

Scale to Zero - No Security Questions Left Unanswered
Scale To Zero
We know security is challenging, but a timely understanding of security is far more challenging! Scale to Zero is built for all the security professionals for helping them to be more privacy and security-sensitive. With this show, we hope to address all the security-related issues that are challenging to understand and resolve without the help of experts. We believed that a community space like Scale to Zero would make things a little bit simpler for everyone after we discovered the discomfort of constantly switching back and forth.
Episodes
Mentioned books

Nov 12, 2025 • 52min
Beyond Tech: Culture and Mindset of Security Engineering | Ft. Dakota Riley | Ep.101 | Cloudanix
In modern, fast-moving organizations, security is a shared responsibility, not a silo. We sat down with a Staff Security Engineer who operates at the intersection of development speed and security integrity to explore what truly defines a strong security program.This episode offers essential advice for leadership, engineers, and recruiters, covering everything from core culture to the risks of new AI models.Also available on YouTube: https://youtu.be/2ut2GQPWA4I00:00 Introduction05:41 CyberArk Acquisition07:40 Top 3 Elements of Building a Strong Security Culture10:50 Good Engineering is Security Engineering13:20 Why do organizations face challenges in achieving a security culture?16:54 Moving Fast - Startups vs. Large Enterprises19:08 Addressing challenges - Startups vs. Large Scale Companies23:00 KPIs to Show Security Progress26:16 Security Teams as Enablers32:57 Right Mindset for Security Engineering36:36 Hiring the Right Security Talent38:31 Addressing Non-Deterministic Nature of LLMs43:13 Trade-Offs of Implementing Bias in Alert Triaging Systems46:11 Training an Agent for Catching Malicious Attacks48:35 Summary49:35 Learning Recommendations

4 snips
Oct 29, 2025 • 55min
Kubernetes Security Mastery: Shifting Mindsets for Ephemeral Environments | Ep.100 | Ft. Dinis Cruz
Dinis Cruz, a seasoned security leader and founder of Cyber Boardroom, dives into the transformative world of Kubernetes security. He discusses the essential shift from static data centers to ephemeral environments and emphasizes the need for engineering mindsets in security teams. Dinis highlights the challenges of balancing security with business priorities, effective logging for containers, and managing identity in this dynamic landscape. He also explores the impact of generative AI on security roles and the necessity of anticipating AI-driven attacks. A must-listen for cloud-native practitioners!

Oct 15, 2025 • 1h 42min
A PSA's Journey - Bridge Between Business and Technology at AWS | Ft. Lalit Khatter | ScaleToZero Business
Have you ever wondered what it takes to drive successful partnerships in the AWS ecosystem? In this episode, we sit down with Lalit Khatter, a Senior AWS Partner Solution Architect, who gives us a deep dive into his dynamic role and the strategies that help AWS Partners thrive.Lalit shares his journey from Software Engineer to PSA and reveals the essential traits of a successful AWS Partner.Whether you're an aspiring PSA, a business leader at an AWS Partner, or simply curious about the engine that drives cloud adoption, this podcast offers unparalleled insights!00:00 Teaser and Introduction03:57 Role of a Partner Solution Architect and their day-to-day08:15 Why Partner Solution Architect as a job role?19:52 Transition from software engineer to AWS PSA23:22 How would a SI company work with Lalit for partnering with AWS?31:04 Trait of a successful partner38:40 AWS programs that help partners get visibility to prospective customers41:58 Aha moment after getting started with the AWS partner environment48:08 Scaling with AWS Marketplace01:03:05 Amazon Pace and Ambassador Program: Hand-in-Hand01:06:23 AWS Ambassador Program and how to invest in it01:10:20 Business Outcome Accelerator (AWS BOX)01:22:53 Weekends of Lalit Khatter01:28:40 Next 5 years of AWS Partner programs01:33:01 Stuff about Lalit

Oct 1, 2025 • 46min
Integrating Security Into Your SDLC Process | Ft. Ashish Bhadouria | Ep. 98 | ScaleToZero Podcast
How do you keep pace with AI adoption without compromising your security standards? We sat down with a Security and Privacy Engineering Manager to tackle the toughest challenges facing modern DevSecOps teams and C-Suite leaders today.This episode is packed with practical strategies on integrating security early and effectively. We dive deep into:00:00 Teaser and Introduction05:35 The real Challenges of Integrating Security into SDLC08:35 Embedding Security Into Developer Workflows12:09 Balancing Security & Velocity: Advice for the C-Suite16:11 Aligned Autonomy: How Enterprises Balance Security & Freedom20:46 AI Adoption is Fast- Security is Playing Catch-Up24:46 The Biggest Misconception About AI Security27:26 Defense-in-Depth for Securing AI Workloads31:27 Evolving Defenses Against Sophisticated AI-Driven Attacks35:04 AI-Driven Transformation in Security Operations and Testing38:15 Human-in-the-Loop: Why SOC Analysts Remain Essential in the AI Era41:25 Summary42:20 Learning RecommendationImportant LinksAshish Bhadouria: https://www.linkedin.com/in/ashishbhadouria/ScaleToZero: https://scaletozero.com/Cloudanix: https://scaletozero.com/Purusottam: https://www.linkedin.com/in/mpurusottamc/Art of War: https://www.amazon.in/Art-War-Sun-Tzu/dp/8184950888TLDR Sec: https://tldrsec.com/Pragmatic Engineer Blog: https://blog.pragmaticengineer.com/

