
technologyJul 24, 202437:49pending
Craig Nelson on Simulating Attacks with Microsoft’s Red Team
About this episode
Craig Nelson, leader of Microsoft's Red Team joins Nic Fillingham and Wendy Zenone on this week's episode of The BlueHat Podcast. Craig explains how the Red Team simulates attacks on Microsoft's infrastructure to identify vulnerabilities and protect customer data stored in the cloud. He emphasizes the importance of these simulated attacks in preparing for real threats and describes the collaborative efforts with other security teams at Microsoft, such as the Azure penetration testing team and the Microsoft Security Response Center. Craig shares his personal journey into cybersecurity, highlighting his early fascination with cryptography and computer security. He also discusses the unique challenges and strategies of Red Teaming at Microsoft, including the need to influence engineering teams and the importance of systemic thinking to create durable security solutions.
In This Episode You Will Learn:
The need for early detection of vulnerabilities during the development lifecycle
Why a mix of technical and persuasive skill build successful red teams
Significance of internal security education and training initiatives
Some Questions We Ask:
What projects are you pursuing in AI and security?
How do you have conversations with engineers to influence their security decisions?
What skills are important for someone aspiring to join the Red Team?
Resources:
View Craig Nelson on LinkedIn
View Wendy Zenone on LinkedIn
View Nic Fillingham on LinkedIn
Related Microsoft Podcasts:
Microsoft Threat Intelligence Podcast
Afternoon Cyber Tea with Ann Johnson
Uncovering Hidden Risks
Discover and follow other Microsoft podcasts at microsoft.com/podcasts
Get every episode summarized
Each time The BlueHat Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The BlueHat Podcast

Hunting Variants: Finding the Bugs Behind the Bug
The BlueHat Podcast
Jul 9, 202539:00pending

Securing Redirections with Mike Macelletti
The BlueHat Podcast
Jun 25, 202542:02pending

Ignore Ram Shankar Siva Kumar’s Previous Directions
The BlueHat Podcast
Jun 11, 202539:54pending

Protecting AI at the Edge with David Weston
The BlueHat Podcast
May 28, 202539:15pending