Cloud Security Podcast

CNAPPs & CSPMs don’t tell the full cloud security story

16 snips
Mar 13, 2025
Nick Jones, Head of Research at WithSecure and an offensive cloud security expert, dives deep into the often overlooked aspects of cloud security. He explains why relying solely on CNAPPs and CSPMs can leave critical gaps. Nick reveals the biggest cloud attack paths and discusses how cloud pentesting differs from traditional methods. He emphasizes identity management's role over direct attacks, challenges common security misconceptions, and shares real-world insights from red team engagements to bolster organizational defenses.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Unexpected Azure

  • Nick Jones's first cloud experience involved a client's unexpected Azure network.
  • This led him to explore AWS and eventually lead WithSecure's cloud security team.
INSIGHT

Cloud Security Maturation

  • Cloud security has matured significantly since 2016, with increased specialization and better tooling.
  • Organizations now recognize the need for dedicated cloud security experts, unlike the earlier lift-and-shift mindset.
INSIGHT

Penetration Testing Value

  • CSPMs and CNAPPs excel at identifying misconfigurations but often lack contextualization.
  • Penetration testing provides context, focusing on real-world attack paths and offering tailored remediation advice.
Get the Snipd Podcast app to discover more snips from this episode
Get the app