Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!
What’s top of mind for healthcare organizations’ CISOs now?
What common advice do you find yourself giving most often to security leaders in healthcare? Is there a list of top 3 items or is this all “it depends”?
What regulations are shaping the healthcare industry and its adoption of new technology? HIPAA is from 1996, how does it work for the cloud in the 2020s?
Why do you think we aren’t seeing more cloud ransomware?
Healthcare orgs are sometimes seen as “IT laggards”, what are the key security lessons from their cloud migrations?
How do we convince some of these organizations that cloud is more secure as long as they use it securely?
EP47 Megatrends, Macro-changes, Microservices, Oh My! Changes in 2022 and Beyond in Cloud Security
Guest:
Phil Venables (@philvenables), Vice President, Chief Information Security Officer (CISO) @ Google Cloud
30:33
Topics covered:
Explain the whole cloud security megatrend concept to us?
How can we better explain that “yes, cloud is more secure than most client’s data centers”?
Could you please explain "shared fate" one more time?
Shared fate seems to require shared incentives. Do we see the incentives to invest in security changing within organizations migrating to Cloud?
"Cloud as the Digital Immune System" concept sounds really cool, what does it mean for a typical practitioner - security and developers both?
What about the risk aggregation (eggs in one basket) argument against relying on CSP for all security?
Does software sovereignty mean that Cloud providers are always going to be held to common standards and lose out on the opportunity to sell highly differentiated software on top?
EP46 Products and Solutions: Helping Our Customers Precipitate Change
Guests:
Alison Reyes, Director, Security Solutions, Google Cloud
Iman Ghanizada, Solutions Manager for Security Operations & Analytics @ Google Cloud
23:23
Topics covered:
What is our thinking on solutions vs products for security? Sure, “security is a process, not a product,” but where do solutions fit in?
Security as an industry has too many vendors with little understanding of how users secure things, can solutions approach fix that?
Google is sometimes known for writing code and just throwing it out there, do solutions change that dynamic for Google Cloud clients who come to us for security?
Who are the target users for our security solutions? Why did we choose those solutions and not others?
To me, solutions is how our products actually live in the real world. But can we really hope to transform customer operations with solutions?
One of the solutions dear to my heart is Autonomic Security Operations that seeks to “10X the SOC”, how was the experience so far? Is 10X real and what does it mean?
How do we know if we succeeded, what are metrics for solutions?
EP43 Automation as Paved Roads in Cloud Enablement
Guests:
Amber Shafi, Product Manager GSK
Svetlin Zamfirov, Senior Platform Engineer at GSK
Ivan Angelov, Principal Platform Engineer at GSK
25;23
Topics covered:
Tell us about your team, what are you responsible for and how is the team setup to make that happen? What components of cloud security do you cover?
Tell us about cloud misconfigurations and why these are different from on- premise misconfiguration?
How are you discovering these misconfigurations?
You've automated responses to misconfiguration. Beyond the obvious upsides of reducing team toil and time to response, what are the other benefits? Are there risk in this approach and how are they handled?
How did this idea to automate come about, and what lessons did you learn along the way?
How have you integrated with the cloud provider security tooling?
Why is there such a huge gap in security professionals who are women and people of color?
How does the lack of women and people of color in tech impact the industry, cybersecurity & tech overall? Are diverse teams better performing, better morale, happier people?
Are there kinds of threats that we miss in threat modeling exercises for lack of diverse team members?
We’ve seen countless examples where AI/ML systems have had problems with laundering biases and having frankly appalling issues due to biased training data. What are security implications here?
Are there organizations helping to close the representation gap in the security workforce and the cloud workforce?
Why do the big tech companies and even the smaller ones have trouble identifying diverse talent? Why is this hard even for people and organizations who clearly want to improve it?
Why do companies have a hard time retaining diverse talent?
When we think about traditional email security, we think anti-spam/phishing. Your company is doing other things, so what are they? In other words, isn’t email security solved with legacy appliance vendors (SEG) and cloud email providers?
What was the combination of technology and security opportunities that really resonated with you and your investors that led to your focus on email security?
Security has almost 2000 vendors and they are noisy, how do you get to clients without screaming too loud? How do you build a better security vendor?
Related to being better vendors, but more broadly, what can we do as an industry to make it easier to buy and get value out of our investments in new security tooling and technology?
How can we build security tooling that requires less of our precious security team’s time?