na área e estudos necessários para se destacar! Acesse https://blueteam-academy.com.br para fazer o download agora mesmo! Links para download das ferramentas mencionadas no vídeo: https://nmap.org/download.html https://www.tenable.com/products/nessus/nessus-professional https://www.wireshark.org/download.html https://www.metasploit.com/download https://portswigger.net/burp/communitydownload

  27. 162

    Estratégias Essenciais para Gestão de Vulnerabilidades

    No programa Blue Team Academy de hoje, Fábio Sobiecki mergulha profundamente no mundo da segurança da informação, oferecendo insights valiosos sobre gestão de vulnerabilidades. Com um foco na importância de identificar, classificar, remediar e mitigar vulnerabilidades em softwares e processos, Sobiecki destaca o papel crítico deste processo contínuo na proteção das empresas contra ataques cibernéticos. Além disso, ele aborda a relevância de ferramentas de detecção de vulnerabilidades, estratégias de remediação e a necessidade de uma abordagem baseada em risco para priorizar as ações de segurança. Acompanhado de dicas práticas para iniciar a gestão de vulnerabilidades eficazmente, este episódio é um recurso essencial para profissionais e entusiastas da área. Bem-vindos ao Blue Team Academy! Neste episódio especial, Fábio Sobiecki nos guia pela crucial área de gestão de vulnerabilidades, explicando seu impacto na segurança das organizações e como efetivamente protegê-las. Discutindo desde a identificação de vulnerabilidades até as estratégias para sua mitigação, Sobiecki oferece um olhar aprofundado sobre como manter sistemas e dados seguros. Além disso, compartilha dicas valiosas para quem busca ingressar ou se desenvolver na carreira de cibersegurança. Não perca a chance de aprimorar seu conhecimento e proteger melhor sua empresa contra as ameaças digitais. Quer aprofundar seus conhecimentos em cibersegurança e aprender como proteger sua empresa contra vulnerabilidades? Acesse o curso da Blue Team Academy em https://blueteam-academy.com.br/curso-formacao-bta e comece hoje mesmo sua jornada para se tornar um especialista em segurança da informação!

  28. 161

    Dominando o NIST Cybersecurity Framework 2.0: O Que Mudou e Como Aplicar na Sua Organização

    Bem-vindo ao episódio de hoje do Blue Team Academy, onde mergulhamos profundamente no recém-lançado NIST Cybersecurity Framework 2.0 (CSF 2.0) e exploramos como ele pode revolucionar a segurança cibernética na sua organização. Se você é um profissional iniciante em cibersegurança ou já tem experiência na área, este episódio é essencial para entender as novidades que o CSF 2.0 traz e como implementá-lo efetivamente. Neste episódio, cobrimos os fundamentos do CSF 2.0, incluindo as adições e ajustes feitos desde a versão anterior. Discutiremos a nova função "Govern", a importância reforçada da gestão de riscos de cadeia de suprimentos e as estratégias para uma implementação bem-sucedida, garantindo que sua organização não apenas atenda aos padrões atuais, mas também esteja preparada para os desafios futuros de segurança cibernética. Além disso, oferecemos insights valiosos de especialistas em segurança cibernética e compartilhamos estudos de caso reais de organizações que já estão implementando o CSF 2.0. Eles compartilharão suas experiências, os desafios enfrentados e como superá-los, oferecendo dicas práticas que você pode começar a aplicar hoje mesmo. Não importa se sua organização é pequena ou grande, o CSF 2.0 é uma ferramenta flexível projetada para ajudar a melhorar a segurança em todos os níveis. Assista a este episódio para descobrir como você pode utilizar o CSF 2.0 para fortalecer a postura de segurança da sua empresa, melhorar a resiliência cibernética e promover uma cultura de segurança consciente e proativa. Junte-se a nós no Blue Team Academy para se manter à frente das ameaças cibernéticas e transformar a segurança da sua organização com o NIST Cybersecurity Framework 2.0. Não esqueça de curtir, comentar com suas dúvidas ou experiências e se inscrever no nosso canal para mais conteúdo valioso sobre segurança da informação. Até lá, mantenha-se seguro e informado! #BlueTeamAcademy #CSF20 #NIST #Cibersegurança #SegurançaDigital #FrameworkDeSegurança

