Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#129
July 10, 2023

EP129 How CISO Cloud Dreams and Realities Collide

Guest:

  • Rick Doten, VP, Information Security at Centene Corporation, CISO Carolina Complete Health
29:29

Topics covered:

  • What are the realistic cloud risks today for an organization using public cloud? 
  • Is the vendor lock-in on that list?  What other risks everybody thinks are real, but they are not?
  • What do you tell people who in 2023 still think “they can host Exchange better themselves” and have silly cloud fears?
  • What do you tell people who insist on “copy/pasting” all their security technology stack from data centers to the cloud?
  • Cloud providers have greater opportunity not only to see issues, but to learn how to react well. Do you think this argument holds water? 
  • What are the most challenging security issues for multi-cloud and hybrid cloud security?
  • How does security chasm (between security haves and have-notes) affect cloud security?
  • Your best cloud security advice for an organization with a security team of 0 FTEs and no CISO?
#128
July 3, 2023

EP128 Building Enterprise Threat Intelligence: The Who, What, Where, and Why

Guest:

  • John Doyle, Principle Intelligence Enablement Consultant at Mandiant / Google Cloud
27:27

Topics covered:

  • You have created a new intelligence class focused on building enterprise threat intelligence capability, so what is the profile of an organization and profile for a person that benefits the most from the class?
  • There are many places to learn threat intel (TI), what is special about your new class? 
  • You talk about country cyber operations in the class, so what is the defender - relevant difference between, say, DPRK and Iran cyber doctrines? More generally, how do defenders benefit from such per country intel?
  • Can you really predict what the state-affiliated attackers would do to your organization based on the country doctrine?
  • In many minds, TI is connected to attribution. What is your best advice on attribution to CISOs of well-resourced organizations? What about mainstream organizations?
  • Overall we see a lot of organizations still failing to operationalize TI, especially strategic TI, how does this help them?
#127
June 26, 2023

EP127 Is IAM Really Fun and How to Stay Ahead of the Curve in Cloud IAM?

Guest:

  • Ian Glazer, founder at Weave Identity, ex-Gartner, ex-SVP of Products at Salesforce, co-founder of IDPro
29:29

Topics covered:

  • OK, tell us why Identity and Access Management (IAM) is exciting (is it exciting?)
  • Could you also explain why IAM is even more exciting in the cloud? 
  • Are you really “one IAM mistake away from a breach” in the cloud? 
  • What advice would you give to someone new to IAM?
  • How to not just “learn IAM in the cloud” but to keep learning IAM?
  • Is what I know about IAM in AWS the same as knowing IAM for GCP? What advice do you have for teams operating in a multi-cloud world?
  • What are the top cloud IAM mistakes? How to avoid them?
#126
June 19, 2023

EP126 What is Policy as Code and How Can It Help You Secure Your Cloud Environment?

Guest:

29:29

Topics covered:

  • What is a policy, is that the same as a control, or is there a difference? And what’s the gap between a policy and a guardrail? 
  • We have IaC, so what is this Policy as Code? Is this about security policy or all policies for cloud?
  • Who do I hire to write and update my policy as code? Do I need to be a coder to create policy now?
  • Who should own the implementation of Policy as Code? Is Policy as Code something that security needs to be driving? Is it the DevOps or Platform Engineering teams?
  • How do organizations grow into safely rolling out new policy as code code? 
  • You [Mondoo] say that "cnspec assesses your entire infrastructure's security and compliance"  and this problem has been unsolved for as long as the cloud existed. Will your toolset change this? 
  • There are other frameworks that exist for security testing like HashiCorp’s sentinel, Open Policy Agent, etc and you are proposing a new one with MQL. Why do we need another security framework?
  • What are some of the success metrics when adopting  Policy as Code? 
#125
June 12, 2023

EP125 Will SIEM Ever Die: SIEM Lessons from the Past for the Future

Guest:

