Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!
James Condon, Director of Security Research @ Lacework
27:27
Topics covered:
What are realistic and actually observed cloud threats today? How did you observe them at Lacework?
Cloud threats: are they on-premise style threats to cloud assets? We hate the line “cloud is just somebody else’s computer” but apparently threats actors seem to think so?
What is the 2nd most dangerous cloud issue after configuration mistakes?
Why is it so common for organizations to have insecure configurations in their cloud environments?
Give me a few examples of the most common mistakes organizations make, and what they can do to avoid those configurations.
Cloud malware and ransomware / RansomOps, are these real risks today?
Are we finally seeing the rise of Linux malware at scale (in the cloud)?
As multi cloud expands in popularity, what are threat actors doing in this area?
Are actors customizing their attacks on a per-cloud basis (AWS, GCP, Azure)?
EP67 Cyber Defense Matrix and Does Cloud Security Have to DIE to Win?
Guest:
Sounil Yu, CISO and Head of Research at JupiterOne
25:25
Topics covered:
How does your Cyber Defense Matrix apply to cloud security? Are things easier or harder?
Cloud (at least the cloudy-cloud, also called cloud native) definitely supports “Distributed / Immutable / Ephemeral” (DIE) - your new creation, how does that change security and CDM?
Cyber resilience generates a lot of confusion, how do you define and describe it?
Is the cloud more or less cyber resilient based on your definition?
Is invisible security a good thing? Can we ever have it? When should security be visible?
Intuitively, security and safety are not the same. So, what is the difference between cyber safety and cyber security? What is cyber safety, really?
EP66 Is This Binary Legit? How Google Uses Binary Authorization and Code Provenance
Guest:
Sandra Guo, Product Manager in Security, Google Cloud
25:23
Topics covered:
We have a really interesting problem here: if we make great investments in our use of trusted repositories, and great investments in doing code review on every change, and securing our build systems, and having reproducible builds, how do we know that all of what we did upstream is actually what gets deployed to production?
What are the realistic threats that Binary Authorization handles? Are there specific organizations that are more at risk from those?
What’s the Google inspiration for this work, both development and adoption?
How do we make this work in practice at a real organization that is not Google?
Where do you see organizations “getting it wrong” and where do you see organizations “getting it right”?
We’ve had a lot of conversations about rolling out zero-trust for enterprise applications, how do those lessons (start small, be visible, plan plan plan) translate into deploying Binauthz into blocking mode?
It’s been a few months since we launched Autonomic Security Operations (ASO) and it seems like the whitepaper has been going viral in the industry. Tell us what ASO is about?
How was the ASO story received by your customers? Any particular reactions?
Will the ASO narrative inspire the next generation of practitioners? Where do you envision the market headed?
ASO is about transforming the SOC, and that often involves culture change. How do you change the culture and deeper approaches common in security operations?
What else can we do to evolve SOC faster than the threats and assets grow?
Could you explain briefly why identity is so important in the cloud?
A skeptic on cloud security once told us that “in the cloud, we are one identity mistake from a breach.” Is this true?
For listeners who aren’t familiar with GCP, could you give us the 30 second story on “what is a service account.” How is it different from a regular IAM account?
What are service account impersonations?
How can I see if my service accounts can be impersonated? How do I detect it?
How can I better secure my organization from impersonation attacks?