Join your hosts, Anton Chuvakin and Timothy Peacock, as they talk with industry experts about some of the most interesting areas of cloud security. If you like having threat models questioned and a few bad puns, please tune in!
NEXT Special - Google Cybersecurity Action Team: What's the Story?
Guest:
Phil Venables (@philvenables), Vice President, Chief Information Security Officer (CISO) @ Google Cloud
23:23
Topics covered:
We are here to talk Google Cybersecurity Action Team, and this is your brainchild, so tell our audience the origin of this idea?
How is Cybersecurity Action Team going to help secure GCP enterprise clients?
Is there also a broader “improve the security of the internet” story?
Many organizations seem stuck in the pre-cloud thinking and mental models, can Cybersecurity Action Team help them transform their security? How?
When we sometimes present our security innovations to clients, they say “but we are not Google”, so how does Cybersecurity Action Team help us bring more of Google Cybersecurity to the world?
What else do we plan to do with Cybersecurity Action Team to help customers modernize their security?
How should customers engage with Cybersecurity Action Team?
Attack Surface Management (ASM). Why do we need a new toolset and a new category? Isn’t this just 1980s asset management or CMDB?
How do we find those assets that may have been misplaced by the organizations? How can any technology do this reliably?
ASM seems to often rely on network layer 3 and 4. Can’t bad guys just hit the app endpoints and all your network is irrelevant then?
When you think about the threats organizations face due to unknown assets, is data theft at the top of the stack? What should organizations keep in mind as a priority here?
Who at an organization is best set up to receive, triage, investigate, and respond to the alerts about the attack surface?
Are there proactive steps organizations can take to prevent shadow IT, or are we stuck responding to each new signal? Isn’t preventing new assets the same as preventing business?
What was your journey into writing this book, how long did it take?
The book seems to be targeted towards Cloud Architects, but you come from a predominantly security background, how has that influenced your writing of this book?
What does this have to do with The Certs Guy (14 certs!?) and what's his mission?
What’s the intersectional thinking on certificates and making our industry more accessible and inclusive? Do certs help or hurt this?
So what’s your advice on certs for various career stages?
What are some of the biggest architectural challenges you’ve seen in the field of Cloud Security?