

EP193 Inherited a Cloud? Now What? How Do I Secure It?
15 snips Oct 7, 2024
Taylor Lehmann, Director at the Office of the CISO, and Luis Urena, Cloud Security Architect at Google Cloud, tackle the complexities of securing inherited cloud environments. They discuss the risks of late security team involvement and the impracticality of drastic measures like 'nuking' the environment. Instead, they offer strategic steps for immediate security improvements, such as managing overly permissive roles. They also evaluate the necessity of compromise assessments and the balance between current priorities and securing new systems.
AI Snips
Chapters
Transcript
Episode notes
Inherited Cloud Anecdotes
- Taylor Lehmann shared anecdotes about inheriting cloud environments.
- These included mergers and acquisitions, new cloud adoption, and surprise discoveries during incident response.
Startup Security
- Luis Urena discussed working with startups that prioritized growth over security.
- These companies later faced market risks when targeting regulated industries, leading them to address security.
Treat as Incident
- Treat inheriting a cloud environment like an incident response.
- Gain control, assess risks, and follow your incident response playbook.