22Sami Laiho
“The blue team plays against the red team, like in military exercises.”
Twitter: @samilaiho • Website: 4sysops.com/members/sami-laiho and samilaiho.com
Sami Laiho is one of the world's leading professionals for the Windows OS and security. Sami has been working with and teaching OS troubleshooting, management, and security since 1996. In 2019 Sami was chosen by TiVi magazine as one of the top 100 influencers in IT in Finland. He is the 11th most followed person on Twitter in his field in Finland.
At Microsoft Ignite 2018, Sami's “Behind the Scenes: How to Build a Conference-Winning Session” and “Sami Laiho: 45 Life Hacks of Windows OS in 45 Minutes” sessions were ranked as #1 and #2 out of 1,708 sessions. This was the first time in the history of the conference that anyone has been able to do this.
How do you define a blue team?
The blue team's focus is to defend the organization from digital/cyberattacks. Basically it includes anything that defends the company from an enemy, but this usually refers to cybersecurity. The blue team plays against the red team, like in military exercises.
What are two core capabilities that a blue team should have?
- Good knowledge/inventory of hardware and software assets so that they know what to secure
- Trained skills on what to do when an incident happens
What are some of the key strengths of an incident response program?
The ...