
Cloud Security Podcast by Google
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure.
We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit.
We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.
Latest episodes

10 snips
Apr 22, 2024 • 28min
EP169 Google Cloud Next 2024 Recap: Is Cloud an Island, So Much AI, Bots in SecOps
The hosts recap Google Cloud Next 2024, highlighting fun security launches, favorite sessions, and new security ideas inspired by the event. They discuss the evolution of cloud-native security, explore new security vendors and the CNAB framework, and delve into the interplay of cloud security, AI, and emerging threats. They also touch on embracing curiosity in technology and science fiction.

13 snips
Apr 15, 2024 • 33min
EP168 Beyond Regular LLMs: How SecLM Enhances Security and What Teams Can Do With It
Join Umesh Shankar and Scott Coull as they discuss teaching AI security, the benefits of security-trained LLMs, the practical applications for security teams, and the feedback on impact. Explore the limitations of LLMs for security tasks and the importance of task-specific training. Delve into using cloud audit logs for anomaly detection and the challenges of intelligent summarization in the security context.

10 snips
Apr 8, 2024 • 25min
EP167 Stolen Cards and Fake Accounts: Defending Google Cloud Against Abuse
Guest Maria Riaz, an Engineering Lead at Google Cloud, discusses counter-abuse and security on GCP, dealing with stolen cards, and relevant competencies for this field. They explore academic vs industry experience, popular abuse types like coin mining, and innovative abuse strategies at Google, emphasizing problem-solving and user safety.

15 snips
Apr 1, 2024 • 30min
EP166 Workload Identity, Zero Trust and SPIFFE (Also Turtles!)
Guests Evan Gilman and Eli Nesterov discuss workload identity, zero trust, and SPIFFE in a lively podcast. They delve into the challenges faced by large organizations, the benefits of adopting modern security paradigms like SPIFFE, and the importance of reimagining traditional technologies for cloud environments. The conversation also touches on the concept of 'solving the bottom turtle' in workload identity and security.

5 snips
Mar 25, 2024 • 25min
EP165 Your Cloud Is Not a Pet - Decoding 'Shifting Left' for Cloud Security
Ahmad Robinson, Cloud Security Architect at Google, discusses 'Pets vs Cattle' mentality in cloud operations, shifting left in cloud security, and the confusion around Policy as Code. He emphasizes the importance of scalability, standardization, and collaboration among teams for efficient security practices.

10 snips
Mar 18, 2024 • 31min
EP164 Quantum Computing: Understanding the (very serious) Threat and Post-Quantum Cryptography
Exploring the looming threats of quantum computing on cryptography, the podcast delves into the urgency of adopting post-quantum algorithms. NIST standards, skepticism vs. reality in quantum computing, and proactive data safeguarding measures are discussed. The importance of discerning truth from hype and practical tips on post-quantum cryptography are highlighted.

6 snips
Mar 11, 2024 • 26min
EP163 Cloud Security Megatrends: Myths, Realities, Contentious Debates and Of Course AI
Exploring cloud security megatrends with a focus on AI integration, governance, and AI for security. Discussing the contentious nature of certain megatrends, the simplicity of cloud over on-premise IT, and the role of AI in enhancing security practices. Delving into questions CISOs should be asking about AI and the transformative potential of AI in improving data governance and scalability.

10 snips
Mar 4, 2024 • 28min
EP162 IAM in the Cloud: What it Means to Do It 'Right' with Kat Traxler
Explore the complexities of IAM in cloud security with expert Kat Traxler. Discuss why people still struggle with IAM mistakes, resource hierarchy, and management. Learn about the importance of assigning roles at the lowest resource-level possible and how the 'big 3' got it wrong.

Feb 26, 2024 • 28min
EP161 Cloud Compliance: A Lawyer - Turned Technologist! - Perspective on Navigating the Cloud
Guest: Victoria Geronimo, Cloud Security Architect, Google Cloud Topics: You work with technical folks at the intersection of compliance, security, and cloud. So what do you do, and where do you find the biggest challenges in communicating across those boundaries? How does cloud make compliance easier? Does it ever make compliance harder? What is your best advice to organizations that approach cloud compliance as they did for the 1990s data centers and classic IT? What has been the most surprising compliance challenge you’ve helped teams debug in your time here? You also work on standards development –can you tell us about how you got into that and what’s been surprising in that for you? We often say on this show that an organization’s ability to threat model is only as good as their team’s perspectives are diverse: how has your background shaped your work here? Resources: Video (YouTube) EP14 Making Compliance Cloud-native EP25 Beyond Compliance: Cloud Security in Europe Fordham University Law and Technology site IAPP site

Feb 19, 2024 • 28min
EP160 Don't Cloud Your Judgement: Security and Cloud Migration, Again!
Guest: Merritt Baer, Field CTO, Lacework, ex-AWS, ex-USG Topics: How can organizations ensure that their security posture is maintained or improved during a cloud migration? Is cloud migration a risk reduction move? What are some of the common security challenges that organizations face during a cloud migration? Are there different gotchas between the three public clouds? What advice would you give to those security leaders who insist on lift/shift or on lift/shift first? How should security and compliance teams approach their engineering and DevOps colleagues to make sure things are starting on the right foot? In your view, what is the essence of a cloud-native approach to security? How can organizations ensure that their security posture scales as their cloud usage grows? Resources: Video (LinkedIn, YouTube) EP69 Cloud Threats and How to Observe Them EP138 Terraform for Security Teams: How to Use IaC to Secure the Cloud EP67 Cyber Defense Matrix and Does Cloud Security Have to DIE to Win? 9 Megatrends drive cloud adoption—and improve security for all Darknet Diaries podcast
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.