Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#149
November 20, 2023

EP149 Canned Detections: From Educational Samples to Production-Ready Code

Guests:

  • John Stoner, Principal Security Strategist, Google Cloud Security
  • Dave Herrald, Head of Adopt Engineering, Google Cloud Security
29:29

Topics covered:

  • In your experience, past and present, what would make clients trust vendor detection content?
  • Regarding “canned”, default or “out-of-the-box” detections, how to make them more production quality and not merely educational samples to learn from?
  • What is more important, seeing the detection or being able to change it, or both?
  • If this is about seeing the detection code/content, what about ML and algorithms?
  • What about the SOC analysts who don't read the code?
  • What about “tuning” - is tuning detections a bad word now in 2023?
  • Everybody is obsessed about “false positives,” what about the false negatives? How are we supposed to eliminate them if we don’t see detection logic?
#148
November 13, 2023

EP148 Decoding SaaS Security: Demystifying Breaches, Vulnerabilities, and Vendor Responsibilities

Guest:

Topics:

SaaS Security
29:29

Topics covered:

  • When people talk about “cloud security” they often forget SaaS, what should be the structured approach to using SaaS securely or securing SaaS?
  • What are the incidents telling us about the realistic threats to SaaS tools?
  • Is the Microsoft 365 breach a SaaS breach, a cloud breach or something else?
  • Do we really need CVEs for SaaS vulnerabilities?
  • What are the least understood aspects of securing SaaS?
  • What do you tell the organizations who assume that “SaaS vendor takes care of all SaaS security”?
  • Isn’t CASB the answer to all SaaS security issues? We also have SSPM now too? Do we really need more tools?
#147
November 8, 2023

EP147 Special: 2024 Security Forecast Report

Guest:

25:25

Topics covered:

  • Can you really forecast threats? Won’t the threat actors ultimately do whatever they want?
  • How can clients use the forecast? Or as Tim would say it, what gets better once you read it?
  • What is the threat forecast for cloud environments? “Cyber attacks targeting hybrid and multi-cloud environments will mature and become more impactful“ - what does it mean?
  • Of course AI makes an appearance as well: “LLMs and other gen AI tools will likely be developed and offered as a service to assist attackers with target compromises.” Do we really expect attacker-run LLM SaaS? What model will they use? Will it be good?
  • There are a number of significant elections scheduled for 2024, are there implications for cloud security?
  • Based on the threat information, tell me about something that is going well, what will get better in 2024?
#146
November 6, 2023

EP146 AI Security: Solving the Problems of the AI Era: A VC's Insights

27:27

Topics covered:

  • We have a view at Google that AI for security and security for AI are largely separable disciplines. Do you feel the same way? Is this distinction a useful one for you? 
  • What are some of the security problems you're hearing from AI companies that are worth solving? 
  • AI is obviously hot, and as always security is chasing the hotness. Where are we seeing the focus of market attention for AI security?
  • Does this feel like an area that's going to have real full products or just a series of features developed by early stage companies that get acquired and rolled up into other orgs? 
  • What lessons can we draw on from previous platform shifts, e.g. cloud security, to inform how this market will evolve?
#145
October 30, 2023

EP145 Cloud Security: Shared Responsibility, Shared Fate, Shared Faith?

Guest:

23:23

Topics covered:

  • What are the challenges with shared responsibility for cloud security?
  • Can you explain "shared" vs "separated" responsibility?
  • In your article, you mention “shared faith”, we have “shared fate”, but we never heard of shared faith. What is this? Can you explain?
  • What about the cloud models (SaaS, PaaS, IaaS), how does this sharing model differ?
  • While at it, what is cloud, really? [yes, we really did ask this!]
#144
October 20, 2023

EP144 LLMs: A Double-Edged Sword for Cloud Security? Weighing the Benefits and Risks of Large Language Models

Guest:

  • Kathryn Shih, Group Product Manager, LLM Lead in Google Cloud Security
25:27

Topics covered:

  • Could you give our audience the quick version of what is an LLM and what things can they do vs not do?  Is this “baby AGI” or is this a glorified “autocomplete”?
  • Let’s talk about the different ways to tune the models, and when we think about tuning what are the ways that attackers might influence or steal our data?
  • Can you help our security listener leaders have the right vocabulary and concepts to reason about the risk of their information a) going into an LLM and b) getting regurgitated by one?
  • How do I keep the output of a model safe, and what questions do I need to ask a vendor to understand if they’re a) talking nonsense or b) actually keeping their output safe? 
  • Are hallucinations inherent to LLMs and can they ever be fixed?
  • So there are risks to data and new opportunities for attacks and hallucinations. How do we know good opportunities in the area given the risks? 
#143
October 16, 2023

EP143 Cloud Security Remediation: The Biggest Headache?

29:29

Topics covered:

  • It seems that in many cases the challenge with cloud configuration weaknesses is not their detection, but remediation, is that true?
  • As far as remediation scope, do we need to cover  traditional vulnerabilities (in stock and custom code), configuration weaknesses and other issues too?
  • One of us used to cover vulnerability management at Gartner, and in many cases the remediation failures [on premise] were due to process, not technology, breakdowns. Is this the same in the cloud? If still true, how can any vendor technology help resolve it?
  • Why is cloud security remediation such a headache for so many organizations?
  • Is the friction real between security and engineering teams? Do they have any hope of ever becoming BFFs?
  • Doesn’t every CSPM (and now ASPM too?) vendor say they do automated remediation today? How should security pros evaluate solutions for prioritizing, triaging, and fixing issues?
#142
October 9, 2023

EP142 Cloud Security Podcast Ask Me Anything #AMA 2023

27:27

Topics covered:

  • Could you tell us how you ended up in security?
  • What was the moment you realized that Cloud security was different from well, regular, security? 
  • Anton is always asking this “3AM test”, where did that come from?
  • How do you source topics for the podcast?
  • What advice would you give to folks who are interested in getting into security?
  • … and other fun questions!
#141
October 2, 2023

EP141 Cloud Security Coast to Coast: From 2015 to 2023, What's Changed and What's the Same?

Guest:

27:27

Topics covered:

  • Before we dive into all of the awesome cloud migrations you’ve experienced and your learnings there, could we start with a topic of East vs West CISO mentality?
  • We are talking to more and more CISOs who see the cloud as a net win for security. What’s your take on whether the cloud improves security? 
  • We talked about doing some “big” cloud migrations, could you talk about what you learned back in 2015 about the “right” way to do a cloud migration and how you’ve applied those lessons since? 
  • How are you approaching securing clouds differently in 2023 (vs the dark past of 2015)?
  • What advice would you give your peers to get out of the “saying no” mentality and into a better collaborative mode? 
  • On the topic of giving advice to people who haven’t asked for it, what advice would you give to teams who are stuck in 1990s thinking when it comes to lift and shifting their security technology stack to cloud?
#140
September 25, 2023

EP140 System Hardening at Google Scale: New Challenges, New Solutions

Guest:

25:23

Topics covered:

  • What is different about system hardening today vs 20 years ago? 
  • Also, what is special about hardening systems at Google massive scale?
  • Can I just apply CIS templates and be done with it?
  • Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity?
  • A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us?
  • Are there cases where we have taken lessons from hardening at scale and converted those into product improvements?
  • What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you’re doing? [Spoiler: the answer here is VERY fun!]