  29. 160

    Segredos Revelados: Como Fortalecer Sua Postura de Segurança

    Bem-vindos a mais um episódio revelador do Blue Team Academy, onde desvendamos os mistérios da cibersegurança para proteger o que mais importa no seu mundo digital. Hoje, embarcamos em uma jornada crítica: melhorar sua postura de segurança. Neste episódio, mergulharemos fundo nas estratégias essenciais e nas ações práticas que empresas e profissionais podem adotar para fortalecer suas defesas contra as crescentes ameaças cibernéticas. Descubra como transformar sua organização em uma verdadeira fortaleza digital, aprendendo a identificar vulnerabilidades, implementar políticas robustas de segurança e cultivar uma cultura de conscientização que resista aos ataques mais sofisticados. Com insights de especialistas líderes na área e estudos de caso inspiradores, revelaremos: As avaliações de risco que você não pode ignorar. Estratégias de treinamento em conscientização de segurança que realmente funcionam. Ações imediatas para elevar sua postura de segurança hoje mesmo. Seja você um profissional de segurança da informação em início de carreira ou um gestor buscando proteger sua empresa, este episódio oferece o conhecimento necessário para dar um salto qualitativo na sua postura de segurança. Não perca a chance de se armar com as melhores práticas e tecnologias que farão a diferença no combate à ciberameaças. Sintonize agora e transforme a segurança da sua empresa de um ponto de interrogação para um ponto de exclamação! Assine minha newsletter no rodapé do site konnio.com

  30. 159

    O jogo de xadrez da cybersegurança: estratégias avançadas para red & blue

    Neste episódio, exploramos o dinâmico campo da cibersegurança, comparado a um jogo de xadrez onde equipes de Red e Blue desempenham papéis críticos na defesa e simulação de ataques cibernéticos. O Red Team foca em testar as defesas, utilizando uma gama de métodos e ferramentas, como phishing e Kali Linux, para identificar vulnerabilidades e aprimorar as medidas de segurança. Por outro lado, o Blue Team é responsável pela detecção, resposta e mitigação de ameaças, empregando tecnologias como inteligência artificial para melhorar a eficácia de suas estratégias. Jogos de guerra cibernéticos são destacados como exercícios essenciais, permitindo que as equipes simulem ataques em ambientes controlados, identifiquem lacunas nas defesas e aprimorem suas habilidades de detecção e resposta. A colaboração e o aprendizado contínuo entre as equipes, juntamente com o uso de tecnologias avançadas e o compromisso com a educação contínua, são enfatizados como elementos críticos para fortalecer a segurança digital e proteger os ativos digitais contra ameaças cibernéticas emergentes e futuras.

  31. 158

    Blindagem Digital: Como Pequenas Empresas no Brasil Estão Virando o Jogo Contra Hackers

    Neste episódio especial da Blue Team Academy, mergulhamos no mundo invisível da cibersegurança, revelando como pequenas empresas brasileiras estão transformando suas vulnerabilidades em fortalezas digitais. À medida que os ataques cibernéticos se tornam cada vez mais sofisticados, descubra as estratégias inovadoras e acessíveis que negócios de menor porte estão adotando para se protegerem contra hackers. Da implementação de treinamentos de conscientização em segurança até a adoção de tecnologias de ponta para a defesa de dados, exploramos casos inspiradores e oferecemos insights valiosos que podem ser a chave para blindar sua empresa na era digital. Se você é um futuro profissional de segurança da informação ou está no início de sua carreira, prepare-se para desvendar os segredos de como pequenas empresas estão navegando com sucesso no complexo cenário de ameaças cibernéticas. Não perca a chance de fortalecer suas defesas e garantir a segurança dos seus dados mais preciosos. Assista agora e transforme a segurança da informação da sua empresa!

