Cloud Security Podcast by Google

By: Anton Chuvakin
  • Summary

  • Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit. We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.
    Copyright Google Cloud
    Show more Show less
activate_Holiday_promo_in_buybox_DT_T2
Episodes
  • EP199 Your Cloud IAM Top Pet Peeves (and How to Fix Them)
    Nov 18 2024

    Guests:

    • Michele Chubirka, Staff Cloud Security Advocate, Google Cloud
    • Sita Lakshmi Sangameswaran, Senior Developer Relations Engineer, Google Cloud

    Topics:

    • What is your reaction to “in the cloud you are one IAM mistake away from a breach”? Do you like it or do you hate it? Or do you "it depends" it? :-)
    • Everyone's talking about how "identity is the new perimeter" in the cloud. Can you break that down in simple terms?
    • A lot of people say “in the cloud, you must do IAM ‘right’”. What do you think that means? What is the first or the main idea that comes to your mind when you hear it?
    • What’s this stuff about least-privilege and separation-of-duties being less relevant? Why do they matter in the cloud that changes rapidly?
    • What are your IAM Top Pet Peeves?

    Resources:

    • Video (LinkedIn, YouTube)
    • EP127 Is IAM Really Fun and How to Stay Ahead of the Curve in Cloud IAM?
    • EP162 IAM in the Cloud: What it Means to Do It 'Right' with Kat Traxler
    • IAM: There and back again using resource hierarchies
    • IAM so lost: A guide to identity in Google Cloud
    • I Hate IAM: but I need it desperately
    • EP33 Cloud Migrations: Security Perspectives from The Field
    • EP176 Google on Google Cloud: How Google Secures Its Own Cloud Use
    • EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant
    • EP188 Beyond the Buzzwords: Identity's True Role in Cloud and SaaS Security
    • “Identity Crisis: The Biggest Prize in Security” paper
    • “Learn to love IAM: The most important step in securing your cloud infrastructure“ Next presentation
    Show more Show less
    29 mins
  • EP198 GenAI Security: Unseen Attack Surfaces & AI Pentesting Lessons
    Nov 11 2024

    Guests:

    • Ante Gojsalic, Co-Founder & CTO at SplxAI

    Topics:

    • What are some of the unique challenges in securing GenAI applications compared to traditional apps?
    • What current attack surfaces are most concerning for GenAI apps, and how do you see these evolving in the future?
    • Do you have your very own list of top 5 GenAI threats? Everybody seem to!
    • What are the most common security mistakes you see clients make with GenAI?
    • Can you explain the main goals when trying to add automation to pentesting for next-gen GenAI apps?
    • What are your AI testing lessons from clients so far?

    Resources:

    • EP171 GenAI in the Wrong Hands: Unmasking the Threat of Malicious AI and Defending Against the Dark Side
    • EP135 AI and Security: The Good, the Bad, and the Magical
    • EP185 SAIF-powered Collaboration to Secure AI: CoSAI and Why It Matters to You
    • SAIF.google
    • Next SAIF presentation with top 5 AI security issues
    • Our Security of AI Papers and Blogs Explained

    Show more Show less
    27 mins
  • EP197 SIEM (Decoupled or Not), and Security Data Lakes: A Google SecOps Perspective
    Nov 4 2024

    Guest:

    • Travis Lanham, Uber Tech Lead (UTL) for Security Operations Engineering, Google Cloud

    Topics:

    • There’s been a ton of discussion in the wake of the three SIEM week about the future of SIEM-like products. We saw a lot of takes on how this augurs the future of disassembled or decoupled SIEMs. Can you explain what these disassembled SIEMs are all about?
    • What are the expected upsides of detaching your SIEM interface and security capabilities from your data backend?
    • Tell us about the early days of SecOps (nee Chronicle) and why we didn’t go with this approach?
    • What are the upsides of a tightly coupled datastore + security experience for a SIEM?
    • Are there more risks or negatives of the decoupled/decentralized approach? Complexity and the need to assemble “at home” are on the list, right?
    • One of the 50 things Google knew to be true back in the day was that product innovation comes from technical innovation, what’s the technical innovation driving decoupled SIEMs?
    • So what about those security data lakes? Any insights?

    Resources:

    • EP139 What is Chronicle? Beyond XDR and into the Next Generation of Security Operations
    • EP190 Unraveling the Security Data Fabric: Need, Benefits, and Futures
    • EP184 One Week SIEM Migration: Fact or Fiction?
    • Hacking Google video series
    • Decoupled SIEM: Brilliant or …. Not :-)
    • UNC5537 Targets Snowflake Customer Instances for Data Theft and Extortion
    • So, Why Did I Join Chronicle Security? (2019)
    Show more Show less
    30 mins

What listeners say about Cloud Security Podcast by Google

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.