Cloud Security Podcast by Google cover image

Cloud Security Podcast by Google

Latest episodes

undefined
8 snips
Sep 2, 2024 • 29min

EP188 Beyond the Buzzwords: Identity's True Role in Cloud and SaaS Security

In a compelling discussion with Dor Fledel, founder and CEO of Spera Security, he dives into the nuanced role of identity in cloud security. He explains the challenges of identity management, addressing concepts like 'identity management debt.' Fledel shares advice on how organizations can navigate this debt while stressing the importance of monitoring user identities, service accounts, and API keys. He also offers insights for founders transitioning from startup to acquisition, emphasizing the need for focus and repeatability in security practices.
undefined
11 snips
Aug 26, 2024 • 30min

EP187 Conquering SOC Challenges: Leadership, Burnout, and the SIEM Evolution

Nicole Beckwith, a Sr. Security Engineering Manager at Kroger, shares her insights into leading successful Security Operations Centers. She emphasizes the importance of self-leadership and adaptability in fostering high-functioning teams while tackling burnout. Nicole discusses innovative, human-centric hiring strategies that value unique qualities over traditional metrics. She also dives into the evolution of SIEM technology, highlighting its transition towards AI-driven solutions. Finally, she outlines a strategic 70-30-90 day plan for new SOC leaders to ensure effective transitions.
undefined
4 snips
Aug 19, 2024 • 27min

EP186 Cloud Security Tools: Trust the Cloud Provider or Go Third-Party? An Epic Debate, Anton vs Tim

Tim, a cloud security advocate, and Anton, a proponent of third-party solutions, engage in a compelling debate on cloud security tools. They explore the merits of relying on cloud providers versus independent vendors, discussing trust, flexibility, and essential security principles. The duo dives into strategies for navigating multi-cloud environments and emphasizes the importance of evaluating specific security needs. With lively exchanges, they encourage listeners to reflect on their own security practices while recommending intriguing readings to further delve into the topic.
undefined
Aug 12, 2024 • 24min

EP185 SAIF-powered Collaboration to Secure AI: CoSAI and Why It Matters to You

Guest:  David LaBianca, Senior Engineering Director, Google  Topics: The universe of AI risks is broad and deep. We’ve made a lot of headway with our SAIF framework: can you give us a) a 90 second tour of SAIF and b) share how it’s gotten so much traction and c) talk about where we go next with it? The Coalition for Secure AI (CoSAI) is a collaborative effort to address AI security challenges. What are Google's specific goals and expectations for CoSAI, and how will its success be measured in the long term? Something we love about CoSAI is that we involved some unexpected folks, notably Microsoft and OpenAI. How did that come about? How do we plan to work with existing organizations, such as Frontier Model Forum (FMF) and Open Source Security Foundation (OpenSSF)? Does this also complement emerging AI security standards? AI is moving quickly. How do we intend to keep up with the pace of change when it comes to emerging threat techniques and actors in the landscape? What do we expect to see out of CoSAI work and when? What should people be looking forward to and what are you most looking forward to releasing from the group? We have proposed projects for CoSAI, including developing a defender's framework and addressing software supply chain security for AI systems. How can others use them?  In other words, if I am a mid-sized bank CISO, do I care? How do I benefit from it? An off-the-cuff question, how to do AI governance well?  Resources: CoSAI site, CoSAI 3 projects SAIF main site Gen AI governance: 10 tips to level up your AI program “Securing AI: Similar or Different?” paper Our Security of AI Papers and Blogs Explained  
undefined
Aug 5, 2024 • 25min

EP184 One Week SIEM Migration: Fact or Fiction?

Manan Doshi, a Senior Security Engineer at Etsy, shares insights on the challenges of migrating to a new SIEM platform. He discusses key hurdles organizations face and debunks myths surrounding flawed tools, emphasizing the importance of processes. Manan reveals the exciting prospect of completing a SIEM migration in just one week and explores the role of AI and 'Detection as Code' in enhancing detection logic. His focus on community insights and strategic planning highlights how a strong engineering culture can transform security operations.
undefined
10 snips
Jul 29, 2024 • 30min

EP183 Cloud Security Journeys: Improve, Evolve, Transform with Cloud Customers

Jaffa Edwards, a Senior Security Manager, and Lyka Segura, a Cloud Security Engineer at Google Cloud, dive into the challenges of cloud security transformation. They share their secrets for effectively tailoring security solutions to diverse customer needs. The duo discusses common pitfalls organizations face when transitioning from on-premises to cloud systems and the cultural shifts required for success. They offer invaluable advice for those starting their cloud security journeys, emphasizing proactive education and adapting security practices to modern environments.
undefined
7 snips
Jul 22, 2024 • 28min

EP182 ITDR: The Missing Piece in Your Security Puzzle or Yet Another Tool to Buy?

Guest Adam Bateman, Co-founder of Push Security, discusses ITDR: its definition, benefits, and alternatives. Topics include workload vs human identity ITDR, common threats detected, and advice for implementation. The podcast explores the evolution of ITDR, its relationship with other security categories, advantages of browser telemetry, and specific threats addressed by ITDR tools.
undefined
13 snips
Jul 15, 2024 • 31min

EP181 Detection Engineering Deep Dive: From Career Paths to Scaling SOC Teams

Zack Allen, Senior Director at Datadog, discusses challenges in detection engineering and advice for aspiring engineers. Topics include the role of detection engineers, balancing vendor-made vs. custom detections, and tips for building effective detection rules. The podcast explores the importance of connecting detection efforts with business objectives and provides recommended reading materials to enhance detection engineering skills.
undefined
Jul 8, 2024 • 28min

EP180 SOC Crossroads: Optimization vs Transformation - Two Paths for Security Operations Center

Guests: Mitchell Rudoll, Specialist Master, Deloitte Alex Glowacki, Senior Consultant, Deloitte Topics: The paper outlines two paths for SOCs: optimization or transformation. Can you elaborate on the key differences between these two approaches and the factors that should influence an organization's decision on which path to pursue?  The paper also mentions that alert overload is still a major challenge for SOCs. What are some of the practices that work in 2024 for reducing alert fatigue and improving the signal-to-noise ratio in security signals? You also discuss the importance of automation for SOCs. What are some of the key areas where automation can be most beneficial, and what are some of the challenges of implementing automation in SOCs? Automation is often easier said than done… What specific skills and knowledge will be most important for SOC analysts in the future that people didn’t think of 5-10 years ago? Looking ahead, what are your predictions for the future of SOCs? What emerging technologies do you see having the biggest impact on how SOCs operate?  Resources: “Future of the SOC: Evolution or Optimization —Choose Your Path” paper and highlights blog “Meet the Ghost of SecOps Future” video based on the paper EP58 SOC is Not Dead: How to Grow and Develop Your SOC for Cloud and Beyond The original Autonomic Security Operations (ASO) paper (2021) “New Paper: “Future of the SOC: Forces shaping modern security operations” (Paper 1 of 4)” “New Paper: “Future of the SOC: SOC People — Skills, Not Tiers” (Paper 2 of 4)” “New Paper: “Future Of The SOC: Process Consistency and Creativity: a Delicate Balance” (Paper 3 of 4)”
undefined
Jul 1, 2024 • 23min

EP179 Teamwork Under Stress: Expedition Behavior in Cybersecurity Incident Response

Guests, Robin Shostack & Jibran Ilyas, discuss expedition behavior in cybersecurity incident response. Topics include teamwork under stress, applying knowledge to security teams, fostering expeditionary behavior, and creating it in new/existing teams. Emphasizes the significance of teamwork, communication, and trust for successful incident resolution.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode