Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#119
May 1, 2023

EP119 RSA 2023 - What We Saw, What We Learned, and What We're Excited About

Guest:

  • Connie Fan, Senior Product and Business Strategy Lead, Google Cloud
25:25

Topics covered:

  • We were at RSA 2023, what did we see that was notable and surprising?
  • Cloud Security showed up with three startups with big booths, and one big player with a small demo station. What have we learned here?
  • What visitors might have seen at the Google Cloud booth that we're really excited about?
  • Could you share why we chose these two AI use cases - generation of code and summarization of complex content - out of all the possibilities and the sometimes zany things we saw elsewhere on the floor?
  • Could you share a story or two that highlights how we came to this AI launch and what it looked like under the surface?
#118
April 24, 2023

EP118 RSA 2023 - How to Protect Your Organization from Cyberattacks in Time of Political Turmoil

Guests:

29:29

Topics covered:

  • It seems like we’re seeing more cyber activity taking place in the context of geopolitical events. A lot of organizations struggle to figure out if/how to respond to these events and any related cyber activity.  What advice do you have for these organizations and their leadership?
  • A  lot of threat intel (TI) suffers from “What does this event mean for threats to our organization?” - sort of how to connect CNN to your IDS? What is your best advice on this to a CISO? 
  • TI also suffers from “1. Get TI 2. ??? 3. Profit!” - how does your model help organizations avoid this trap? 
  • Surely there are different levels of granularity here to TI and its relevance. Is what a CISO needs different from what an IR member needs? Do you differentiate your feed along those axes?
  • What does success look like? How will organizations know when they’re successful? What are good KPIs for these types of threat intelligence? In other words, how would customers know they benefit from it?
  • Is there anything unique that cloud providers can do in this process?
#117
April 17, 2023

EP117 Can a Small Team Adopt an Engineering-Centric Approach to Cybersecurity?

Guest:

29:29

Topics covered:

  • What does an engineering-centric approach to cybersecurity mean?
  • What to tell people who want to "consume" rather than "engineer" security?
  • Is “engineering-centric” approach the same as evidence-based or provable? 
  • In practical terms, what does it mean to adopt an "engineering-centric approach" to cybersecurity for an organization? 
  • How will it differ from what we have today? What will it enable?
  • Can you practice this with a very small team? How about a very small team of “non engineers”?
  • You seem to say that tomorrow's cybersecurity will look a lot like software engineering. Where do we draw the line between these two?
#116
April 10, 2023

EP116 SBOMs: A Step Towards a More Secure Software Supply Chain

Guest:

29:49

Topics covered:

  • Why is everyone talking about SBOMs all of a sudden? Why does this matter to a typical security leader?
  • Some software vendors don’t want SBOM, and this reminds us of the food safety rules debates in the past, how does this analogy work here?
  • One interesting challenge in the world of SBOMs and unintended consequences is that large well resourced organizations may be better equipped to produce SBOMs than small independent and open source projects. Is that a risk?
  • Is the SBOM requirement setting the government up to be overly reliant on megacorps and are we going to unintentionally ban open source from the government? 
  • What is the relationship between SBOM and software liability? Is SBOM a step to this? Won’t software liability kill open source?
  • How does Google prepare for EO internally; how do we use SBOM and other related tools?
  • To come back to the food analogy, SBOMs are all well and good, but the goal is not that consumers know they’re eating lead, but rather that our food becomes healthier. Where are we heading in the next five years to improve software supply chain "health and safety"?
#115
April 3, 2023

EP115 How to Approach Cloud in a Cloudy Way, not As Somebody Else’s Computer?

Guest:

29:29

Topics covered:

  • You had a very fun blog where you reminded the world that many organizations still approach cloud as a rented data center, do you still see it now? Do you think this will persist for 3, 5, 10 years?
  • Other than microservices, what’re the most important differences between public cloud and a rented data center for a CISO to keep in mind?
  • Analysts say that “cloud is secure, but clients just aren’t using it securely”, what is your reaction to this? 
  • Actually, how do you define “use cloud securely”?
  • Have you met any CISOs who are active cloud fans who prefer cloud for security reasons?
  • You also work for an NDR vendor, do you think NDR in the cloud has a future? 
#114
March 27, 2023

EP114 Minimal Viable Secure Product (MVSP) - Is That a Thing?

