Mark's List

Mark's List

...of Cybersecurity resources frequently sent to customers and colleagues (Last updated December 2025). https://aka.ms/markslist | Twitter: @MarkSimos | Bluesky: @markasimos.bsky.social

Share and enjoy!

Recent Updates

The Open Group Standards

These standards provide clear vendor neutral guidance for Security and Zero Trust.

Microsoft Security Adoption Framework (SAF)

Article content
Microsoft Security Adoption Framework (SAF)

Microsoft SAF provides overall guidance for security strategy and architecture that enable a modern and effective security approach using Microsoft technology.

Article content
Microsoft SAF Workshops

These take the form of workshops available to all Microsoft Unified customers as well as several related/derived works that are published publicly:

If you are interested in any of these workshops, contact your Microsoft representative (customer success account manager)

The Zero Trust Playbook (Series)

I am coauthoring this series of books that provides role by role guidance to adopt a complete Zero Trust approach across business, technology, and security teams using a 6-stage plan.

The first book in the series, Zero Trust Overview and Playbook Introduction, is available now on Amazon, and book subscriptions from Packt, O'Reilly, and others.

Article content
Zero Trust Playbook Series - Book 1

Additional Guidance from Microsoft and Others

Threat Intelligence / Recent Events

  • Microsoft Digital Defense Report (MDDR) - current analysis of threat landscape - https://aka.ms/MDDR

Privileged Access and Identity

Ransomware, Extortion, and Destructive attacks

  • Security Guidance - Detailed mitigation plan for attacks including Objectives and Key Results (OKRs) for 10 security initiatives, links to technical procedures, recommended team members, checklists, and more 

No alt text provided for this image

  • Backup Guidance - Backup and restore guidance to ensure you can rapidly continue business operations after these attacks (which intentionally target backups)

Microsoft Ninja Training

This is technical training for various Microsoft security technologies

Article content

Zero Trust Resources

Security Operations (SecOps) / [Center] (SOC)

Incident Response and Recovery

Operational Technology (OT) Security

Enterprise Patch Management

Cloud Security, Benchmarks, and recommended configurations


I can't believe I'm just finding this now! What a great list, Mark! Not even halfway through and I've already found excellent resources I've not heard about before.

Like
Reply

Hey mark just found this gem of security resources, Thanks!

Like
Reply

Have watched your "Making end to end security real" session at Seattle Ignite. This directed me to this very brilliant collection of cybersec information at one place. Thank you!

Like
Reply

Cannot see this video "Security Return on Investment (ROI) Video (1.5 minutes)", getting below error Video unavailable This video is private

Like
Reply

Great collection of resources. Thanks!

Like
Reply

To view or add a comment, sign in

More articles by Mark Simos

  • Security Roles and Glossary

    Fixing Security Accountabilities and Responsibilities from the boardroom to CEOs, CISOs, CIOs, technologists, analysts,…

    7 Comments
  • Security and Zero Trust at The Open Group

    This article provides an overview of resources available from The Open Group you can use to: Improve or transform…

    1 Comment
  • Words Matter - What is threat data vs. intelligence?

    As we have been working through the standards for the threat intelligence roles in security operations (SecOps/SOC), we…

    5 Comments
  • People Matter - Security Operations Roles

    This is proposed text I am working on for Security Operations (SecOps/SOC) roles and responsibilities for the upcoming…

    18 Comments
  • Clarity Matters: Identity and Access Capabilities

    I am working on a proposed revision to the Zero Trust Reference Model from The Open Group and wanted to get your…

    6 Comments
  • Words Matter #3 - Incident, Compromise, and Breach

    The Open Group is working on updated definitions for various Security and Zero Trust terms for an upcoming security…

    20 Comments
  • Security Roles and Responsibilities

    Security is a team sport across the organization Updated 11-20-2025 to add download links for draft standards If you…

    12 Comments
  • Words Matter #2 - Security Policy and Security Policy exception

    The Open Group is working on updated definitions for various Security and Zero Trust terms for an upcoming security…

    10 Comments
  • Words Matter: Trust and Trustworthiness

    What is Trust? Do we really need Zero of it? What about Trusting AI? The Open Group is working on updated definitions…

    26 Comments
  • Security Roles

    Nikhil Kumar and I found that we had to create a list of roles impacted by cybersecurity for the Zero Trust Playbook…

    1 Comment

Explore content categories