Cloud Security Podcast

Cloud Security Podcast Team
undefined
9 snips
Jan 28, 2025 • 32min

CISO Challenges Across Industries

In this discussion, Sunil Rane, a seasoned cybersecurity leader with over 20 years of experience, sheds light on the intricate challenges faced by CISOs across various sectors. He elaborates on balancing data sensitivity in healthcare with operational efficiency, the complexities of compliance in consulting, and the unique hurdles in the media industry regarding public accountability. Sunil also emphasizes the importance of communication and collaboration for effective cybersecurity leadership, all while sharing a personal touch with tales of his culinary passions.
undefined
Jan 24, 2025 • 51min

Why Solving the Data Problem is Key to Cloud Security?

Francis Odum, founder and lead research analyst at Software Analyst Cyber Research, shares valuable insights into cloud security and identity management. He discusses the critical role of addressing data problems to mitigate false positives and enhance SOC efficiency. The conversation also delves into the promising yet complex landscape of AI security, emphasizing the importance of proper data governance. Additionally, Odum predicts key trends for 2025, urging the cybersecurity industry to prioritize innovative solutions while navigating evolving challenges.
undefined
35 snips
Jan 21, 2025 • 26min

The economics of cybersecurity and trends

Mike Privette, founder of Return on Security, shares his deep insights into the economics of cybersecurity and its evolving landscape. He discusses how AI is reshaping governance, risk, and compliance while emphasizing the need for strategic planning in cybersecurity efforts. The integration of cloud and application security takes center stage, highlighting unified approaches to protect against data loss. Additionally, Mike touches on the rise of startups in the cyber market and the ongoing challenges they face in this dynamic environment.
undefined
14 snips
Jan 14, 2025 • 40min

The Truth About CNAPP and Kubernetes Security

James Berthoty, founder of Latio.Tech, shares his expertise on cloud security tools. He clarifies the concept of CNAPP and discusses whether Kubernetes security is becoming the new standard. The chat dives into the distinction between runtime security and vulnerability management, emphasizing the need for clear approaches in cloud-native security. James also addresses the evolving challenges security engineers face in integrating security within development processes, alongside the pressing necessity for user-centric security tool consolidation.
undefined
23 snips
Jan 10, 2025 • 1h 10min

Cybersecurity Isn’t Crowded: Security Engineering and the 5,000 Vendor Problem

Ross Haleliuk, author of "Cybersecurity for Builders" and creator of the Venture in Security blog, dives into the complex world of cybersecurity. He discusses why the industry is less crowded than it appears and the critical divide between in-house security and vendor reliance. Ross also emphasizes the importance of balancing business needs with security engineering, sharing insights on addressing market problems for startups. The conversation highlights the ongoing need for knowledge sharing and innovation in this ever-evolving tech landscape.
undefined
Dec 17, 2024 • 49min

Centralized VPC Endpoints - Why It Works for AWS Networking

Meg Ashby, a Senior Cloud Security Engineer at Alloy with a background at Goldman Sachs, sheds light on AWS's centralized VPC endpoints, often deemed an anti-pattern. She shares insights on transforming this unconventional setup into a cost-effective and scalable solution with strong controls and visibility. Delving into the challenges of monitoring traffic and implementing granular IAM controls, she provides valuable strategies for balancing security with network efficiency. Plus, her personal anecdotes add an enjoyable touch to the tech-heavy discussion!
undefined
6 snips
Dec 5, 2024 • 29min

What is CADR?

In this discussion, Shauli Rozen, co-founder and CEO of ARMO Security and an expert in Kubernetes security, dives into the fascinating world of cloud application detection and response (CADR). He highlights the challenges faced in runtime security and critiques traditional CSPM tools. The conversation also covers the 'Four C's' of cloud security—cloud, cluster, container, and code—and emphasizes the crucial role of runtime data using eBPF. Shauli's insights shed light on how Kubernetes is transforming DevOps and security collaboration.
undefined
Nov 21, 2024 • 37min

Building Platforms in Regulated Industries

At HashiConf 2024 in Boston, our host Ashish Rajan had a great chat over some cannolis and a game of Jenga with AJ Oller, AVP of Engineering at The Hartford about how automation, mainframes, and compliance intersect to drive innovation in regulated industries like insurance. They spoke about why regulations aren't barriers but frameworks to prevent failure, the human side of engineering and how to manage change fatigue during transformations and how automation enhances security, disaster recovery, and operational efficiency. Guest Socials:⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠AJ' s Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels: - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp Questions asked: (00:00) Introduction (01:53) A bit about AJ Oller (02:17) The Cannoli taste test (04:38) Technology in the Insurance industry (10:19)What is a platform? (11:46) What skillsets do you need in platform team? (14:19) Maturity for building platform teams (19:5)8 Business case for investing in Automation (24:49) Does Automation help with security regulations? (28:10) Leaders communicating automation value to business (30:37) Cheerleading for digital transformation (32:32) The Fun Section
undefined
15 snips
Nov 12, 2024 • 46min

Dynamic Permission Boundaries: A New Approach to Cloud Security

Kushagra Sharma, a Staff Cloud Security Engineer with extensive experience in scaling IAM across AWS environments, shares his insights on dynamic permission boundaries. He discusses the failures of traditional IAM models at scale and emphasizes the need for innovative solutions like Terraform for security management. Kushagra also covers the challenges of multi-cloud setups and the evolving responsibilities between developers and security teams, all while maintaining a balance between security and developer autonomy.
undefined
Nov 9, 2024 • 39min

Building a Resilient Cloud Security Program after Merger and Acquisition

In this episode, host Ashish Rajan sits down with Prahathess Rengasamy, a cloud security expert with extensive experience at companies like Credit Karma, Block, and Apple. Together, they explore the challenges and best practices for scaling cloud security, especially in the complex scenarios of mergers and acquisitions. Starting with foundational elements like CSPMs and security policies, Prahathess breaks down the evolution of cloud security strategies. He explains why cloud security cannot succeed in isolation and emphasizes the need for collaboration with platform and infrastructure engineering teams. The conversation delves into real-world examples, including managing AWS and GCP security post-acquisition and navigating the cultural and technical challenges that come with multi-cloud environments. Guest Socials:⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Prahathess's Linkedin Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels: - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Podcast- Youtube⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security Newsletter ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ - ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp Questions asked: (00:00) Introduction (02:02) A bit about Prahathess (02:36) How does Cloud Security Scale? (07:51) Where do we see just in time provisioning? (10:05) Cloud Security for Mergers and Acquisitions (14:31) Should people become MultiCloud Experts? (15:28) The need for data insights (16:54) Data sources to have as part of data insights (21:06) Benefits of Data insights for Cloud Security Teams (21:30) How to bring the new team along the cloud security journey? (24:29) How to learn about data insights? (26:35) How to maximize security efforts with data? (36:21) The Fun Section

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app