Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#109
February 20, 2023

EP109 How Google Does Vulnerability Management: The Not So Secret Secrets!

Guest:

  • Ana Oprea, Staff Security Engineer, European Lead of Vulnerability Coordination Center @ Google
27:27

Topics covered:

  • What is the scope for the vulnerability management program at Google? Does it cover OS, off-the-shelf applications, custom code we wrote … or all of the above?
  • Our vulnerability prioritization includes a process called “impact assessment.” What does our impact assessment for a vulnerability look like?
  • How do we prioritize what to remediate? How do we decide on the speed of remediation needed?
  • How do we know if we’ve done a good job? When we look backwards, what are our critical metrics (SLIs and SLOs) and how high up the security stack is the reporting on our progress?
  • What of the “Google Approach” should other companies not try to emulate? Surely some things work because of Google being Google, so what are the weird or surprising things that only work for us?
#108
February 13, 2023

EP108 How to Hunt the Cloud: Lessons and Experiences from Years of Threat Hunting

Guest:

  • John Stoner, Principal Security Strategist @ Google Cloud
26:09

Topics covered:

  • Please define threat hunting  for us quickly, the term has been corrupted a bit.
  • What are your favorite beginner hunts to jump start the effort at a new team?
  • How to incorporate hunting lessons in detection?
  • What are the differences for hunting in the cloud?
  • Are there specific data sources you prefer to have access to when threat hunting? In the cloud?
  • Should every organization threat hunt?
  • What are traits you might look for in a threat hunter?
#107
February 6, 2023

EP107 How Google Secures It's Google Cloud Usage at Massive Scale

Guest:

  • Karan Dwivedi, Security Engineering Manager, Enterprise Infrastructure Protection @ Google Cloud
28:50

Topics covered:

  • Google’s use of Google Cloud is a massive cloud environment with wildly diverse use cases. Could you share, for our listeners, a few examples of the different kinds of things we’re running in GCP?
  • Given that we’re doing these wildly different things in GCP, how do we think about scaling the right security guardrails to the right places in our GCP org?
  • How do you work with application engineering teams and project owner teams to make sure the right controls are there but not getting in the way of business? 
  • How do we scale this exemption management process? Are there things we do here that don’t make sense at a smaller scale? Are there emergent challenges that only we would face?
  • How do you correctly federate security responsibilities between the central team defining policy and the constituent user teams actually using the platform?
  • Burnout is a perennial challenge for security teams – what are you doing to keep your people happy and engaged?
#106
January 30, 2023

EP106 Beyond BeyondProd - How Do You Zero Trust Your Workloads?

Guest:

  • Anoosh Saboori, former Product Manager at Google Cloud
23:23

Topics covered:

  • We had zero trust episodes before and definitions vary! When we say zero trust, what do we mean?  
    • What about zero trust for workloads in production? When you say “workload,” what do you mean?
  • What is BeyondProd, for those that are unfamiliar with it? And how is this different from BeyondCorp? 
  • How has BeyondProd actually been implemented at Google?  
  • What threats does it help with? Is this real threats or compliance?
  • Why is now a good time to be thinking about zero trust for production systems? 
  • Companies have many security tools deployed, including microsegmentation and firewalls, how does this toolset fit? Does it replace anything they have deployed?
#105
January 23, 2023

EP105 Security Architect View: Cloud Migration Successes, Failures and Lessons

Guest:

27:27

Topics covered:

  • We are here to talk about cloud migrations and we are here to talk about failures. What are your favorites?
  • What are your favorite cloud security process failures? 
  • What are your favorite cloud security technical failures? 
    • What are your favorite cloud security container and k8s failures?
  • Is "lift and shift" always wrong from the security point of view? 
    • Can it at least work as step 1 for a full cloud transformation?
#104
January 17, 2023

EP104 CISO Walks Into the Cloud: And The Magic Starts to Happen!

