Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#79
August 15, 2022

EP79 Modernize Data Security with Autonomic Data Security Approach

Guest:

  • John Stone,  Chaos Coordinator @ Office of the CISO, Google Cloud
23:23

Topics covered:

  • So what is Autonomic Data Security, described in our just released paper? 
  • What are some notorious data security issues today? Perhaps common data security mistakes security leaders commit?
  • What never worked in data security, like say manual data classification?
  • How should organizations think about securing the data they migrated and the data that was created in the cloud?
  • Do you really believe the cloud can make data security better than data security in traditional environments?
#78
August 8, 2022

EP78 Classic SOC Meets Cloud: What Changes? What Stays the Same?

Guest:

23:29

Topics covered:

  • How do we get a legacy SOC team to think about the cloud?
  • How to think about cloud threat detection, in general? What is different … threats, the environment, what else? What is the same? 
  • How do we know which TTPs are relevant for the new environments? What to bring with us to the cloud?
  • Do content/rules and detection engines need to be different to cover the cloud detection use cases?
  • What cases are appropriate for machine learning (ML) in the cloud? Does cloud threats drive the need for new ML detections?
#77
August 1, 2022

EP77 Operational Realities of SOAR: Automate and/or Enrich, Playbooks, Magic

Guest:

  • Cyrus Robinson, SOC Director and IR Team lead at Ingalls Information Security
25:25

Topics covered:

  • You’ve been using SOAR tools for years, so what do you think of the technology so far?
  • What is driving SOAR adoption today? And what is inhibiting SOAR adoption?
  • Realistically, how hard is SOAR to operationalize for a typical company?
  • What are your favorite SOAR playbooks to start with?
  • How to build, train and keep the SOAR team? Do they need to code to succeed?
  • We like the SOAR maturity model approach. How would you imagine a SOAR adoption maturity model?
  • How to implement SOAR from scratch in scaling operations? How to start? How to plan? How to not fail?
#76
July 25, 2022

EP76 Powering Secure SaaS … But Not with CASB? Cloud Detection and Response?

Guest:

27:27

Topics covered:

  • Why is there so much attention lately on SaaS security? Doesn’t this area date back to 2015 or so?
  • What do you see as the primary challenges in securing SaaS?
  • What does a SaaS threat model look like? What are the top threats you see?
  • CASB has been the fastest growing security market and it has grown into a broad platform and many assume that “securing SaaS = using CASB”, what are they missing?
  • Where would another technology to secure SaaS fit architecturally, inline with CASB or as another API-based system?
  • Securing IaaS spanned a robust ecosystem of vendors (CWPP, CSPM, now CNAPP) and many of these have ambitions for securing SaaS, thus clashing with CASB. Where do you fit in this battle?
  • For a while, you were talking more about CDR - what is it and do we really need a separate CDR technology?
#75
July 18, 2022

EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil

Guest:

  • Tim Nguyen, Director of Detection and Response @ Google
27:27

Topics covered:

  • I know we don’t like to say “SOC” here, so why don’t we talk about the role of automation in detection and response (D&R) at Google?
  • One SRE concept we found useful in security operations is “toil” - How do we squeeze toil out of D&R practice at Google?
  • A combined analyst and engineer role (just like an SRE) was critical for both increasing automation and reducing toil, how hard was it to put this into practice? Tell us about that journey?
  • How do we automate security signal analysis, can you give us a few examples?
  • D&R metrics have been a big pain point for many organizations, how does SRE thinking of SLOs and SLIs (and less about SLAs) helps us in our “not SOC”?
  • How do we avoid falling into the “time to respond” trap that rewards fast response, sometimes at the cost of good?
#74
July 11, 2022

EP74 Who Will Solve Cloud Security: A View from Google Investment Side

Guest:

25:25

Topics covered:

  • You've looked at hundreds of security startups at the growth stage - what is getting funded? What is not getting funded? What is the difference?
  • What's your view on the current market environment for security companies? Is security "recession-proof", whatever that means?
  • How do you think about what problems are worth solving with a new venture vs existing vendors (and/or CSPs) expanding to cover the new area?
  • Why do many cloud security vendors get funded and get high valuations while there is a wide perception that CSP (like us at Google) are doing security really well?
  • How do we solve the challenge that many organizations are barely moving off “antivirus and firewalls” security of the 1990s?
  • What is your best advice to cloud security startups trying to get wider adoption?
#73
July 5, 2022

EP73 Your SOC Is Dead? Evolve to Output-driven Detect and Respond!

Guest:

  • Erik Bloch,  Senior Director of Detection and Response at Sprinklr

Topics:

SIEM and SOC
29:29

Topics covered:

  • You recently coined a concept of “output-driven Detection and Response” and even perhaps broader “output-driven security.” What is it and how does it work?
  • Detection and response is alive (obviously), but sometimes you say SOC is dead, what do you mean by that?
  • You refer to a federated approach for Detection and Response”  (“route the outcomes to the teams that need them or can address them”), but is it workable for any organization? 
  • What about the separation of duty concerns that some raise in response to this? What about the organizations that don’t have any security talent in those teams?
  • Is the approach you advocate "cloud native"? Does it only work in the cloud? Can a traditional, on-premise focused organization use it?
  • The model of “security team as a decision-maker, not an implementer” has a bit of a painful history, as this is what led to “GRC-only teams” who lack any technical knowledge. Why will this approach work this time?
#72
June 27, 2022

EP72 What Does Good Detection and Response Look Like in the Cloud? Insights from Expel MDR

Guests:

27:27

Topics covered:

  • Many MDRs claim to be “security from the cloud”, but they actually don’t know much about cloud security. What does good looks like for MDR in the cloud (cloud being a full range from IaaS to SaaS)?
  • What are the key challenges for clients picking an MDR for their cloud environments?  What are the questions to ask your potential MDR?
  • Do clients want the same security outcomes done in the cloud vs on-premise?  
  • Does it mean that MSSP/MDR capabilities must be different for good coverage of the cloud? 
  • Is MDR technology different for Cloud detection and response as opposed to on-prem D&R? 
  • How do you communicate with clients about the importance and value of cloud specific detection vs detection for endpoints running in the cloud? 
  • What are the top threats against client cloud environments that you see, detect and protect from?
  • Which clouds (IaaS?) are easiest for MDR to protect? What makes them easier to handle than the other Clouds?
#71
June 21, 2022

EP71 Attacking Google to Defend Google: How Google Does Red Team

Guest:

23:23

Topics covered:

  • What is our “red team” testing philosophy and approach at Google? 
  • How did we evolve to this approach? 
  • What is the path from testing to making Google and our users more secure? How does our testing power the improvements we make?
  • What is unique about red teaming at Google?
  • Care to share some fun testing stories or examples from your experience?
#70
June 16, 2022

EP70 Special - RSA 2022 Reflections - Securing the Past vs Securing the Future

Guest:

none

23:23

Topics covered:

  • What have we seen at the RSA 2022 Conference?
  • What was the most interesting and unexpected?
  • What was missing?