Cloud Security Podcast by Google artwork

Cloud Security Podcast by Google

181 episodes - English - Latest episode: 12 days ago - ★★★★★ - 33 ratings

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure.

We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit.

We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.

Technology cloudsecurity cloud cybersecurity security
Homepage Apple Podcasts Google Podcasts Overcast Castro Pocket Casts RSS feed

Episodes

EP31 Cloud Certifications, and Cloud Security with TheCertsGuy

September 13, 2021 16:52 - 22 minutes - 30.5 MB

Guest: Iman Ghanizada,   Solutions Manager for Security Operations & Analytics @ Google Cloud Topics: What is your book “Google Cloud Certified Professional Cloud Architect All-in-One Exam Guide” about?  What was your journey into writing this book, how long did it take? The book seems to be targeted towards Cloud Architects, but you come from a predominantly security background, how has that influenced your writing of this book? What does this have to do with The Certs Guy (14 cer...

EP30 Malware Hunting with VirusTotal

September 07, 2021 17:44 - 26 minutes - 36.2 MB

Guest: Vicente Diaz,  Threat Intelligence Strategist @ VirusTotal Topics: How would you describe modern threat hunting process? Share some of the more interesting examples of attacker activities or artifacts you've seen? Do we even hunt for malware? What gets you more concerned, malware or human attackers? How do you handle the risk of attackers knowing how you perform hunting? What is the role of threat research role for hunting? Do you need research to hunt well? Does threat r...

Future of EDR: Is It Reason-able to Suggest XDR?

August 30, 2021 17:05 - 27 minutes - 38.4 MB

Guest:  Sam Curry,  Chief Security Officer @ Cybereason and Visiting Fellow @ National Security Institute Topics: EDR was “invented” in 2013 and we are now in 2021. What do you consider to be modern EDR components and capabilities? Where has EDR fallen short on its initial hype? How focused are the attackers on bypassing EDR? How do you think EDR works in the cloud? In your view, how would future EDR work for containers, microservices, etc? Why aren’t we winning the war against ...

Tales from the Trenches: Using AI for Gmail Security

August 23, 2021 16:34 - 19 minutes - 26.5 MB

Guest: Andy Wen, Product Lead for Abuse & Security @ Google Cloud Topics: What are you doing with AI for security? What kinds of security problems are addressable with AI, and which ones are harder to address with ML techniques? Tell us where you’ve been surprised by AI’s success? Do you expect a) AI use by adversaries and b) attacks focused on disrupting the AI use by defenders? What advice would you give a PM or technical lead starting out on thinking they want to use AI to solv...

The Mysteries of Detection Engineering: Revealed!

August 16, 2021 17:15 - 30 minutes - 41.5 MB

Guest: Keith McCammon, Co-founder and Chief Security Officer, Red Canary Topics: What is Detection Engineering? How it differs from just building rules/analytics? How to convert threat intelligence into detections?  How to tell good detections from bad? And perhaps also good from great? How to test detections in the real world? Anything special about building detections for cloud environments? What do you think is the role of “rule-less” (such as ML) detections? Is “ML unicorn c...

SOC in a Large, Complex and Evolving Organization

August 09, 2021 16:56 - 20 minutes - 28.1 MB

Guest: Johnathan Keith, Director of Information Security (CISO) @  ViacomCBS Streaming / Digital (at the time of the recording) Topics: What is the mission for your SOC? Has it evolved in recent years? How do you rate your state of maturity in security operations? I hear that your organization is complex and decentralized, how do you run a SOC in such a case? How do you approach the balance of people, process and technology in your SOC? What is the role of outsourcing in your SOC...

Beyond Compliance: Cloud Security in Europe

August 02, 2021 15:22 - 27 minutes - 37.2 MB

Guest:  John Stone, Chaos Coordinator at the Office of the CISO @ Google Cloud Topics: What are the top European-specific cloud migration security challenges? Are there interesting cloud adoption barriers related to security in Europe? Are some of these challenges more compliance than security related? Do you think compliance still drives security in the cloud for European companies? Do you think Europe can ever "make their own cloud"? So, what do you make of this entire movemen...