  32. 157

    Decifrando o COBIT: Como ele te ajuda na Segurança das Empresas

    Neste episódio, discutimos o COBIT (Control Objectives for Information and Related Technologies), um framework crucial na área de Tecnologia da Informação. Exploramos seus princípios, aplicabilidade na segurança da informação e benefícios para profissionais dessa área. Vamos abordar o COBIT (Control Objectives for Information and Related Technologies), um framework essencial na área de Tecnologia da Informação. Como sempre, trago informações valiosas para quem está interessado em segurança da informação e quer aprimorar sua carreira nesse campo. Se você deseja entender como o COBIT pode ser integrado à segurança da informação e como isso pode beneficiar sua empresa ou sua trajetória profissional, este vídeo é para você!

  33. 156

    Desvendando os Segredos e Defesas Contra Ataques de Rainbow Table

    Você já ouviu falar sobre Ataques de Rainbow Table, mas sabe realmente o que se esconde por trás dessa técnica que soa tão colorida? No episódio de hoje de 'Blue Team Academy', mergulhamos profundamente nas entranhas dos Ataques de Rainbow Table, uma das ferramentas mais astutas e perigosas no arsenal de hackers. Descubra como esta técnica pode representar uma ameaça séria à segurança de suas senhas e dados mais preciosos. Vamos explorar não apenas como esses ataques funcionam, mas também como você pode se blindar contra eles, adotando práticas de segurança inovadoras e robustas. Se você se preocupa com a segurança cibernética, este é um episódio que não pode perder. Prepare-se para ter sua curiosidade saciada e equipar-se com o conhecimento para proteger sua empresa contra um dos métodos de ataque mais intrigantes do mundo digital. Sintonize conosco e transforme sua preocupação em ação!

  34. 155

    Primeiros Passos em Threat Intelligence: Orientações para Profissionais Iniciantes

    Neste vídeo, Fabio Sobiecki, um especialista em segurança da informação, introduz o conceito de "Threat Intelligence" (Inteligência de Ameaças) e como ele é crucial na prevenção de ataques cibernéticos. Ele explora casos práticos, aborda a importância da análise e correlação de dados, e diferencia "Threat Intelligence" de gerenciamento de incidentes e coleta de dados. A discussão é voltada tanto para profissionais da área quanto para quem deseja ingressar na carreira.

  35. 154

    Será que ainda vale a pena ter certificação CISSP hoje em dia?

    A certificação CISSP já foi citada como a principal ou mais desejada certificação profissional para segurança da informação. Parece que seu reinado está ameaçado, a medida que novas certificações de produto e profissionais são desenvolvidadas. Mas hoje, Fabio Sobiecki, que é certificado CISSP, nos fala sobre esta dúvida que permeia vários novos profissionais de segurança da informação. Junte-se a nós neste debate e comente sua opinião.

  36. 153

    5 motivos para você se tornar profissional de cibersegurança ainda em 2024

    A cada virada de ano, nós costumamos fazer promessas para este novo ciclo e provavelmente você deve estar pensando que em 2024 você quer se tornar profissional de segurança da informação. Neste vídeo, vamos discutir e te dar 5 motivadores para você seguir este objetivo de se preparar, profissionalmente e pessoalmente para encarar o desafio de concluir o ano, empregado em segurança da informação.

  37. 152

    Como fazer segurança da informação em criptomoedas

    As criptomoedas estão em evidência por que muitas pessoas físicas e até jurídicas estão começando a trabalhar com isso, e precisam assegurar suas auto-custódias. Óbviamente não é um tutorial de como fazer a segurança de carteiras, mas é uma visão sobre os cuidados que nós profissionais temos que ter sobre carteiras de criptomoedas.

  38. 151

    Passwordless, sem senha ou menos senha?