Sep 17, 2025 • 55min
A Founder's Guide to Proactive Security & Leadership | Ft. Ashish Garg | Ep.97 | ScaleToZero Podcast
What does it really take to build a security program that stands up to modern threats? In this episode, we sit down with Ashish Garg, Founder of RIGA Cyber, to move beyond the frameworks and discuss what matters most: people.You can also watch on YouTube: https://youtu.be/99AzjI-RKTYWe cover the essential strategies for any security leader looking to build a resilient, proactive security culture. We dive into:00:00 Teaser and Introduction06:12 Making Security Everyone's Responsibility11:23 Tailoring the Story: Communicating Security Across Audiences15:38 Building a Proactive Security Program: Beyond Frameworks19:38 Overcoming Stakeholder Hurdles: Building Trust Through Alignment23:26 Bridging the Gap Between Security and Engineering28:06 Measuring Trust and Providing Security Value37:34 From Engineering to Security Leadership: The Power of Mentorship & Alignment42:03 Avoiding Burnout as a Security Leader: Prioritize & delegate44:45 AI in Security: Hype, Risk & Real Use Cases51:25 Summary52:10 Learning Recommendation#Cybersecurity #SecurityLeadership #ProactiveSecurity #InfoSec #CybersecurityPodcast #SecurityCulture #AIinSecurity #CISO #SecurityEngineering #CorporateSecurity

Sep 3, 2025 • 48min
Designing Security for GenAI: 9 Key Concepts | Ft. Shweta Thapa | Ep. 96 | ScaleToZero Podcast
Ever wonder about the security risks lurking behind your favorite AI tools? In this episode, we sit down with Shweta Thapa, Security Specialist Solutions Architect from AWS, to demystify the complex world of GenAI and traditional application security.Transcript: https://www.scaletozero.com/episodes/designing-security-for-genai-with-security-specialist-solutions-architect-shweta-thapa/Guest: https://www.linkedin.com/in/shwetast/Host: https://www.linkedin.com/in/mpurusottamc/Cloudanix: https://cloudanix.com/We'll cover 9 critical topics that every tech professional, business leader, and security enthusiast needs to know. Get ready to learn about:00:00 Teaser and Introduction05:01 Fundamentals of Designing Security for GenAI and Traditional Applications09:00 Control of Shared Responsibility Model: LLM Provider vs. Consumer12:25 Top Five Security Checks for GenAI System 17:39 Securing GenAI Outputs: Trustworthy vs. Toxic Content22:03 Synthetic Data: Helpful or Harmful24:16 Validating AI Output: Monitoring, Context & Human Judgment28:07 Strategic Advisory Questions to Ask Stakeholders When Investing in GenAI Application31:22 Misconceptions of Security Leaders about GenAI Security35:56 Getting Started with GenAI: Startups vs. Enterprises43:50 Summary45:00 Learning Recommendation

Aug 20, 2025 • 57min
Beyond the Debate: Security as an Enabler & GRC Maturity | Ft. Winthrop Welch | Ep. 95 | ScaleToZero
What does it truly take to lead security and GRC in today's complex, high-stakes environments? It's about much more than just technology—it's about building trust, creating champions, and acting as an enabler, not a blocker.In this powerful episode, we sit down with [Guest Name], a seasoned Fractional CISO and Cybersecurity Advisor. With their extensive experience, we'll dive into the real-world lessons learned from bridging the gap between security teams and the rest of the business, and how to turn GRC from a requirement into a strategic advantage.00:00 Teaser and Introduction07:24 Security and Compliance Debate09:55 How are Security and Compliance not different from each other?11:17 Security challenges evolved over the years - from data centers to AI14:10 Challenges of aligning security strategies within enterprises16:53 Tips to build trust and create security champions21:00 How do you support and educate others around you?23:05 How have security engineering and leadership roles helped you evolve?25:35 Security teams working closely with other business teams28:45 Security leaders being open to security teams31:40 GRC maturity levels in organizations today34:50 Implementing GRCs more efficiently38:32 Reducing friction between security and other business teams42:48 Security teams as enablers and not blockers47:49 Scenario where your leadership was tested53:23 Summary54:16 Learning recommendations