Linking Up The Pieces: Software Supply Chain Security at Google and Beyond

July 26, 2021 17:31 - 23 minutes - 31.7 MB

Guests: Eric Brewer, VP of Infrastructure, and Google Fellow @ Google Aparna Sinha, Director of Product Management @ Google Cloud Topics: What is software supply chain security and how is it different from other kinds of supply chain security?  What types of organizations need to care about it? Is supply chain security a concern for large, elite enterprises only?  What’s the relationship between what we’re doing here, and what SBOM is? Can you talk us through a quick threat assess...

Threat Detection at Google Cloud Security Summit

July 19, 2021 17:28 - 21 minutes - 29.2 MB

No guests. We interviewed each other! Topics: What would you say are the most things that Chronicle is trying to address today? What are the good ways to use threat intel to detect threats that do not ruin your SOC? What does “autonomic” security mean, anyway? Is this a fancy way of saying “automatic” or something more? For sure, “the Cloud is not JUST someone else’s computer“ - but how does this apply to threat detection? What makes threat detection “cloud-native”? What kinds o...

Securing Multi-Cloud from a CISO Perspective, Part 3

July 12, 2021 15:59 - 24 minutes - 33.3 MB

Guests: Phil Venables (@philvenables), Vice President, Chief Information Security Officer (CISO) @ Google Cloud  Dave Hannigan, Director, Financial Services Security & Compliance @ Google Cloud  Topics: As a CISO, would you ever decide to use multiple clouds, if it were in your hands?  How is security typically considered when companies go multi-cloud in their approach? Practically, or operationally, how does one think through securing multiple public cloud environments? What are ...

Security Marketing? Every Product Needs a Story!

July 06, 2021 17:35 - 23 minutes - 32.7 MB

Guest: Kelly Anderson, Head of Product Marketing, User Protection Services @ Google Cloud Topics: What is marketing, really? Why is it sometimes reviled by the technologists? What makes a great marketer in cloud security? What’s different about cloud security marketing, as opposed to regular old on-premise security marketing? Is there still FUD in the cloud? Which things are the easiest or hardest to do in Google Cloud Security marketing? How do you talk about products so they sta...

Security Operations, Reliability, and Securing Google with Heather Adkins

June 28, 2021 15:32 - 28 minutes - 39.1 MB

Guest: Heather Adkins, Sr Director, Information Security @ Google Topics: Your RSA presentation has 3 pillars: zero trust, microservices, automation/zero prod, is this all you need to be secure & reliable in the modern world? Let’s drill down again into the “secure and reliable” concept, are you sure that they are interrelated? Is there a risk that microservices could actually increase attack surface? What are the practical security upsides of “no touch production”?  SRE and DevO...

Double-clicking, but not on fire hydrants, with bot fighters

June 21, 2021 17:19 - 34 minutes - 46.8 MB

Guest 1: Sparky Toews, Product Manager for Adobe identity @ Adobe Topics 1: Why are bots a problem to you? Give us a bit of your bot threat assessment? Can you tell us how you think about and practice securing the user experience? What kind of security products or best practices are involved? How do you see what security professionals do to secure the user experience evolving over time? Guests 2: Randy Gingeleski, Senior Staff Security Engineer @ HBO Max Brian Lozada, CISO @ HBO...

More Cloud Migration Security Lessons

June 14, 2021 16:50 - 32 minutes - 44.1 MB

Guests: Jane Chung, VP of Cloud @ Palo Alto Joe Crawford, Director of Strategic Technology Partnerships for Google Cloud @ Palo Alto Topics: What are the top security mistakes you’ve seen during cloud migrations? What is your best advice to security leaders who want to go to the cloud using the on-premise playbook? What security technologies may no longer be needed in the cloud? Which are transformed by the cloud? Cloud often implies agility, but sometimes security slows things do...

Modern Threat Detection at Google

June 07, 2021 16:10 - 24 minutes - 33.3 MB

Guest: Julien Vehent, Security Engineering Manager in the Detection and Response team @ Google Topics: What is special about detecting modern threats in modern environments? How does the Google team turn the knowledge of threats into detection logic? Run through an example of creating a detection for a new threat? How do we test our detection rules? We use the same people to write detections and to respond to resulting alerts, how is it working? What are the key skills of good s...

Modern Data Security Approaches: Is Cloud More Secure?

