Cloud Security Podcast cover image

Cloud Security Podcast

CNAPPs & CSPMs don’t tell the full cloud security story

Mar 13, 2025
Nick Jones, Head of Research at WithSecure and an offensive cloud security expert, dives deep into the often overlooked aspects of cloud security. He explains why relying solely on CNAPPs and CSPMs can leave critical gaps. Nick reveals the biggest cloud attack paths and discusses how cloud pentesting differs from traditional methods. He emphasizes identity management's role over direct attacks, challenges common security misconceptions, and shares real-world insights from red team engagements to bolster organizational defenses.
49:23

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • Cloud Security Posture Management (CSPM) significantly enhances penetration testing by enabling focused identification of vulnerabilities in cloud environments.
  • Organizations must adopt a distinct mindset towards cloud security, recognizing that traditional measures are insufficient and that identity is the new perimeter.

Deep dives

The Role of CSPM in Pen Testing

Providing Cloud Security Posture Management (CSPM) output significantly enhances the effectiveness of penetration testing. By sharing this data, organizations enable testers to easily identify what's covered and which vulnerabilities remain. Including CSPM findings in the report allows for a more informed assessment of critical security issues that could impact attack paths. This collaborative approach can streamline the pen testing process and yield more actionable insights for remediation.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner