

Cloud Security Podcast by Google
Anton Chuvakin
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure.
We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit.
We hope you'll join us if you're interested in where technology overlaps with process and bumps up against organizational design. We're hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can't keep as the world moves from on-premises computing to cloud computing.
We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit.
We hope you'll join us if you're interested in where technology overlaps with process and bumps up against organizational design. We're hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can't keep as the world moves from on-premises computing to cloud computing.
Episodes
Mentioned books

Jul 12, 2021 • 24min
Securing Multi-Cloud from a CISO Perspective, Part 3
Guests: Phil Venables (@philvenables), Vice President, Chief Information Security Officer (CISO) @ Google Cloud Dave Hannigan, Director, Financial Services Security & Compliance @ Google Cloud Topics: As a CISO, would you ever decide to use multiple clouds, if it were in your hands? How is security typically considered when companies go multi-cloud in their approach? Practically, or operationally, how does one think through securing multiple public cloud environments? What are the top challenges here? Different controls? Lack of tools? Confusing process? Skills on the team? Would you always buy security tools from a 3rd party (not a CSP) if you have to cover more than one cloud provider? Anything to add about compliance across multiple clouds? What is the best approach for securing multiple SaaS services that your company uses? Resources: "IDC: A multicloud strategy can mitigate regulatory, business risks" "Anthos security" SANS papers on securing multiple clouds (example)

Jul 6, 2021 • 24min
Security Marketing? Every Product Needs a Story!
Guest: Kelly Anderson, Head of Product Marketing, User Protection Services @ Google Cloud Topics: What is marketing, really? Why is it sometimes reviled by the technologists? What makes a great marketer in cloud security? What's different about cloud security marketing, as opposed to regular old on-premise security marketing? Is there still FUD in the cloud? Which things are the easiest or hardest to do in Google Cloud Security marketing? How do you talk about products so they stand out from the noise? How's Google Cloud marketing helping our users stay ahead of the adversaries? Resources: Security insights that help customers stay up to date Customer case studies on our security products Quarterly Google Cloud Security Talks Cloud security webinars on BrightTALK and Cloud OnAir Identity and security blogs on the Google Cloud blog

Jun 28, 2021 • 28min
Security Operations, Reliability, and Securing Google with Heather Adkins
Guest: Heather Adkins, Sr Director, Information Security @ Google Topics: Your RSA presentation has 3 pillars: zero trust, microservices, automation/zero prod, is this all you need to be secure & reliable in the modern world? Let's drill down again into the "secure and reliable" concept, are you sure that they are interrelated? Is there a risk that microservices could actually increase attack surface? What are the practical security upsides of "no touch production"? SRE and DevOps revolutionized IT, can we expect a similar revolution for security? Where would it come from? Resources: "Building Secure and Reliable Systems" RSA 2021 presentation by Heather Adkins "Building Secure and Reliable Systems" book (free) "Modern Threat Detection at Google" (ep 17) Google BeyondCorp Google BeyondProd NIST 800-27 "Zero Trust Architecture"

Jun 21, 2021 • 34min
Double-clicking, but not on fire hydrants, with bot fighters
Guest 1: Sparky Toews, Product Manager for Adobe identity @ Adobe Topics 1: Why are bots a problem to you? Give us a bit of your bot threat assessment? Can you tell us how you think about and practice securing the user experience? What kind of security products or best practices are involved? How do you see what security professionals do to secure the user experience evolving over time? Guests 2: Randy Gingeleski, Senior Staff Security Engineer @ HBO Max Brian Lozada, CISO @ HBO Max Topics 2: Can you tell us how you think about and practice securing the user experience at HBO? What kind of security products or best practices are involved? How does reCAPTCHA Enterprise fit into all of this? How do you see what security professionals do to secure the user experience evolving over time?

Jun 14, 2021 • 32min
More Cloud Migration Security Lessons
Guests: Jane Chung, VP of Cloud @ Palo Alto Joe Crawford, Director of Strategic Technology Partnerships for Google Cloud @ Palo Alto Topics: What are the top security mistakes you've seen during cloud migrations? What is your best advice to security leaders who want to go to the cloud using the on-premise playbook? What security technologies may no longer be needed in the cloud? Which are transformed by the cloud? Cloud often implies agility, but sometimes security slows things down, how to fix that? How do security needs change based on adoption architecture (cloud, hybrid with on-premise, multi-cloud, multi cloud with on-premise)? From a security perspective, is there really any such thing as "lift and shift"? How do we teach cloud to security leaders who "grew up" on-premise? Resources: Use "Move and Improve" Instead of "Lift an Shift" "Data Security in the Cloud" (Episode 2) "The Perfect Weapon: War, Sabotage, and Fear in the Cyber Age" book CSA CCM v4

Jun 7, 2021 • 24min
Modern Threat Detection at Google
Guest: Julien Vehent, Security Engineering Manager in the Detection and Response team @ Google Topics: What is special about detecting modern threats in modern environments? How does the Google team turn the knowledge of threats into detection logic? Run through an example of creating a detection for a new threat? How do we test our detection rules? We use the same people to write detections and to respond to resulting alerts, how is it working? What are the key skills of good security analysts to build cloud threat detection? Resources: "Site Reliability Engineering" book (free) "Building Secure & Reliable Systems" book (free) "Securing DevOps" by our very guest Julien Vehent

Jun 1, 2021 • 28min
Modern Data Security Approaches: Is Cloud More Secure?
Guests: Tim Dierks, Engineering Director, Data Protection @ Google Cloud Topics: What are the key components of data security in the public cloud today? Why do companies need specific data security plans and products? Do you think Google Cloud today has enough controls for processing the most sensitive data? Many organizations seem to be unaware of where sensitive data exists in their cloud environments, how do you think this problem will be fixed? What is your view on encryption's role in future cloud security? Do organizations mostly encrypt for security or for compliance? How do we help companies navigate the tradeoffs between complying with nation-state regulations and best practices for availability? I hear you are involved with some interesting key management innovations like HYOK via Cloud EKM, why do these matter for clients today? Resources: Forrester report "The Forrester Wave™: Unstructured Data Security Platforms, Q2 2021" "New whitepaper: Designing and deploying a data security strategy with Google Cloud" "Hold your own key with Google Cloud External Key Manager" "Building Secure and Resilient Systems" book (free)

May 24, 2021 • 21min
Scaling Google Kubernetes Engine Security
Guest: Greg Castle, Senior Staff Security Engineer at Google Topics: How is kubernetes security different from traditional host security? What's different about securing GKE vs security Kubernetes on-prem? Where does one start with security hardening for GKE? In your view, what are top realistic threats to container deployments? What do users get wrong most often? Did we manage to make containers both more secure and more usable?

May 19, 2021 • 20min
Making Compliance Cloud-native
Guest: Zeal Somani, Security Solutions Manager @ Google Cloud, former PCI QSA Topics: What are the usable recipes for thinking about compliance in the cloud? What regulations are more challenging for public cloud users? How do you see the client/provider responsibility split for compliance? What is this "shift left" for compliance? How do we educate auditors and regulators who insist on 1980s solutions to 2020s problems? What are the most popular mistakes and blind spots with trying to be compliant in the cloud? Resources: Whitepaper "Risk governance of digital transformation: guide for risk, compliance & audit teams"

May 10, 2021 • 25min
Application Security in the Cloud
Guest: Alyssa Miller, BISO @ S&P Global Ratings Topics: How do application security practices change as organizations launch their cloud transformations? What bad things happen to you if you lift/shift your big applications to somebody's IaaS? What unique challenges do containers and serverless deployments create for application security? Is there good news here? How can cloud native technologies make application security easier than a traditional on-prem environment? What can organizations do to ensure the security of cloud-based SaaS solutions? How do DevOps and CI/CD impact the ability to secure cloud-based applications? What is your advice to security leaders who still want to practice appsec for cloud apps in the same manner as they did it for on-premise, the old way? What follow-up reading do you recommend on preparing for an application migration to Cloud? Resources: Cloud security trainings DevOps.com