June 01, 2021 14:03 - 28 minutes - 38.9 MB

Guests: Tim Dierks, Engineering Director, Data Protection @ Google Cloud Topics: What are the key components of data security in the public cloud today? Why do companies need specific data security plans and products? Do you think Google Cloud today has enough controls for processing the most sensitive data? Many organizations seem to be unaware of where sensitive data exists in their cloud environments, how do you think this problem will be fixed? What is your view on encryption'...

Scaling Google Kubernetes Engine Security

May 24, 2021 17:40 - 20 minutes - 28.6 MB

Guest: Greg Castle, Senior Staff Security Engineer at Google Topics: How is kubernetes security different from traditional host security? What’s different about securing GKE vs security Kubernetes on-prem? Where does one start with security hardening for GKE? In your view, what are top realistic threats to container deployments? What do users get wrong most often? Did we manage to make containers both more secure and more usable?

Making Compliance Cloud-native

May 19, 2021 16:48 - 20 minutes - 27.8 MB

Guest: Zeal Somani, Security Solutions Manager @ Google Cloud, former PCI QSA Topics: What are the usable recipes for thinking about compliance in the cloud? What regulations are more challenging for public cloud users? How do you see the client/provider responsibility split for compliance? What is this “shift left” for compliance? How do we educate auditors and regulators who insist on 1980s solutions to 2020s problems? What are the most popular mistakes and blind spots with tr...

Application Security in the Cloud

May 10, 2021 16:59 - 24 minutes - 34.3 MB

Guest: Alyssa Miller,  BISO @ S&P Global Ratings Topics: How do application security practices change as organizations launch their cloud transformations? What bad things happen to you if you lift/shift your big applications to somebody's IaaS? What unique challenges do containers and serverless deployments create for application security? Is there good news here? How can cloud native technologies make application security easier than a traditional on-prem environment? What can or...

Threat Models and Cloud Security

May 03, 2021 16:12 - 19 minutes - 27.1 MB

Guest: Seth Vargo, Security Engineer @ Google Cloud Topics: How should security teams change their thinking about threats in the cloud? Where and when should an organization start in building their threat model for their cloud environment? What are the key changes of threat models after cloud migration? More specifically, when it comes to identity, credentials, lateral movement, what are the key ways in which cloud security differs from traditional or on-premises security? How sho...

Preparing for Cloud Migrations from a CISO Perspective, Part 2

April 26, 2021 15:27 - 20 minutes - 28.8 MB

Guests: Phil Venables (@philvenables), Vice President, Chief Information Security Officer (CISO) @ Google Cloud Dave Hannigan, Director, Financial Services Security & Compliance @ Google Cloud Topics: To continue on the theme from Part 1, is “cloud-native” about thinking? Security tools? Systems? Architecture? How do we practically help CISOs “speak cloud”? What are the first steps to cloud thinking for an “on-premise CISO”? What are the areas of security where it is easier to be...

SIEM Modernization? Is That a Thing?

April 19, 2021 16:55 - 24 minutes - 34 MB

Guest: Eric Foster, President at CYDERES, a Fishtech Group company Topics: How do you define “modern” SIEM? Does modern SIEM always imply SaaS SIEM? Is there a future for on-premises SIEM? What are your top 3 root causes for SIEM deployment failure today? Modern or not, does SIEM have a future? Can XDR or some other technology drive it off the rails? What features or inputs should SIEM have to detect modern threats such as those to cloud environments but also others? What’s diff...

Building a Third Party Platform for Cloud Security

April 12, 2021 17:00 - 27 minutes - 38.4 MB

Guest: Avi Shua, CEO and Co-founder @ Orca Security Topics: Where do you spend more efforts, on detection of pre-fail issues (like configuration errors) or post-fail issues (like incidents)? How do you prioritize the preventative and detective controls in your platform? When talking to CISOs, how do you explain that cloud threat detection is different from the on-premise type? In your opinion, are agents dead in the cloud? Do you think your customers care more about cloud-specific...

Zero Trust: Fast Forward from 2010 to 2021

April 01, 2021 17:00 - 28 minutes - 38.7 MB

Guest:  John Kindervag, who is widely considered to be the creator of zero trust model in 2010 (currently works at ON2IT) Topics: What has changed in the world of zero trust since 2010? What must be trusted for a zero trust (ZT) system to work? What are key ZT project success pre-requisites? What is the first step in ZT implementation that increases the chance of its success? Is zero trust hard for most companies? What’s the most spectacular failure you’ve seen in a ZT project? ...

No One Expects the Malware Inquisition

March 24, 2021 18:40 - 25 minutes - 34.8 MB

Guest: Brandon Levene, Malware Inquisitor @ Google Cloud Topics covered: Which malware is scarier, state-sponsored or criminal? How do we approach cybercrime mitigation at Google? How do we actually track malware? Don’t we need “attribution” for it? What are the most useful telemetry sources for study in modern malware? Does ransomware have a bright future? Where do you see threat actors making the biggest investments? Resource: "Crimeware In The Modern Era" paper by Brandon L...

Cloud Security Talks Summarized: A Recap Episode

March 17, 2021 20:46 - 22 minutes - 31.3 MB

Guests: no guests, just Tim and Anton  Topics covered: Discussion of the interesting presentations from Cloud Security Talks Q1 2021 focused on trusted cloud, container security, cyber insurance, Chronicle, ML for network security, etc Resources: All Q1 2021 Cloud Security Talks “Cloud Risk Panel Discussion” video “A conversation on overcoming risk management challenges in the Cloud” video  “Better together - expanding the Confidential Computing ecosystem” video “Detect pot...

Preparing for Cloud Migrations from a CISO Perspective, Part 1

March 11, 2021 17:44 - 20 minutes - 27.9 MB

Guests: Phil Venables (@philvenables), Vice President, Chief Information Security Officer (CISO) @ Google Cloud  Nick Godfrey, Director, Financial Services Security & Compliance and a member of Office of the CISO @ Google Cloud Topics covered: Why do you think so many CISOs of traditional organizations fear cloud migrations? What is your best advice to a CISO who wants to migrate to the cloud using the on-premise playbook, or lift and shift?  What are the real tradeoffs in this deci...

Gathering Data for Zero Trust

February 24, 2021 21:43 - 24 minutes - 33.2 MB

Episode 4 “Gathering Data for Zero Trust” focuses on enabling zero trust access in the real world Guest: Max Saltonstall (@maxsaltonstall), Developer Advocate @ Google Cloud   Topics covered: What should be trusted for a zero trust system to work? What is the first thing you need to do to have a zero trust access project succeed? What data needs to be collected for zero trust system operation?

Automate and/or Die?

February 11, 2021 17:57 - 17 minutes - 24.2 MB

Episode 3 “Automate and/or Die?” focuses on automated remediation (or is it response!) in the cloud Guest: Joe Crawford, formerly in charge of cloud-native security at a large bank Topics covered: Can we automatically remediate vulnerabilities and threats in the cloud? Did you require humans to be in the loop for your automation? Is that still automation if we do? Does security fear of automation have a place in the cloud?

Data Security in the Cloud

February 11, 2021 17:53 - 19 minutes - 27.4 MB

Episode 2 “Data Security in the Cloud” focuses on data security in the cloud  Guest: Andrew Lance, Sidechain Topics covered: What is special about data security in the cloud? How data security plays in the shift from perimeter and network security to identity-based security? Can I use detective data security controls and turn them into preventative controls? Resources: “Designing and deploying a data security strategy with Google Cloud” paper

Confidentially Speaking

February 11, 2021 17:45 - 21 minutes - 29 MB

“Confidentially Speaking” episode focuses on confidential computing Guest: Nelly Porter, Group Product Manager @ Google. Topics covered: What risks are mitigated by confidential computing? What types of organizations must adopt confidential computing? How and where the data is encrypted? Resources:  Confidential computing at Google Cloud

Twitter Mentions

@philvenables 6 Episodes
@anton_chuvakin 2 Episodes
@googlecloud 1 Episode
@cloudsecpodcast 1 Episode
@performify 1 Episode
@alyssam_infosec 1 Episode
@divinetechygirl 1 Episode
@trompi 1 Episode
@shareincyber 1 Episode
@kellyanderson93 1 Episode
@stfn42 1 Episode
@vladhiewsha 1 Episode
@lzxdc 1 Episode
@maxsaltonstall 1 Episode
@lancinimarco 1 Episode
@sethvargo 1 Episode
@naderzaveri 1 Episode
@insecurenature 1 Episode
@samjcurry 1 Episode