Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#159
February 12, 2024

EP159 Workspace Security: Built for the Modern Threat. But How?

Guest:

27:27

Topics covered:

  • Workspace makes the claim that unlike other productivity suites available today, it’s architectured for the modern threat landscape. That’s a big claim! What gives Google the ability to make this claim?
  • Workspace environments would have many different types of data, some very sensitive. What are some of the common challenges with controlling access to data and protecting data in hybrid work? 
  • What are some of the common mistakes you see customers making with Workspace security?
  • What are some of the ways context aware access and DLP (now SDP) help with this?
  • What are the cool future plans for DLP and CAA?
#158
February 5, 2024

EP158 Ghostbusters for the Cloud: Who You Gonna Call for Cloud Forensics

Guest:

29:29

Topics covered:

  • Could you share a bit about when you get pulled into incidents and what are your goals when you are?
  • How does that change in the cloud? How do you establish a chain of custody and prove it for law enforcement, if needed?
  • What tooling do you rely on for cloud forensics and is that tooling available to "normal people"? 
  • How do we at Google know when it’s time to call for help, and how should our customers know that it’s time? 
  • Can I quote Ray Parker Jr and ask, who you gonna call?
  • What’s your advice to a security leader on how to “prepare for the inevitable” in this context? 
  • Cloud forensics - is it easier or harder than the 1990s classic forensics?
#157
January 29, 2024

EP157 Decoding CDR & CIRA: What Happens When SecOps Meets Cloud

Guest:

27:27

Topics covered:

  • How does Cloud Detection and Response (CDR) differ from traditional, on-premises detection and response?
  • What are the key challenges of cloud detection and response?
  • Often we lift and shift our teams to Cloud, and not always for bad reasons, so  what’s your advice on how to teach the old dogs new tricks: “on-premise-trained” D&R teams and cloud D&R?
  • What is this new CIRA thing that Gartner just cooked up?  Should CIRA exist as a separate market or technology or is this just a slice of CDR or even SIEM perhaps?
  • What do you tell people who say that “SIEM is their CDR”?
  • What are the key roles and responsibilities of the CDR team? How is the cloud D&R process related to DevOps and cloud-style IT processes?
#156
January 22, 2024

EP156 Living Off the Land and Attacking Critical Infrastructure: Mandiant Incident Deep Dive

Guest:

29:29

Topics covered:

  • Could you give us a brief overview of what this power disruption incident was about?
  • This incident involved both Living Off the Land and attacks on operational technology (OT). Could you explain to our audience what these mean and what the attacker did here?
  • We also saw a wiper used to hide forensics, is that common these days?
  • Did the attacker risk tipping their hand about upcoming physical attacks? If we’d seen this intrusion earlier, might we have understood the attacker’s next moves?
  • How did your team establish robust attribution in this case, and how they do it in general? How sure are we, really? 
  • Could you share how this came about and maybe some of the highlights in our relationship helping defend that country?
#155
January 15, 2024

EP155 Cyber, Geopolitics, AI, Cloud - All in One Book?

Guests:

  • Derek Reveron, Professor and Chair of National Security at the US Naval War College
  • John Savage, An Wang Professor Emeritus of Computer Science of Brown University
29:59

Topics covered:

  • You wrote a book on cyber and war, how did this come about and what did you most enjoy learning from the other during the writing process?
  • Is generative AI going to be a game changer in international relations and war, or is it just another tool?
  • You also touch briefly on lethal autonomous weapons systems and ethics–that feels like the genie is right in the very neck of the bottle right now, is it too late?
  • Aside from this book, and the awesome course you offered at Brown that sparked Tim’s interest in this field, how can we democratize this space better? 
  • How does the emergence and shift to Cloud impact security in the cyber age?
  • What are your thoughts on the intersection of Cloud as a set of technologies and operating model and state security (like sovereignty)? Does Cloud make espionage harder or easier? 
#154
January 8, 2024

EP154 Mike Schiffman: from Blueboxing to LLMs via Network Security at Google

Guest:

29:29

Topics covered:

