
Cloud Security Podcast
Learn Cloud Security in Public Cloud the unbiased way from CyberSecurity Experts solving challenges at Cloud Scale. We can be honest because we are not owned by Cloud Service Provider like AWS, Azure or Google Cloud.
We aim to make the community learn Cloud Security through community stories from small - Large organisations solving multi-cloud challenges to diving into specific topics of Cloud Security.
We LIVE STREAM interviews on Cloud Security Topics every weekend on Linkedin, YouTube, Facebook and Twitter with over 150 people watching and asking questions and interacting with the Guest.
Latest episodes

Feb 2, 2024 • 40min
Role of application security posture management in cybersecurity
Idan Plotnik, Co-Founder of Apiiro, with 24 years of cybersecurity experience, discusses the challenges of managing vast quantities of repositories and misconceptions about Application Security Posture Management. He highlights the relevance of ASPM in both large and small organizations. The podcast explores the differences between Cloud Security and Application Security Tools, and the growing need for Application Security Tools. It concludes with insights into managing cybersecurity, mean time to remediation, and importance of customer feedback.

Jan 26, 2024 • 30min
Cybersecurity Best Practices and Password Security in Cloud and AI
Troy Hunt and Scott Helme discuss best practices for decoding TLS, password security, and data breaches in cloud and AI. They emphasize the importance of early security training, strong passwords combined with multi-factor authentication, and proper password storage and encryption. The speakers also explore the risks and benefits of building LLMs, debunk TLS misconceptions, and highlight the relevance of security policies and cybersecurity training in improving security without expensive appliances.

Jan 19, 2024 • 27min
Multicloud strategy for AWS and GCP
Vivek Menon, CISO for Digital Turbine, talks about the strategic approaches to cloud security in 2024, the challenges of multi-cloud environments, managing identities and misconfigurations, and the value of dedicated cloud-specific teams.

Jan 12, 2024 • 20min
AI's Role in Security Efficiency - Kubernetes Edition
Dive into the world of AI and Kubernetes with Shopify's Shane Lawrence in this episode of the Cloud Security Podcast. Shane, shares his experience in the security team at Shopify and working on the intersection of AI, Large Language Models (LLMs), and Kubernetes security. Shopify is looking to pioneer the use of AI to streamline developer operations, enhance productivity, and bolster security measures in multi-tenant Kubernetes environments.
This episode will be valuable for you if you work in Kubernetes, Security and looking for how AI can build efficiency in your team.
Guest Socials: Shane's Linkedin (Shane's Linkedin)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction to AI and Kubernetes
(01:32) Shane Lawrence and Shopify's AI Journey
(02:21) AI and Developer Efficiency in Kubernetes
(04:39) AI-Driven Automation for Security
(06:34) Challenges of AI in Kubernetes Environment
(11:22) Case Studies for AI in Kubernetes
(13:43) The Future of Kubernetes and AI
(15:59) Learning and Experimenting with AI in Kubernetes
(17:49) Closing Thoughts and Fun Q&A

Jan 5, 2024 • 49min
Build an Effective AWS Cloud Security Program in 2024
Chris Farris, a cloud security expert and one of the first AWS Heroes for security, shares insights on building an effective AWS cloud security program in 2024. Topics include the importance of AWS organizations and Identity Centre, best practices for cloud security posture management, and actionable advice for startups and small businesses navigating AWS.

Dec 19, 2023 • 23min
Offensive Cloud Security Program for 2024
Is Offensive Security part of your 2024 Security Roadmap? We caught up with Sam Kirkman, Director at NetSPI EMEA at BlackHat Europe 2023 about what an Offensive Security Roadmap going into 2024 should look like. Offensive security is much more than pentesting. We spoke about how to build a capable team, different maturity stages of building such a program and resources you can lean on while you are on this journey across different industries.
Guest Socials: Sam's Linkedin (@sam-kirkman-cybersecurity)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:53)A bit about Sam Kirkman
(03:53) What is offensive security?
(04:52) The attack landscape
(07:34) Offensive Security Roadmap
(09:43) Components of Offensive Security Roadmap
(11:04) Whats a good starting point?
(12:55) Skillsets required in the team
(16:57) Different stages of maturity
(19:09) Where can people learn more about this?
(22:03) Where you can connect with Sam
You can learn more about NetSPI and offensive security here

