

Cloud Security Podcast
Cloud Security Podcast Team
Learn Cloud Security in Public Cloud the unbiased way from CyberSecurity Experts solving challenges at Cloud Scale. We can be honest because we are not owned by Cloud Service Provider like AWS, Azure or Google Cloud.
We aim to make the community learn Cloud Security through community stories from small - Large organisations solving multi-cloud challenges to diving into specific topics of Cloud Security.
We LIVE STREAM interviews on Cloud Security Topics every weekend on Linkedin, YouTube, Facebook and Twitter with over 150 people watching and asking questions and interacting with the Guest.
We aim to make the community learn Cloud Security through community stories from small - Large organisations solving multi-cloud challenges to diving into specific topics of Cloud Security.
We LIVE STREAM interviews on Cloud Security Topics every weekend on Linkedin, YouTube, Facebook and Twitter with over 150 people watching and asking questions and interacting with the Guest.
Episodes
Mentioned books

Mar 1, 2024 • 50min
Understanding Threat Modeling in Cloud
Exploring the importance of threat modeling in cloud, the differences between cloud and on-prem threat modeling, practical examples, and challenges of scaling threat modeling. Discussions on incorporating threat modeling in security programs, various approaches to threat modeling, and personal insights on building effective threat models.

Feb 23, 2024 • 18min
Balancing Efficiency & Security: AI’s Transformation of Legal Data Analysis
Discover how GenAI and Custom LLM models are transforming legal data analysis at LexisNexis. Explore the intersection of cloud engineering, cybersecurity, and AI in the legal sector. Learn about the importance of data security in AI applications for legal research and document drafting.

Feb 16, 2024 • 16min
Sidecar Container Vulnerability in Kubernetes explained
Magno Logan, an expert in Kubernetes security, talks about the silent but deadly vulnerabilities of sidecar containers in Kubernetes. He discusses common attack paths, entry points for attackers, container escape, and ways to secure sidecars, shedding light on the threats beyond crypto mining attacks.

Feb 2, 2024 • 40min
Role of application security posture management in cybersecurity
Idan Plotnik, Co-Founder of Apiiro, with 24 years of cybersecurity experience, discusses the challenges of managing vast quantities of repositories and misconceptions about Application Security Posture Management. He highlights the relevance of ASPM in both large and small organizations. The podcast explores the differences between Cloud Security and Application Security Tools, and the growing need for Application Security Tools. It concludes with insights into managing cybersecurity, mean time to remediation, and importance of customer feedback.

Jan 26, 2024 • 30min
Cybersecurity Best Practices and Password Security in Cloud and AI
Troy Hunt and Scott Helme discuss best practices for decoding TLS, password security, and data breaches in cloud and AI. They emphasize the importance of early security training, strong passwords combined with multi-factor authentication, and proper password storage and encryption. The speakers also explore the risks and benefits of building LLMs, debunk TLS misconceptions, and highlight the relevance of security policies and cybersecurity training in improving security without expensive appliances.

Jan 19, 2024 • 27min
Multicloud strategy for AWS and GCP
Vivek Menon, CISO for Digital Turbine, talks about the strategic approaches to cloud security in 2024, the challenges of multi-cloud environments, managing identities and misconfigurations, and the value of dedicated cloud-specific teams.

Jan 12, 2024 • 20min
AI's Role in Security Efficiency - Kubernetes Edition
Dive into the world of AI and Kubernetes with Shopify's Shane Lawrence in this episode of the Cloud Security Podcast. Shane, shares his experience in the security team at Shopify and working on the intersection of AI, Large Language Models (LLMs), and Kubernetes security. Shopify is looking to pioneer the use of AI to streamline developer operations, enhance productivity, and bolster security measures in multi-tenant Kubernetes environments.
This episode will be valuable for you if you work in Kubernetes, Security and looking for how AI can build efficiency in your team.
Guest Socials: Shane's Linkedin (Shane's Linkedin)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction to AI and Kubernetes
(01:32) Shane Lawrence and Shopify's AI Journey
(02:21) AI and Developer Efficiency in Kubernetes
(04:39) AI-Driven Automation for Security
(06:34) Challenges of AI in Kubernetes Environment
(11:22) Case Studies for AI in Kubernetes
(13:43) The Future of Kubernetes and AI
(15:59) Learning and Experimenting with AI in Kubernetes
(17:49) Closing Thoughts and Fun Q&A

Jan 5, 2024 • 49min
Build an Effective AWS Cloud Security Program in 2024
Chris Farris, a cloud security expert and one of the first AWS Heroes for security, shares insights on building an effective AWS cloud security program in 2024. Topics include the importance of AWS organizations and Identity Centre, best practices for cloud security posture management, and actionable advice for startups and small businesses navigating AWS.

Dec 19, 2023 • 23min
Offensive Cloud Security Program for 2024
Is Offensive Security part of your 2024 Security Roadmap? We caught up with Sam Kirkman, Director at NetSPI EMEA at BlackHat Europe 2023 about what an Offensive Security Roadmap going into 2024 should look like. Offensive security is much more than pentesting. We spoke about how to build a capable team, different maturity stages of building such a program and resources you can lean on while you are on this journey across different industries.
Guest Socials: Sam's Linkedin (@sam-kirkman-cybersecurity)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:53)A bit about Sam Kirkman
(03:53) What is offensive security?
(04:52) The attack landscape
(07:34) Offensive Security Roadmap
(09:43) Components of Offensive Security Roadmap
(11:04) Whats a good starting point?
(12:55) Skillsets required in the team
(16:57) Different stages of maturity
(19:09) Where can people learn more about this?
(22:03) Where you can connect with Sam
You can learn more about NetSPI and offensive security here

Dec 15, 2023 • 27min
Understand Your Cloud Security Landscape to cut through the noise!
Cloud Security environments looks very complex in 2023, and it will continue to evolve in 2024 now with AI. At AWS re:Invent 2023 this year, we sat down with Alex Jauch, Senior Director of Product Management at Outshift to talk about the complexities in Cloud Security, the role of GenAI and what can be items to consider for your 2024 Cloud Security Program.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
Questions Asked:
(00:00) Introduction
(01:34) A bit about Alex
(02:02) Current Cloud Security Landscape
(04:43) The cloud security acronyms
(08:44) Dealing with complex infrastructure
(12:31) Impact of GenAI on Security
(15:26) Do you have GenAi in Production?
(16:55) We are all one team!
(19:04) 2024 Security Program
(20:39) Whats not being spoken about?
(22:11) The fun section
(26:00) Where you can connect with Alex!