Guest:

25:00

Topics covered:

  • "So we're talking about your journey as a CISO migrating to Cloud. Could you give us the 30 second overview of 
    • What triggered your organization's migration to the cloud?
    • When did you and the security organization get brought in?
    • How did you plan your security  organization's journey to the cloud?
  • Did you take going to cloud as an opportunity to change things beyond the tools you were using? 
  • As you got going into the cloud, what was the hardest part for your organization?
  • If that was hardest, what was most surprising? Good surprise and bad surprise?
  • Let’s shift to some tactical gears:
    • How did you design security controls for the cloud?
    • Did your data security practice change?
    • Did your detection  / response practice change?
  • How has the CISO role evolved and is evolving due to the cloud?
  • Having covered all that tactical terrain, one final strategic question: is moving to Cloud a net risk reduction? Can it be?
#103
January 9, 2023

EP103 Security Incident Response and Public Cloud - Exploring with Mandiant

Guest:

  • Nader Zaveri, Senior Manager of IR and Remediation at Mandiant, now part of Google Cloud
27:27

Topics covered:

  • Could we start with a story of a cloud incident response (IR) failure and where things went wrong? 
  • What should that team have done to get it right? 
  • Are there skills that matter more in cloud incidents than they do for on-prem incidents? Are there on-prem instincts that will lead incident responders astray in cloud?
  • What 3 things an IR team leader needs to do to prepare his team for IR in the cloud?
  • Are there on-premise tools that can stay on prem and not join us in the cloud?
  • What processes should we leave behind? Keep with us?
  • What logs and context should we prepare for cloud IR?  What access should we have behind “break glass”?
  • While doing IR, what things should we look at in the cloud logs (which logs, also?) to expedite the investigation?
#102
December 19, 2022

EP102 Sunil Potti on Building Cloud Security at Google

Guest:

25:23

Topics covered:

  • One of the biggest shifts we’ve noticed is the shift from building security because we think security is good, to building security as a business. How did you make that cultural shift happen in our organization? 
  • With organizations migrating to cloud we have a set of tradeoffs between meeting security teams where they are with on-prem expectations of security vs cloud-native approaches. How do you think about investing in next generation products vs holding the hands of CISOs just stepping into the cloud?
  • What matters more to you as a leader, secure cloud (GCP, Workspace) or security products (Chronicle SecOps, BCE, SCC, etc)?
  • Is invisible security the same as “building security in”? Aren’t there security controls where the value is derived from them being visible to users?
  • Mandiant brings services expertise to Google Cloud, typically not our strong area and not our DNA, how do we plan to make the most of Mandiant within Google’s culture?
#101
December 12, 2022

EP101 Cloud Threat Detection Lessons from a CISO

Guest:

24:40

Topics covered:

1. You were at Google for a long time, and at Google you sat between Google security and Cloud. Now that you're leading security for a major company, how are you prioritizing your focus between your on-premise resources and your cloud resources? 

2. How are you thinking about threat detection in the Cloud?

3. In detection, how has your technology changed? How has your process changed? What threats do you mostly focus on?

4. Why don’t we talk about the role of automation in detection and response (D&R)? How do you approach automation and eliminating toil?

5. As you're scaling teams, processes and technology for your cloud footprint, what has been easiest to get right and what's been hardest to get right?

6. How do you approach measuring security? What cloud metrics are you sharing upwards to your board?

#100
December 5, 2022

EP100 2022 Accelerate State of DevOps Report and Software Supply Chain Security

Guests:

27:27

Topics covered:

  • How did you get involved with this year’s Accelerate State of DevOps Report (DORA report)?
  • So what is DORA and why did you decide to focus on supply chain security for the 2022 report?
  • What are the big learnings from this year’s report?
  • What’s the difference between SLSA and SSDF? Is one spicy and the other savory? How’re companies adopting these and how is adoption going? 
  • Are there other areas that DevOps can be a contributor in the overall security landscape? 
  • How can CISOs rope DevOps fully into their security gang?
  • Operationally, how should security and developers and DevOps come together to keep vulnerabilities out in the first place?
  • How should security and developers and DevOps come together to respond quickly to vulnerabilities when they’re discovered?
  • How do security and developers and DevOps come together to prove to their auditors and customers that they’re doing a good job of the above?