Cloud Security Podcast by Google

Anton Chuvakin
undefined
Nov 25, 2024 • 28min

EP200 Zero Touch Prod, Security Rings, and Foundational Services: How Google Does Workload Security

Guest: Michael Czapinski, Security & Reliability Enthusiast, Google Topics: "How Google protects its production services" paper covers how Google's infrastructure balances several crucial aspects, including security, reliability, development speed, and maintainability. How do you prioritize these competing demands in a real-world setting? What attack vectors do you consider most critical in the production environment, and how has Google's defenses against these vectors improved over time? Can you elaborate on the concept of Foundational services and their significance in Google's security posture? How does your security approach adapt to this vast spectrum of sensitivity and purpose of our servers and services, actually? How do you implement this principle of zero touch prod for both human and service accounts within our complex infrastructure? Can you talk us through the broader approach you take through Workload Security Rings and how this helps? Resources: "How Google protects its production services" paper (deep!) SLSA framework EP189 How Google Does Security Programs at Scale: CISO Insights EP109 How Google Does Vulnerability Management: The Not So Secret Secrets! EP176 Google on Google Cloud: How Google Secures Its Own Cloud Use EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil SREcon presentation on zero touch prod. The SRS book (free access)
undefined
Nov 18, 2024 • 29min

EP199 Your Cloud IAM Top Pet Peeves (and How to Fix Them)

Guests: Michele Chubirka, Staff Cloud Security Advocate, Google Cloud Sita Lakshmi Sangameswaran, Senior Developer Relations Engineer, Google Cloud Topics: What is your reaction to "in the cloud you are one IAM mistake away from a breach"? Do you like it or do you hate it? Or do you "it depends" it? :-) Everyone's talking about how "identity is the new perimeter" in the cloud. Can you break that down in simple terms? A lot of people say "in the cloud, you must do IAM 'right'". What do you think that means? What is the first or the main idea that comes to your mind when you hear it? What's this stuff about least-privilege and separation-of-duties being less relevant? Why do they matter in the cloud that changes rapidly? What are your IAM Top Pet Peeves? Resources: Video (LinkedIn, YouTube) EP127 Is IAM Really Fun and How to Stay Ahead of the Curve in Cloud IAM? EP162 IAM in the Cloud: What it Means to Do It 'Right' with Kat Traxler IAM: There and back again using resource hierarchies IAM so lost: A guide to identity in Google Cloud I Hate IAM: but I need it desperately EP33 Cloud Migrations: Security Perspectives from The Field EP176 Google on Google Cloud: How Google Secures Its Own Cloud Use EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant EP188 Beyond the Buzzwords: Identity's True Role in Cloud and SaaS Security "Identity Crisis: The Biggest Prize in Security" paper "Learn to love IAM: The most important step in securing your cloud infrastructure" Next presentation
undefined
11 snips
Nov 11, 2024 • 27min

EP198 GenAI Security: Unseen Attack Surfaces & AI Pentesting Lessons

Ante Gojsalic, Co-Founder & CTO at SplxAI, dives into the intricacies of securing generative AI applications. He outlines the unique challenges of penetration testing in this realm, such as non-determinism and the complex interplay of data and applications. Ante discusses the most concerning current attack surfaces and shares his insights on common security mistakes companies make. He emphasizes the importance of blending automated pentesting with human expertise and offers practical strategies for learning about AI security. Tune in for crucial tips on navigating this evolving landscape!
undefined
31 snips
Nov 4, 2024 • 30min

EP197 SIEM (Decoupled or Not), and Security Data Lakes: A Google SecOps Perspective

Travis Lanham, Uber Tech Lead for Security Operations Engineering at Google Cloud, dives deep into the future of SIEM-like products. He discusses the concept of disassembled SIEMs and their potential advantages, like separating security capabilities from data backends. Lanham reflects on the early days of SecOps and shares why a tightly coupled approach was preferred. He examines the complexities of decentralized systems and their implications. The conversation also touches on innovations driving decoupled SIEMs and insights into security data lakes.
undefined
6 snips
Oct 28, 2024 • 28min

EP196 AI+TI: What Happens When Two Intelligences Meet?

Vijay Ganti, Director of Product Management at Google Cloud Security, dives into the world of threat intelligence and AI-driven security. He addresses the challenges organizations face in utilizing threat intelligence effectively, highlighting the need for better integration. Vijay discusses the revolutionary impact of AI on threat detection and the crucial balance between human expertise and automation. The conversation also emphasizes the importance of staying updated with AI research to enhance understanding and application in the field.
undefined
10 snips
Oct 21, 2024 • 41min

EP195 Containers vs. VMs: The Security Showdown!

Michele Chubirka, a Cloud Security Advocate at Google Cloud with a rich background in finance and academia, delves into the security dynamics between containers and virtual machines. She discusses the implications of attack surfaces, patch speed, and the complexities of misconfigurations in orchestrators. Michele shares strategies for organizations to effectively balance the strengths and vulnerabilities of both technologies. With insights on the future interplay of containers, VMs, and WebAssembly, she inspires a proactive approach to evolving security challenges.
undefined
6 snips
Oct 14, 2024 • 31min

EP194 Deep Dive into ADR - Application Detection and Response

Daniel Shechter, Co-founder and CEO at Miggo Security, dives into the world of Application Detection and Response (ADR), highlighting its essential role in addressing today's complex cloud application threats. He explains how ADR differs from traditional EDR and CDR tools, emphasizing the need for contextual insights that improve security monitoring. Shechter also tackles the challenges of automation and collaboration in application security, offering real-world examples of ADR in action. Discover how ADR enhances visibility and efficiency for security teams facing evolving vulnerabilities.
undefined
15 snips
Oct 7, 2024 • 31min

EP193 Inherited a Cloud? Now What? How Do I Secure It?

Taylor Lehmann, Director at the Office of the CISO, and Luis Urena, Cloud Security Architect at Google Cloud, tackle the complexities of securing inherited cloud environments. They discuss the risks of late security team involvement and the impracticality of drastic measures like 'nuking' the environment. Instead, they offer strategic steps for immediate security improvements, such as managing overly permissive roles. They also evaluate the necessity of compromise assessments and the balance between current priorities and securing new systems.
undefined
Sep 30, 2024 • 33min

EP192 Confidential + AI: Can AI Keep a Secret?

Guest: Nelly Porter, Director of PM, Cloud Security at Google Cloud Topics: Share your story and how you ended here doing confidential AI at Google? What problem does confidential compute + AI solve and for what clients? What are some specific real-world applications or use cases where you see the combination of AI and confidential computing making the most significant impact? What about AI in confidential vs AI on prem? Should those people just do on-prem AI instead? Which parts of the AI lifecycle need to be run in Confidential AI: Training? Data curation? Operational workloads? What are the performance (and thus cost) implications of running AI workloads in a confidential computing environment? Are there new risks that arise out of confidential AI? Resources: Video EP48 Confidentially Speaking 2: Cloudful of Secrets EP1 Confidentially Speaking "To securely build AI on Google Cloud, follow these best practices" blog (paper)
undefined
Sep 23, 2024 • 24min

EP191 Why Aren't More Defenders Winning? Defender's Advantage and How to Gain it!

Dan Nutting, a manager in Cyber Defense at Google Cloud, shares his insights on the concept of the Defender's Advantage. He discusses why many defenders struggle to realize this advantage and emphasizes the importance of being intelligence-led in cyber defense. Nutting explains the continuous cycle of detection engineering and how organizations can maintain effective detection capabilities. He also introduces the intriguing idea of 'Mission Control' for proactive security management, enhancing collaboration among teams to tackle threats.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app