Guest:

  • Chris John Riley, Senior Security Engineer and a Technical Debt Corrector  @ Google
27:27

Topics covered:

  • We’ve heard of MVP, what is MVSP or Minimal Viable Secure Product?
  • What problem is MVSP trying to solve for the industry, community, planet, etc?
  • How does MVSP actually help anybody?
  • Who is the MVSP checklist for? Leaders or engineers?
  • How does MVSP differ from compliance standards like ISO 27001, or even SOC 2?
  • How does Google use MVSP? Has it improved our security in some way?
  • How to balance the dynamic nature of security with minimal security basics?
  • The working group has recently completed a control refresh for 2022, what are some highlights?
#113
March 20, 2023

EP113 Love it or Hate it, Network Security is Coming to the Cloud

Guest:

28:00

Topics covered:

  • What is the role of network security in the public cloud? Networks used to be the perimeter, now we have an API and identity driven perimeter. Are networks still relevant as a layer of defense?
  • We often joke that “you don’t need to get your firewalls with you to the cloud”, is this really true? How do you do network access control if not with firewalls?
  • What about the NIDS? Does NIDS have a place in the cloud?
  • So we agree that some network security things drop off in the cloud, but are there new network security threats and challenges?
  • There’s cloud architecture and then there’s multi cloud and hybrid architectures–how does this story change if we open the aperture to network security for multi cloud and hybrid? 
  • Should solutions that provide cloud network security be in the cloud themselves? Is this an obvious question?
#112
March 13, 2023

EP112 Threat Horizons - How Google Does Threat Intelligence

Guest:

29:00

Topics covered:

  • What is unique about Google Cloud approach to threat intelligence? Is it the sensor coverage? Size of the team? Other things?
  • Why is Threat Horizons report unique among the threat reports released by other organizations?
  • Based on your research, what are the realistic threats to cloud environments today?
  • What threats are prevalent and what threats are most damaging?
  • Where do you see things in 2023? What should companies look for? 
  • What’s one thing that surprised you when preparing the report? What do you think will surprise audiences?
  • What is the most counter-intuitive hardening and operational advice can we glean from this Threat Horizons report
  • What's most important to know when it comes to understanding OT and cloud?
#111
March 6, 2023

EP111 How to Solve the Mystery of Application Security in the Cloud?

Guest:

23:23

Topics covered:

  • What got you interested in security and motivated you to make this your area of focus? You came from a developer background, right?
  • Occasionally we hear the sentiment that “developers don’t care about security,” how would you counter it (and would you?)?
  • How do we encourage developers and operations to use the appropriate security controls and settings in the cloud? Is “encourage” the right word?
  • Can we really achieve “secure by default” but for developers?
  • What do you think are the main application security issues that developers need to deal with in the cloud? 
  • You mentioned software supply chain security, do you treat this as a part of application security? How important is this, realistically, for an average organization and its developers?
  • Going to our favorite subject of threat detection, how do you think we can better encourage developers to supply the logs necessary for our detection and response teams to act upon? 
#110
February 27, 2023

EP110 Detection and Response in a High Velocity and High Complexity Environment

Guest:

27:05

Topics covered:

  • Tell us about joining Robinhood and prioritizing focus areas for detection in your environment?
  • Tim and Anton argue a lot about what kind of detection is best - fully bespoke and homemade, or scalable off-the-shelf. First, does our framework here make sense, and second, looking at your suite of detection capabilities, how have you chosen to prioritize detection development and detection triage?
  • You're operating in AWS: there are a lot of vendors doing detection in AWS, including AWS themselves. How have you thought about choosing your detection approaches and data sources?
  • Finding people with as much cloud expertise as you can't be easy: how are you structuring your organization to succeed despite cloud detection and response talent being hard to find? What matters more: detection skills or cloud skills?
  • What has been effective in ramping up your D&R team in the cloud?
  • What are your favorite telemetry data sources for detection in the cloud?