  • Given your impressive and interesting history, tell us a few things about yourself?
  • What are the biggest challenges facing network security today based on your experience?
  • You came to Google to work on Network Security challenges. What are some of the surprising ones you’ve uncovered here?
  • What lessons from Google's approach to network security absolutely don’t apply to others? Which ones perhaps do?
  • If you have to explain the difference between network security in the cloud and on-premise, what comes to mind first?
  • How do we balance better encryption with better network security monitoring and detection?
  • Speaking of challenges in cryptography, we’re all getting fired up about post-quantum and network security. Could you give us the maybe 5 minute teaser version of this because we have an upcoming episode dedicated to this?
  • We hear you have some interesting insight on LLMs, something to do with blueboxing or something. What is that about?
#153
December 18, 2023

EP153 Kevin Mandia on Cloud Breaches: New Threat Actors, Old Mistakes, and Lessons for All

Guest:

29:29

Topics covered:

  • When you look back, what were the most surprising cloud breaches in 2023, and what can we learn from them? How were they different from the “old world” of on-prem breaches? 
  • For a long time it’s felt like incident response has been an on-prem specialization, and that adversaries are primarily focused on compromising on-prem infrastructure. Who are we seeing go after cloud environments? The same threat actors or not?
  • Could you share a bit about the mistakes and risks that you saw organizations make that made their cloud breaches possible or made them worse? Conversely, what ended up being helpful to organizations in limiting the blast radius or making response easier? 
  • Tim’s mother worked in a network disaster recovery team for a long time–their motto was “preparing for the inevitable.” What advice do you have for helping security teams and IT teams get ready for cloud breaches? Especially for recent cloud entrants?
#152
December 11, 2023

EP152 Trust, Security and Google's Annual Transparency Report

Guest:

  • Michee Smith, Director, Product Management for Global Affairs Works, Google
27:27

Topics covered:

  • What is Google Annual Transparency Report and how did we get started doing this? 
  • Surely the challenge of a transparency report is that there are things we can’t be transparent about, how do we balance this? What are those? Is it a safe question?
  • What Access Transparency Logs are and if they are connected to the report –other than in Tim's mind and your career? 
  • Beyond building the annual transparency report, you also work on our central risk data platform. Every business has a problem managing risk–what’s special here? Do we have any Google magic here? 
  • Could you tell us about your path in Product Management here? You have been here eight years, and recently became Director. Do you have any advice for the ambitious Google PMs listening to the show? 
#151
December 4, 2023

EP151 Cyber Insurance in the Cloud Era: Balancing Protection, Data and Risks

Guest:

  • Monica Shokrai, Head of Business Risk and Insurance for Google Cloud 
29:29

Topics covered:

  • Could you give us the 30 second run down of what cyber insurance is and isn't?
  • Can you tie that to clouds? How does the cloud change it? Is it the case that now I don't need insurance for some of the "old school" cyber risks?
  • What challenges are insurers facing with assessing cloud risks? On this show I struggle to find CISOs who "get" cloud, are there insurers and underwriters who get it?
  • We recently heard about an insurer reducing coverage for incidents caused by old CVEs! What's your take on this? Effective incentive structure to push orgs towards patching operational excellence or someone finding yet another way not to pay out? Is insurance the magic tool for improving security?
  • Doesn't cyber insurance have a difficult reputation with clients? “Will they even pay?” “Will it be enough?” “Is this a cyberwar exception?” type stuff?
  • How do we balance our motives between selling more cloud and providing effective risk underwriting data to insurers?
  • How soon do you think we will have actuarial data from many clients re: real risks in the cloud? What about the fact that risks change all the time unlike say many “non cyber” risks?
#150
November 27, 2023

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

29:29

Topics covered:

  • Gary, you’ve been doing software security for many decades, so tell us: are we really behind on securing ML and AI systems? 
  • If not SBOM for data or “DBOM”, then what? Can data supply chain tools or just better data governance practices help?
  • How would you threat model a system with ML in it or a new ML system you are building? 
  • What are the key differences and similarities between securing AI and securing a traditional, complex enterprise system?
  • What are the key differences between securing the AI you built and AI you buy or subscribe to?
  • Which security tools and frameworks will solve all of these problems for us?