    A palavra da moda é "passwordless", mas tenho visto muitos fabricantes fazendo isso errado e consequentemente os profissionais de segurança da informação entram nessa. Afinal, passwordless é diminiuir o uso de senhas ou eliminar 100% as senhas dos seus ambientes? Já é sabido que as senhas colocam empresas e usuários em risco, por que compartilham, usam senhas fracas, reutilizam senhas. Como você poderá garantir a segurança da sua empresa, se o seu próprio colaborador ou parceiro não te ajuda?

  39. 150

    Forense computacional, ainda é uma opção de carreira?

    Será que vale a pena investir seu tempo para conhecer e se aprofundar para se tornar um profissional de forense computacional? Apesar de ser o sonho de muitos jovens que buscam começar na carreira de segurança da informação, a opçao de forense computacional pode se tornar um nicho de mercado onde a oferta é escassa. Neste episódio eu vou mostrar alguns pontos desta especialidade e por que está se tornando algo raro.

  40. 149

    Como montar seu lab de testes para ferramentas de cibersegurança?

    Você sabe, mas vale a pena lembrar. NUNCA teste produtos de segurança em ambientes reais. Além de ser crime, você pode causar danos severos e pode correr riscos desnecessários. Para isto, temos recursos bem dinâmicos e acessíveis para montar ambinetes separados, segregados e vulneráveis para executar todos os testes que você precisa. Além disso, Fabio fala sobre como faz para buscar ferramentas e onde buscar ajuda na hora de instalar um produto de segurança e também configurar corretamente este produto sem perder tempo. Por algum motivo, o episódio em vídeo não está sendo aceito pela plataforma Spotify.

  41. 148

    Relatório de Força de Trabalho da (ISC)2 2023

    O relatório de Força de Trabalho em Segurança da Informação já está disponível e vamos aqui discutir os pontos chave deste documento. Para que serve este relatório? Quem gera o relatório? De onde eles tiram estas informações? Estas e outras dúvidas serão respondidas por mim aqui então começa logo a ver este episódio que está demais.

  42. 147

    Como criar ou atualizar sua política de segurança da informação

    Ter uma política de segurança da informação, para muitos é o primeiro passo de organização da área em uma empresa. Mas vamos ver neste episódio que não se começa por aí, até mesmo por que muitas empresas já possuem políticas defasadas ou que ninguém sabe ou conhece. Como profissional de segurança da informação, você deve zelar pela atualização deste documento e utilizá-lo no dia-a-dia como um caderno de combinados entre você que protege a empresa e os funcionários que utilizam os dados diariamente.

  43. 146

    Por quê você deve começar hoje mesmo a registrar o histórico de incidentes da sua empresa

    Ninguém gosta de incidentes de segurança, pelo menos não os profissionais de segurança da informação, que pensa na proteção da empresa. Mas, depois do problema resolvido, uma coisa muito importante e que muitas vezes é deixada de lado é o registro de incidentes e a coleta de evidências. Neste episódio de Blue Team Academy, eu discuto com vocês sobre a documentação de incidentes de segurança, por que fazê-lo, como fazê-lo e as oportunidades que você terá, tendo isto registrado.

  44. 145

    Carreira de Analista ou de consultor? O que é melhor?

    Para quem está começando na carreira, você vai se deparar com escolhas entre analista ou consultor. O que faz mais sentido? O que é melhor? Tudo isso vai depender de uma série de fatores que você vai ter que avaliar. O mais importante é que sua carreira precisa de um norte e eu te explico aqui quem deve estar no comando da sua carreira. #SegurançadaInformação #cibersegurança

