

Cloud Security Podcast by Google
Anton Chuvakin
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure.
We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit.
We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.
We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit.
We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.
Episodes
Mentioned books

10 snips
Oct 23, 2023 • 29min
EP144 LLMs: A Double-Edged Sword for Cloud Security? Weighing the Benefits and Risks of Large Language Models
Kathryn Shih, Group Product Manager in Google Cloud Security, discusses the capabilities and risks of Large Language Models (LLMs). Topics covered include understanding LLMs, their association with intelligence, risks of model tuning, data access control, and security considerations. The podcast provides insights into the nuances and challenges of working with LLMs and offers tips for improving outcomes with them.

Oct 16, 2023 • 26min
EP143 Cloud Security Remediation: The Biggest Headache?
In this episode, Tomer Schwartz, CTO at Dazz, discusses the challenges of cloud security remediation, including detecting vulnerabilities, overcoming process breakdowns, and addressing automation. The chapter topics cover difficulties in vulnerability management, patching containers, and the need for alignment between security and development teams.

9 snips
Oct 9, 2023 • 33min
EP142 Cloud Security Podcast Ask Me Anything #AMA 2023
Guests Anton Chuvakin and Tim Peacock discuss their journeys into security, the '3am test' for effective alerts, sourcing topics for the podcast, and hopes for the future of security.

Oct 2, 2023 • 25min
EP141 Cloud Security Coast to Coast: From 2015 to 2023, What's Changed and What's the Same?
Jeremiah Kung, Global Head of Information Security at AppLovin, discusses East vs West CISO mentality and the cloud's impact on security. He shares lessons from cloud migrations in 2015 and offers advice for securing clouds in 2023. Kung also provides tips for collaborative mindset and transforming outdated security technology stack.

Sep 25, 2023 • 27min
EP140 System Hardening at Google Scale: New Challenges, New Solutions
Guest: Andrew Hoying, Senior Security Engineering Manager @ Google Topics: What is different about system hardening today vs 20 years ago? Also, what is special about hardening systems at Google massive scale? Can I just apply CIS templates and be done with it? Part of hardening has to be following up with developers after they have un-hardened things – how do we operationalize that at scale without getting too much in the way of productivity? A part of hardening has got to be responding to new regulation and compliance regimes, how do you incorporate new controls and stay responsive to the changing world around us? Are there cases where we have taken lessons from hardening at scale and converted those into product improvements? What metrics do you track to keep your teams moving, and what metrics do your leads look at to understand how you’re doing? [Spoiler: the answer here is VERY fun!] Resources: “Why Shared Fate is a Better Way to Manage Cloud Risk” article (and this too) CIS for GCP GCP IAM Deny CloudSecList by Marco Lancini

Sep 18, 2023 • 24min
EP139 What is Chronicle? Beyond XDR and into the Next Generation of Security Operations
The podcast discusses Chronicle, the Mandiant acquisition, and the balance between products and practices in security operations. They explore leveraging expertise for Chronicle's market position and offer advice for security professionals transitioning into product management.

14 snips
Sep 11, 2023 • 30min
EP138 Terraform for Security Teams: How to Use IaC to Secure the Cloud
Guest Rosemary Wang, Developer Advocate at HashiCorp, discusses using Terraform for security automation, applying security best practices, and the relationship between Terraform and policy as code. Tips for getting started and recommendations for enhancing security journey with Terraform are also shared.

Sep 5, 2023 • 24min
EP137 Next 2023 Special: Conference Recap - AI, Cloud, Security, Magical Hallway Conversations
Guests: no guests, all banter, all very fun :-) Topics: How is Google Next this year? What is new in cloud security? Is Google finally a security vendor? What are some of the fun security presentations we've seen, including our own? Any impactful launches in security? What was the most interesting overall? Resources: “Next 2023 Special: Building AI-powered Security Tools - How Do We Do It?” (ep136) “RSA 2023 - What We Saw, What We Learned, and What We're Excited About” (ep119) “Cyber Defense Matrix and Does Cloud Security Have to DIE to Win?” (ep67) “Detecting, investigating, and responding to threats in your Google Cloud environment” at Cloud Next 2023 by Anton “Prevent cloud compromises: Learn how Uber discovers cyber risks and remediates threats” at Cloud Next 2023 by Tim “Generative AI for defenders with Sec-PaLM 2 and Duet AI” at Cloud Next 2023 by Eric Doerr (his episode) “A blueprint for modern security operations” at Cloud Next 2023 by our future guest, Chris… Kevin Mandia at Next keynote (start at 1:15:00) “New AI capabilities that can help address your security challenges” blog

Aug 28, 2023 • 22min
EP136 Next 2023 Special: Building AI-powered Security Tools - How We Do It?
Eric Doerr, VP of Engineering at Google Cloud Security, discusses the exciting prospects of using AI for security and trusting AI in the business context. They also explore threat modeling AI systems and the worst security use cases for GenAI. Teaching AI security and the surprising challenges involved are also covered.

Aug 21, 2023 • 26min
EP135 AI and Security: The Good, the Bad, and the Magical
Phil Venables, Google Cloud's Chief Information Security Officer, discusses the game-changing potential of AI in cybersecurity. Topics include the impact of AI and machine learning on security, the use of generative AI to enhance productivity and secure software development, and the asymmetry between attackers and defenders in AI systems. The concept of shared faith in securing AI and the intersection of AI, security, and board governance are also explored.