Aug 6, 2025 • 48min
The Future CISO: AI, Quantum & Becoming a Multidisciplinary Strategist | Ft. Patricia Titus | Ep. 94 | ScaleToZero Podcast
The role of a CISO is evolving at an unprecedented pace. It's no longer just about technical defenses; it's about leading multidisciplinary teams, understanding business strategy, and navigating the profound impacts of emerging technologies like AI and Quantum Computing.In this episode, we sit down with Patricia Titus, a seasoned Field CISO, to break down what it takes for today’s security leaders to become the multidisciplinary strategists of tomorrow. We explore how to move beyond traditional security models and embrace a future where security is a core business enabler.Watch the episode on YouTube: https://youtu.be/s6475pSgSxc00:00 Introduction04:45 From Learning AI to Secure Deployment08:25 Cross-Disciplinary Teams & the CISO's Co-Leadership Role10:05 Will AI impact only GRC or a broader area?13:29 Governance frameworks for CISOs before deploying workloads17:35 Establishing & Measuring AI Governance Frameworks20:50 Behavioral AI: Cultural shifts required to build a security mindset25:20 Measuring the effectiveness of Behavioral AI30:57 How security leaders can stay ahead in the AI native security world?33:27 Non-technical Skills for Future CISOs in the AI world35:52 Areas of expertise today's CISOs must actively cultivate39:48 Explaining the importance of AI and Quantum to stakeholders44:57 Summary45:45 Learning recommendations from Patricia

Jul 23, 2025 • 1h 22min
AWS Marketplace, ISV Partnerships, Channel Acquisitions, and More | Cybersecurity Sales | Ep. 93 | ScaleToZero Business Podcast
Join us for an inspiring and incredibly practical conversation with Faraz Khan, a seasoned AWS Marketplace Leader who shares invaluable insights from a career dedicated to sales, relationships, and driving business growth. This isn't just about tech; it's about the human element of sales, the power of partnerships, and navigating massive commercial opportunities.Faraz Khan: https://www.linkedin.com/in/m-faraz-k-4842883/Sujay Maheshwari: https://www.linkedin.com/in/sujaymaheshwari/0:00 Teaser and Introduction6:50 Sales and Relationship Learnings at Oracle Middle East11:20 Getting into Sales Life14:50 Cracking a $3 Million Deal18:08 Identifying Sales Personality Within People and Coaching Them22:10 Leaving Middle East and Shifting to India26:35 Understanding AWS Marketplace32:30 Getting Successful at AWS Marketplace40:50 Helping Understand AWS Marketplace Co-Sell to Early Adopters47:50 Wisdom for AWS Marketplace Skeptics52:55 Maneuvering AWS Marketplace and Its Different Areas59:30 Faraz Dislikes Some Aspects of His Job01:04:19 Problems Solved with AWS Marketplace India Launch01:07:35 Faraz's Life And A Day in His Life01:11:55 Faraz as a "Shayar" ("Poet") and Life Recently

Jul 9, 2025 • 1h
Zero Trust Security - The Right Way | Ft. Uttej Badwane | Ep.92 | ScaleToZero Podcast | Cloudanix
Embark with us on a crucial journey into the world of Zero Trust with our guest Uttej Badwane, a seasoned Senior Security Engineer. In this episode, we'll demystify Zero Trust for organizations just getting started, dive into practical implementation steps, and explore the cutting-edge intersection of Zero Trust and Artificial Intelligence.This episode is indispensable for security leaders, engineers, architects, and anyone keen on building resilient, future-ready security postures. Don't forget to Like, Share, and Subscribe for more expert insights!Cloudanix: https://www.cloudanix.com/Zero Trust Security: https://www.cloudanix.com/learn/what-is-zero-trust-securityUttej: https://www.linkedin.com/in/uttej-badwane/00:00 Teaser and Guest Introduction03:55 Defining Zero to Zero Trust for organizations getting started08:48 Steps to evaluate and implement a zero-trust model12:34 Multi-factor Authentication, or Micro-segmentation, or Zero Trust17:38 Challenges of implementing a zero-trust framework25:58 Is Zero Trust a right fit for you?30:24 Balancing organizational complexities and zero-trust implementation35:17 IAM recommendations for a robust zero-trust implementation42:05 Staying on top of operational complexities with practical governance steps48:52 Role of AI in Zero Trust Architecture54:54 How will zero trust models change if servers are running AI agents?58:29 Learning recommendations from Uttej