  45. 144

    Entenda se a área de segurança é mesmo competitiva

    Em muitos casos a competitividade no trabalho pode ser um problema que vai causar impacto na vida e saúde do profissional. Sabemos que em algumas carreiras, ganha-se bem mas é uma vida cheia de stress ou onde o ritmo de trabalho é alto com plantões de longo tempo ou trabalhos noturnos. Não que isso não aconteça também em tecnologia, sabemos que algumas pessoas tem que virar a noite, mas o fato de não ser uma rotina ajuda. Mas afinal, a carreira dos profissionais de segurança da informação é muito competitiva ou não? Será que vamos brigar por vagas ou alguma outra coisa? Veja neste episódio de Blue Team Academy. #FabioSobiecki #BlueTeamAcademy #SegurançadaInformação

  46. 143

    Usando OSINT e Geolocalização para descobrir informações

    As técnicas de pesquisa em bases abertas estão cada vez mais abrangentes e podem ofererecer riscos à empresas. Vejam estes exemplos onde pessoas postam fotos nas redes sociais e é possível encontrar o endereço exato do local onde a pessoa estava. #FabioSobiecki #BlueTeamAcademy #SegurançadaInformação

  47. 142

    Reagindo ao Hacking na Web - Rafael Sousa

    Para a alegria de um total de 2 pessoas, trago a vocês mais um react de CTF, a exemplo do que fizemos com o Bruno Fraga do Técnicas de Invasão. A vítima da vez é o Rafael Sousa, do canal Hacking na Web, se você não segue acompanha lá que vale a pena. O Rafael resolveu um CTF do TryHackMe e mostrou para nós aqui como fazer e como sempre eu vou comentando aqui como proteger ou como você pode evitar que falhas e vulnerabilidades como estas do CTF estejam presentes na sua empresa. #FabioSobiecki #BlueTeamAcademy #SegurançadaInformação

  48. 141

    Rinha de Contratação: CLT vs PJ e trabalhos no Exterior

    O objetivo deste episódio é apenas de explicar algumas diferenças que existe entre os dois modelos de contratação mais comuns em segurança da informação. De um lado os CLTs com suas vantagens e desvantagens. Tem até uma torcida cativa e pessoas que o odeia. Do outro lado, os PJs, queridinho de alguns profissionais que já não abrem mão de voltar ao regime antigo. Seja qual for sua torcida, vale a pena assistir este episódio e saber diferenças e como é trabalhar no Exterior. #FabioSobiecki #BlueTeamAcademy #SegurançadaInformação

  49. 140

    Onde foram parar os empregos de Segurança da Informação?

    Hoje eu abordo um tema solicitado pelo espectador Hashib, que pergunta onde estão os empregos que todo mundo fala de segurança da informação. Ele não foi específico no comentário em que tipo de vagas ele está buscando então eu pesquisei uma série delas e dados estatísticos para testar a tese se está ou não está faltando vagas no mercado de segurança. Veja também dicas de como você pode buscar vagas que se encaixam melhor no seu perfil e como buscar oportunidades neste mercado. #FabioSobiecki #BlueTeamAcademy #SegurançadaInformação

  50. 139

    Weak Cipher, qual é o problema e como resolver

    Este problema aparece de vez em quando em um resultado de scanner de vulnerabilidades, e logo a área de pentest vem com o apontamento. Mas o que de fato significa isso, é um problema de criptografia? Como podemos gerenciar isso e mudar nossa configuração para algo mais seguro. E se você não curte criptografia, acha difícil, vem comigo por que eu expliquei com bastante didática hoje. #FabioSobiecki #BlueTeamAcademy #SegurançadaInformação

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Um podcast para você quer proteger empresas e pessoas de ataques hackers

HOSTED BY

Fabio Sobiecki

CATEGORIES

Frequently Asked Questions

How many episodes does Blue Team Academy have?

Blue Team Academy currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is Blue Team Academy about?

Um podcast para você quer proteger empresas e pessoas de ataques hackers

How often does Blue Team Academy release new episodes?

Blue Team Academy has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to Blue Team Academy?

You can listen to Blue Team Academy on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts Blue Team Academy?

Blue Team Academy is created and hosted by Fabio Sobiecki.
URL copied to clipboard!