Talking with team implementing network policy, 80-90% of red teamers and actual attackers can be stopped with two simple rules:

Default deny ingress – If they can’t get in, they can’t start

Default deny egress – If they do get in, they can't take things back out

Comments