How to pragmatically implement a host based firewall on workstations to 1) protect machines while off the corporate network and 2) prevent lateral movement while on the corporate network. How to build the policy, an example policy, how to ensure its effective (nmap, bloodhound etc) link it to the mitre attack framework, next steps etc.