
Cloud Security Podcast
Learn Cloud Security in Public Cloud the unbiased way from CyberSecurity Experts solving challenges at Cloud Scale. We can be honest because we are not owned by Cloud Service Provider like AWS, Azure or Google Cloud.
We aim to make the community learn Cloud Security through community stories from small - Large organisations solving multi-cloud challenges to diving into specific topics of Cloud Security.
We LIVE STREAM interviews on Cloud Security Topics every weekend on Linkedin, YouTube, Facebook and Twitter with over 150 people watching and asking questions and interacting with the Guest.
Latest episodes

Apr 23, 2024 • 38min
The Future of Software Development with AI
How can we leverage AI for more secure and efficient code and how will it impact devsecops? Ashish spoke to Michael Hanley, CSO and SVP of Engineering at GitHub, about the transformative impact of GitHub Copilot and AI on software development and security. Michael speaks about GitHub's internal use of Copilot for over three years and its role in enhancing developer satisfaction and productivity by removing mundane coding tasks. They speak about the broader implications for DevSecOps, the future of AI in coding, and strategic tips for integrating AI tools within organizations.
Guest Socials: Michael's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:19) A bit about Michael Hanley
(04:25) Making Security Easy for Developers
(07:17) What is GitHub Copilot?
(10:01) Whats the Future of AI for Security and Developers?
(13:36) Security Recommendations for using AI
(16:35) How is data stored in GitHub Copilot?
(17:40) How is AI impacting DevSecOps?
(21:50) The balance between Security and Innovation
(24:18) The evolution of education with AI
(27:30) Strategic Approach for CISOs implementing AI Pair Programmers
(30:08) Bridging the gap between Security and Engineering
(34:37) The Fun Questions
Resources spoken about during the episode:
https://resources.github.com/copilot-trust-center/https://www.github.careers/careers-home

Apr 16, 2024 • 22min
The role of Real Time Defense in Cloud Security
Loris Degioanni, Co-Founder and CTO of Sysdig, discusses the Open Source Project, Falco, and its role in protecting Kubernetes environments. They talk about the gap between traditional security measures and modern infrastructures, the significance of eBPF technology, ROI for runtime security tools, preventative security vs. runtime security, and the future roadmap for Falco.

Apr 9, 2024 • 49min
CISO's guide to embracing risk in business
Fredrick Lee, CISO at Reddit, delves into embracing risk in business for innovation. Topics cover cost-effective cybersecurity strategies, Reddit's S.P.A.C.E team, and challenges in the modern tech environment. The conversation explores the importance of risk-taking, driving success, and the evolving landscape of security priorities.

Apr 5, 2024 • 30min
Why Email Breaches Still Happen?
Abhishek Agrawal, Co-founder of Material Security, discusses the persistence of email security challenges and the importance of focusing on threat management and posture management in today's digital landscape. The podcast delves into the evolving tactics used in email breaches, emphasizing the need for enhanced identity protection measures and highlighting the critical aspects of securing productivity suites like Microsoft 365 and Google Workspace.

Apr 2, 2024 • 46min
Essential Strategies to master Incident Response in Cloud
Andrew Tabona, SVP of Cyber Threat Management, challenges traditional incident response plans in the cloud. They discuss mean time to detect, respond, and recover, strategies for building a detection framework, nuances of incident response in cloud vs. on-premise environments, balanced log ingestion, and the importance of mastering fundamentals for effective cloud security.

Mar 12, 2024 • 21min
From Code Suggestions to Security
Learn all about GitHub Copilot, an AI-powered coding assistant redefining how developers write code. From its impact on security professionals to the trustworthiness of AI-generated code, discover how GitHub Copilot enhances productivity and security in the coding world. Explore the versatility of this tool in various programming languages and its potential for revolutionizing software development. Plus, enjoy a fun chat about gaming, work-life balance, and favorite cuisines.

9 snips
Mar 8, 2024 • 36min
Cloud Security Operations for Modern Threats
The podcast delves into the concept of 'Assume Breach' for cloud incident preparedness, the effectiveness of CSPM, and the importance of logs in incident response. It also discusses gaining deep visibility in cloud environments, the need for a Security Data Lake, and demonstrating ROI for Security Operations.

Mar 1, 2024 • 50min
Understanding Threat Modeling in Cloud
Exploring the importance of threat modeling in cloud, the differences between cloud and on-prem threat modeling, practical examples, and challenges of scaling threat modeling. Discussions on incorporating threat modeling in security programs, various approaches to threat modeling, and personal insights on building effective threat models.

Feb 23, 2024 • 18min
Balancing Efficiency & Security: AI’s Transformation of Legal Data Analysis
Discover how GenAI and Custom LLM models are transforming legal data analysis at LexisNexis. Explore the intersection of cloud engineering, cybersecurity, and AI in the legal sector. Learn about the importance of data security in AI applications for legal research and document drafting.

Feb 16, 2024 • 16min
Sidecar Container Vulnerability in Kubernetes explained
Magno Logan, an expert in Kubernetes security, talks about the silent but deadly vulnerabilities of sidecar containers in Kubernetes. He discusses common attack paths, entry points for attackers, container escape, and ways to secure sidecars, shedding light on the threats beyond crypto mining attacks.