

Real-World Cloud Security Challenges and Solutions Explained for 2024
17 snips May 21, 2024
Experienced cloud security experts Rich Mogull and Chris Farris share insights on effective cloud security strategies, moving beyond vulnerabilities. They discuss the Universal Threat Actor Model, practical steps in cloud environments, and managing a large volume of CSPM findings. The podcast also explores real-world security breaches, triaging, and automation of security responses, along with the speakers' diverse hobbies and favorite cuisines.
AI Snips
Chapters
Transcript
Episode notes
Start by Orienting Yourself
- When dropped into a new cloud environment, first orient yourself politically and technically.
- Identify governance structures and ownership before addressing technical security holes.
Zero-Days Are Rare Distractions
- Zero-day vulnerabilities exist but are rare and usually undisclosed publicly.
- Focus on what you can control instead of chasing every vulnerability.
Focus on Big Security Holes
- Use your CSPM tool for threat hunting, focusing first on critical issues.
- Fix big gaping security holes like public S3 buckets before worrying about everything.