27:27

Topics covered:

  • Which old Security Information and Event Management (SIEM) lessons apply today?
  • Which old SIEM lessons absolutely do not apply today and will harm you?
  • What are the benefits and costs of SIEM in 2023?
  • What are the top cloud security use cases for SIEM in 2023?
  • What are your favorite challenges with SIEM in 2023 special in the cloud? Are they different from, say, 2013 or perhaps 2003?
  • Do you think SIEM can ever die?
#124
June 5, 2023

EP124 Safe Browsing: Lessons from How Google Secures Five Billion Devices at Low False Positive Rates

Guest:

27:27

Topics covered:

  • Could you give us the 30 second overview of our favorite “billion user security product” - SafeBrowsing - and, since you were there, how did it get started?
  • SafeBrowsing is a consumer and business product – are you mitigating the same threats and threat models on each side?
  • Making this work at scale can’t be easy, anytime we’re talking about billion device protection, there are massive scale questions. How did we make it work at such a scale? 
  • Talk to us about the engineering and scaling magic behind the low false positive rate for blocking?

Resources:

#123
May 29, 2023

EP123 The Good, the Bad, and the Epic of Threat Detection at Scale with Panther

Guest:

29:29

Topics covered:

  • What is good detection, defined at micro-level for a rule or a piece of detection content? 
  • What is good detection, defined at macro-level for a program at a company? 
  • How to reliably produce good detection content at scale?
  • What is a detection content lifecycle that reliably produces good detections at scale?
  • What is the purpose of a SIEM today?
  • Where do you stand on a classic debate on vendor-written vs customer-created detection content?
#122
May 22, 2023

EP122 Firewalls in the Cloud: How to Implement Trust Boundaries for Access Control

Guest:

25:23

Topics covered:

  • So, if somebody wakes you up at 3AM (“Anton’s 3AM test”) and asks “Do we need firewalls in the cloud?” what would you say?
  • Firewalls (=virtual appliances in the cloud or routing cloud traffic through physical firewalls) vs firewalling (=controlling network access) in the cloud, do they match the cloud-native realities?
  • How do you implement trust boundaries for access control with cloud-native options?
  • Can you imagine a modern cloud native security architecture that includes a firewall?
  • Can you imagine a modern cloud native security architecture that excludes any firewalling? 
  • Firewall, NIDS, NIPS, NGFW …. How do these other concepts map to the cloud? How do you build a "traditional-like" network visibility layer in the cloud (and do we need to)?
#121
May 15, 2023

EP121 What Happens Here Stays Here: Confidential City (and Space)

Guests:

25:25

Topics covered:

  • Could you remind our listeners what confidential computing is?
  • What threats does this stop? Are these common at our clients? 
  • Are there other use cases for this technology like compliance or sovereignty?
  • We have a new addition to our Confidential Computing family - Confidential Space. Could you tell us how it came about?
  • What new use cases does this bring for clients?
#120
May 8, 2023

EP120 Building Secure Cloud and Building Security Products: Finding the Balance

Guest:

  • Jeff Reed, VP of Product, Cloud Security @ Google Cloud
23:23

Topics covered:

  • You’ve had a long career in software and security, what brought you to Google Cloud Security for this role?
  • How do you balance the needs of huge global financials that often ask for esoteric controls (say EKM with KAJ) vs the needs of SMBs that want easy yet effective, invisibility security?
  • We’ve got an interesting split within our security business: some of our focus is on making Google Cloud more secure, while some of our focus is on selling security products.  How are you thinking about the strategy and allocation between these functions for business growth?
  • What aspects of Cloud security have you seen cloud customers struggle with the most?
  • What’s been the most surprising or unexpected security challenge you’ve seen with our users?
  • “Google named a Leader in Forrester Wave™ IaaS Platform Native Security” - can you share a little bit about how this came to be and what was involved in this?
  • Is cloud migration a risk reduction move?