
Hosted by Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos
A twice-monthly podcast dedicated to all things relating to Security, Privacy, Compliance and Reliability on the Microsoft Cloud Platform. Hosted by Microsoft security experts, Michael Howard, Sarah Young, Gladys Rodriguez and Mark Simos. ©2020-2025 Michael Howard, Sarah Young, Gladys Rodriquez, and Mark Simos.
128 episodes · publishes fortnightly · latest 2026-06-12 · ~37 min/episode
Rank
#175
Substance
81.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#175 of 6183
Substance
Top 3%
outscores 97% of the index
The Azure Security Podcast ranks #175 on The B2B Podcast Index with a substance score of 81.0 out of 100, scored across 5 recent episodes. It scores highest on guest caliber and insight density. Michael is a seasoned Microsoft security engineer with demonstrated Red Team and cryptography SDL background; Jack Richens leads Microsoft's post-quantum transition team and manages Azure Key Management (Key Vault, HSM products). Both are genuine practitioners at scale with deep organizational context. However, neither are pioneering cryptography researchers or independent industry authorities - they are implementation and deployment specialists working within Microsoft's ecosystem. Their value is practical and organizational rather than foundational research.
Averaged across 5 recently scored episodes, with cited evidence.
The episode contains substantive technical content on post-quantum cryptography fundamentals, threat timeline, and transition strategies. However, significant portions consist of basic explanations and analogies (chess knights, multiverse, two-man rule) that are accessible but not densely packed with novel insights. The content on harvest-now-decrypt-later, Mosca's theorem, and algorithm specifics (MLKEM, MLDSA, lattice mathematics) adds value, but the episode dedicates substantial time to remedial cryptography education and day-in-the-life anecdotes that dilute insight density.
“The real problem, what it really boils down to, is that you use asymmetric crypto to wrap a symmetric key, like AES. Those keys are for the most part okay. But it's the asymmetric keys that become real problems.”
“There's this attack called harvest now, decrypt later, where people could just harvest network traffic or capture stolen encrypted data, and it would still have high value years later.”
The episode relies heavily on established frameworks and publicly known information (NIST CNSA 2.0, Shor's algorithm, hybrid encryption rationale). While the guests add practical Microsoft context and useful segmentation (data in transit/at rest/cryptographic trust), the core conceptual material is well-trodden in security circles. The Y2K analogy, the two-man rule framing, and the focus on crypto agility are sensible but not contrarian or first-principles thinking. The discussion of IoT device triaging and cost-benefit analysis adds some practical originality.
“It's a lot like the Y2K problem. It's coming up whether we like it or not.”
“Do some kind of hybrid composite scheme where you have to break both a traditional algorithm that is a known quantity and resilient against traditional computers, and you have to break the quantum-resistant algorithm.”
Michael is a seasoned Microsoft security engineer with demonstrated Red Team and cryptography SDL background; Jack Richens leads Microsoft's post-quantum transition team and manages Azure Key Management (Key Vault, HSM products). Both are genuine practitioners at scale with deep organizational context. However, neither are pioneering cryptography researchers or independent industry authorities - they are implementation and deployment specialists working within Microsoft's ecosystem. Their value is practical and organizational rather than foundational research.
“Michael, let's start off. You are now focused on post-quantum computing.”
“Jack Richens. I am the lead for the post-quantum transition team. But my other hat is I manage the Azure security key management team.”
The episode references specific algorithms (MLKEM, MLDSA, SLHDSA, LMS), cites NIST CNSA 2.0 and Q date concept, and names products (SimCrypt, S-Channel, Azure Key Vault, Managed HSM). However, concrete numerical evidence is sparse: no specific performance metrics, no precise size comparisons of signatures/ciphertexts, no timeline data beyond the vague "2030" estimate, no dollar figures or deployment statistics. The discussion of packet fragmentation and TLS handshake impacts is qualitative without metrics. Examples are mostly generic ("CA route rotations", "IoT leak sensors") rather than specific case studies.
“It could happen in 2030, that we could have a cryptographically relevant quantum computer.”
“NIST and NSA, they've made statements around a lot of government data needs to be protected for 10 to 15 years.”
The host asks reasonable setup questions and provides some structure, but rarely pushes back or challenges claims. When guests make assertions (e.g., size issues are manageable, standards are ready), there is minimal probing. The host occasionally asks follow-ups ("Who wants to say the bad news?") but these are soft. There are tangential personal asides (coffee-making, workout timing) that consume airtime without adding substance. The host does attempt to segue into practical frameworks (data in transit/at rest/cryptographic trust), which shows some craft, but the conversation lacks the rigor of genuinely exploratory dialogue where counterarguments or tensions are explored.
“Michael, anything I ... well it's anything right it's not just it's not just like communications”
“Can you talk a little bit about like which algorithms people should be looking for?”
2026-06-02
2026-04-30
2026-02-27
First period on the Index - history builds from here.
10 scored on substance · 60 tracked in total.
Episode 129: John Savill's Top of Mind
2026-06-12 · 43 min
Episode 128: Post Quantum Cryptography
2026-06-02 · 55 min
Episode 127: Threat intel update and AI
2026-04-30 · 36 min
Episode 126: Microsoft Baseline Security Mode
2026-03-21 · 36 min
Episode 125: Origins of MITRE ATT&CK
2026-02-27 · 35 min
Episode 124: Microsoft Security Response Center for AI
2026-01-30 · 29 min
Episode 123: Agentic Identity
2026-01-21 · 36 min
Episode 122: Microsoft Ignite 2025 Wrap-up
2025-12-15 · 33 min
Episode 121: New Open Group Security Standards Documentation
2025-11-21 · 48 min
Episode 120: The Zero Trust Workshop (and so much more!)
2025-10-29 · 59 min
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/the-azure-security-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/the-azure-security-podcast/badge.svg" alt="Ranked #26 on The B2B Podcast Index" width="360" height="136" />
</a>Track The Azure Security Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.