Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!
Why is there so much attention lately on SaaS security? Doesn’t this area date back to 2015 or so?
What do you see as the primary challenges in securing SaaS?
What does a SaaS threat model look like? What are the top threats you see?
CASB has been the fastest growing security market and it has grown into a broad platform and many assume that “securing SaaS = using CASB”, what are they missing?
Where would another technology to secure SaaS fit architecturally, inline with CASB or as another API-based system?
Securing IaaS spanned a robust ecosystem of vendors (CWPP, CSPM, now CNAPP) and many of these have ambitions for securing SaaS, thus clashing with CASB. Where do you fit in this battle?
For a while, you were talking more about CDR - what is it and do we really need a separate CDR technology?
I know we don’t like to say “SOC” here, so why don’t we talk about the role of automation in detection and response (D&R) at Google?
One SRE concept we found useful in security operations is “toil” - How do we squeeze toil out of D&R practice at Google?
A combined analyst and engineer role (just like an SRE) was critical for both increasing automation and reducing toil, how hard was it to put this into practice? Tell us about that journey?
How do we automate security signal analysis, can you give us a few examples?
D&R metrics have been a big pain point for many organizations, how does SRE thinking of SLOs and SLIs (and less about SLAs) helps us in our “not SOC”?
How do we avoid falling into the “time to respond” trap that rewards fast response, sometimes at the cost of good?
You've looked at hundreds of security startups at the growth stage - what is getting funded? What is not getting funded? What is the difference?
What's your view on the current market environment for security companies? Is security "recession-proof", whatever that means?
How do you think about what problems are worth solving with a new venture vs existing vendors (and/or CSPs) expanding to cover the new area?
Why do many cloud security vendors get funded and get high valuations while there is a wide perception that CSP (like us at Google) are doing security really well?
How do we solve the challenge that many organizations are barely moving off “antivirus and firewalls” security of the 1990s?
What is your best advice to cloud security startups trying to get wider adoption?
You recently coined a concept of “output-driven Detection and Response” and even perhaps broader “output-driven security.” What is it and how does it work?
Detection and response is alive (obviously), but sometimes you say SOC is dead, what do you mean by that?
You refer to a federated approach for Detection and Response” (“route the outcomes to the teams that need them or can address them”), but is it workable for any organization?
What about the separation of duty concerns that some raise in response to this? What about the organizations that don’t have any security talent in those teams?
Is the approach you advocate "cloud native"? Does it only work in the cloud? Can a traditional, on-premise focused organization use it?
The model of “security team as a decision-maker, not an implementer” has a bit of a painful history, as this is what led to “GRC-only teams” who lack any technical knowledge. Why will this approach work this time?
Many MDRs claim to be “security from the cloud”, but they actually don’t know much about cloud security. What does good looks like for MDR in the cloud (cloud being a full range from IaaS to SaaS)?
What are the key challenges for clients picking an MDR for their cloud environments? What are the questions to ask your potential MDR?
Do clients want the same security outcomes done in the cloud vs on-premise?
Does it mean that MSSP/MDR capabilities must be different for good coverage of the cloud?
Is MDR technology different for Cloud detection and response as opposed to on-prem D&R?
How do you communicate with clients about the importance and value of cloud specific detection vs detection for endpoints running in the cloud?
What are the top threats against client cloud environments that you see, detect and protect from?
Which clouds (IaaS?) are easiest for MDR to protect? What makes them easier to handle than the other Clouds?