Dec 15, 2023 • 27min
Understand Your Cloud Security Landscape to cut through the noise!
Cloud Security environments looks very complex in 2023, and it will continue to evolve in 2024 now with AI. At AWS re:Invent 2023 this year, we sat down with Alex Jauch, Senior Director of Product Management at Outshift to talk about the complexities in Cloud Security, the role of GenAI and what can be items to consider for your 2024 Cloud Security Program.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions Asked:
(00:00) Introduction
(01:34) A bit about Alex
(02:02) Current Cloud Security Landscape
(04:43) The cloud security acronyms
(08:44) Dealing with complex infrastructure
(12:31) Impact of GenAI on Security
(15:26) Do you have GenAi in Production?
(16:55) We are all one team!
(19:04) 2024 Security Program
(20:39) Whats not being spoken about?
(22:11) The fun section
(26:00) Where you can connect with Alex!

Dec 14, 2023 • 33min
Kubernetes Security Trends 2024 | Software Supply Chain Security, Zero Trust and AI
Kubernetes is shaping the future of cloud native technology with interest from security folks, businesses and developers - what does the future of Kubernetes Security look like? At Kubecon NA 2023, we spoke to Emily Fox who is the chair of CNCF's Technical Oversight Committee and Software Engineering Lead at RedHat about how Zero Trust plays out in the Kubernetes environment, challenges and solutions in securing the software supply chain within Kubernetes, the impact of AI workloads on Kubernetes and future of Edge Computing and Kubernetes.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions Asked:
(00:00) Introduction
(02:23) A bit about Emily
(02:51) What is Supply Chain Security?
(03:51) What triggered this conversation?
(05:10) Supply Chain Security in Managed Kubernetes
(06:07) What is Zero Trust?
(07:24) Implementing Zero Trust
(09:29) The role of Security and Compliance
(11:13) Compliance as code in Kubernetes
(13:22) What is Edge?
(17:41) The impact of AI on Security
(20:39) Detection for AI and Kubernetes
(22:29) How are the skillsets changing?
(25:00) Security for Open Source Projects
(28:01) The fun section

11 snips
Dec 12, 2023 • 26min
Kubernetes Network Security for Multi Tenancy
Cailyn Edwards, Senior Security Engineer at Shopify, discusses the complexities of Kubernetes Network Security in a multi-tenant environment, including tools and tactics for securing Kubernetes environments. She also shares insights from her journey at Shopify and tips for advancing the security maturity of Kubernetes networks.

Dec 5, 2023 • 56min
AWS reInvent 2023 - Security highlights and announcements
Cloud Security Podcast just got back from AWS re:invent 2023, there was a lot of chat around, you guessed it - GenAI but along with that there were plenty of security updates and announcement. Shilpi and Ashish broke them all down for you and what it all actually means for all security practitioners.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(04:49) GenAI at AWS re:Invent
(06:01) No new security service announced
(06:48) Updates from CEO and CTO Keynotes
(11:29) What is Amazon Inspector?
(12:10) Amazon Inspector Security Updates
(15:09) What is AWS Security Hub?
(15:52) AWS Security Hub Security Updates
(18:52) What is Amazon GuardDuty?
(20:10) Amazon GuardDuty Security Updates
(22:49) What is Amazon Detective?
(23:45) Amazon Detective Security Updates
(26:22) What is IAM Access Analyser?
(28:06) IAM Access Analyser Security Updates
(30:33) What is AWS Config?
(31:25) AWS Config Security Updates
(32:35) Other Security Updates
(33:46) 3 Layers of AI
(35:21) What is Amazon CodeWhisperer?
(36:36) Amazon Application Composer
(37:34) Guardrails for Bedrock
(38:13) Amazon Q
(41:17) Zero Trust
(41:45) Ransomware
(44:29) Security Talks
(45:54) Input filtering and validation for WAF
(50:31) Enterprise IAM and data perimeter
(53:00) Conclusion and find out more!
You can check out the Top announcements of AWS re:Invent 2023 + AWS re:Invent 2023 - Security Compliance & Identity