Cloud Security Podcast

Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!

cloud-security-podcast_high_res.png

Episode list

#69
June 13, 2022

EP69 Cloud Threats and How to Observe Them

Guest:

27:27

Topics covered:

  • What are realistic and actually observed cloud threats today? How did you observe them at Lacework?
  • Cloud threats: are they on-premise style threats to cloud assets? We hate the line “cloud is just somebody else’s computer” but apparently threats actors seem to think so?
  • What is the 2nd most dangerous cloud issue after configuration mistakes?
  • Why is it so common for organizations to have insecure configurations in their cloud environments?
  • Give me a few examples of the most common mistakes organizations make, and what they can do to avoid those configurations.
  • Cloud malware and ransomware / RansomOps, are these real risks today?
  • Are we finally seeing the rise of Linux malware at scale (in the cloud)?
  • As multi cloud expands in popularity, what are threat actors doing in this area?
  • Are actors customizing their attacks on a per-cloud basis (AWS, GCP, Azure)?
#68
June 6, 2022

EP68 How We Attack AI? Learn More at Our RSA Panel!

Guest:

25:27

Topics covered:

  • What is your threat model for a large-scale AI system? How do you approach this problem? How do you rank the attacks?
  • How do you judge if an attack is something to mitigate? How do you separate realistic from theoretical?
  • Are there AI threats that were theoretical in 2020, but may become a daily occurrence in 2025?
  • What are the threat-derived lessons for securing AI?
  • Do we practice the same or different approaches for secure AI and reliable AI?
  • How does relative lack of transparency in AI helps (or hurts?) attackers and defenders?
#67
May 31, 2022

EP67 Cyber Defense Matrix and Does Cloud Security Have to DIE to Win?

Guest:

  • Sounil Yu, CISO and Head of Research at JupiterOne
25:25

Topics covered:

  • How does your Cyber Defense Matrix apply to cloud security? Are things easier or harder?
  • Cloud (at least the cloudy-cloud, also called cloud native) definitely supports “Distributed / Immutable / Ephemeral” (DIE) - your new creation, how does that change security and CDM?
  • Cyber resilience generates a lot of confusion, how do you define and describe it? 
  • Is the cloud more or less cyber resilient based on your definition?
  • Is invisible security a good thing? Can we ever have it? When should security be visible?
  • Intuitively, security and safety are not the same. So, what is the difference between cyber safety and cyber security? What is cyber safety, really?
#66
May 23, 2022

EP66 Is This Binary Legit? How Google Uses Binary Authorization and Code Provenance

Guest:

  • Sandra Guo, Product Manager in Security, Google Cloud
25:23

Topics covered:

  • We have a really interesting problem here: if we make great investments in our use of trusted repositories, and great investments in doing code review on every change, and securing our build systems, and having reproducible builds, how do we know that all of what we did upstream is actually what gets deployed to production?
  • What are the realistic threats that Binary Authorization handles? Are there specific organizations that are more at risk from those?
  • What’s the Google inspiration for this work, both development and adoption? 
  • How do we make this work in practice at a real organization that is not Google? 
  • Where do you see organizations “getting it wrong” and where do you see organizations “getting it right”?
  • We’ve had a lot of conversations about rolling out zero-trust for enterprise applications, how do those lessons (start small, be visible, plan plan plan) translate into deploying Binauthz into blocking mode? 
#65
May 16, 2022

EP65 Is Your Healthcare Security Healthy? Mandiant Incident Response Insights

Guests:

27:27

Topics covered:

  • What are the current “popular” incidents at healthcare providers that you handled? Any of them involve cloud? 
  • Do healthcare CISOs have time for anything other than ransomware?
  • Does insider threat matter? What can incident response teach us here?
  • How do you think the threat actors benefit from the health data they steal? 
  • Based on your IR experience, what are the more interesting ways in, other than phishing?
  • Give us your IR-informed take on ransomware pay/not pay focused on healthcare, ideally? 
#64
May 9, 2022

EP64 Security Operations Center: The People Side and How to Do it Right

Guest:

Topics:

SIEM and SOC
25:25

Topics covered:

  • What are some tenets of good SOC training? How does this depend on the SOC model (traditional L1/L2/L3, virtual, etc)?
  • How do you make SOC training realistic?
  • Should training be about the toolset or should it be about the analyst’s skills?
  • Should you primarily train for engineering skills or analysis skills?
  • Do you need to code to succeed in a modern SOC?
  • Are competitive events like CTFs effective for SOC training?
  • What role does SOC training play in bringing new, perhaps under-represented people into security operations and promoting inclusivity?
#63
May 2, 2022

EP63 State of Autonomic Security Operations: Are There Sharks in Your SOC with Robert Herjavec

Guests:

Topics:

SIEM and SOC
34:57

Topics covered:

  • It’s been a few months since we launched Autonomic Security Operations (ASO) and it seems like the whitepaper has been going viral in the industry. Tell us what ASO is about?
  • How was the ASO story received by your customers? Any particular reactions?
  • Will the ASO narrative inspire the next generation of practitioners? Where do you envision the market headed?
  • ASO is about transforming the SOC, and that often involves culture change. How do you change the culture and deeper approaches common in security operations?
  • What else can we do to evolve SOC faster than the threats and assets grow?
#62
April 25, 2022

EP62 Protect Modern Applications in the Cloud: Union of API and Application Security

Guest:

  • Etienne De Burgh, Senior Security and Compliance Specialist, Office of the CISO @ Google Cloud
29:29

Topics covered:

  • Why is API security hot now? What happened that made it a priority for many? 
  • Is API security different from application security? Doesn't the first "A" in API  stand for application? 
  • What are the real threats to exposed APIs?
  • APIs are designed for automated use, so how do you tell automated use from automated abuse / attack?
  • What are the biggest challenges that companies are having with API security?
  • What are the components of API security? Is there a “secure by default API”? API threat detection?
  • Just like cloud in general, API misconfigurations seem to be leading to security problems, are APIs hard to configure securely for most organizations?
#61
April 18, 2022

EP61 Anniversary Episode - What Did We Learn So Far on Cloud Security Podcast?

Guest:

  • Anton Chuvakin
  • Timothy Peacock
23:23

Topics covered:

  • Why cloud security? What do we really think about our podcast name and topic, cloud security?
  • Can you once again explain security for the cloud, in the cloud, from the cloud?
  • What is one thing that we learned from doing a podcast?
  • Favorite cloud security trend that we encountered on the podcast? 
  • What did we learn about security from organization's migrating to the cloud?
  • What are our favorite reading materials related to cloud security?
  • What are our favorite tips from the guests on securing the cloud?
#60
April 11, 2022

EP60 Impersonating Service Accounts in GCP and Beyond: Cloud Security Is About IAM?

Guest:

23:23

Topics covered:

  • Could you explain briefly why identity is so important in the cloud?
  • A skeptic on cloud security once told us that “in the cloud, we are one identity mistake from a breach.” Is this true?
  • For listeners who aren’t familiar with GCP, could you give us the 30 second story on “what is a service account.” How is it different from a regular IAM account?
  • What are service account impersonations?
  • How can I see if my service accounts can be impersonated? How do I detect it?
  • How can I better secure my organization from impersonation attacks?