Access Control: Recent Episodes

Teleport

Access Control, a podcast providing practical security advice for startups.

View Details

Ben Arent interviews Alyssa Miller, a seasoned hacker, highly experienced security executive, and BISO at S&P Global Ratings.

View Details

Key topics on Access Control Podcast: Episode 14 - Securing CI/CD and Supply Chain

  • What is CI/CD? CI/CD stands for continuous integration, continuous deployment.
  • With regard to software supply chain problems, as with other similar problems, there's always the question of how long have we known about something versus how long has it been happening.
  • Continuous deployment is important for remediation because the length of time to push a deployment impacts the duration of exposure to a given security problem.
  • The SolarWinds incident was caused by a compromised build server and involved sophisticated loading of a backdoor into the deployed Orion system.
  • Prior to recent security incidents, traditional CI/CD's focussed around image and artifact scanning. Securing Tokens and Build Infrastructure have been a key part of the solution to keep CI/CD secure.
  • As companies string together a large number of tools, it's important for them to ask: What is the security model we have here? We'll discuss this in detail with this eposide.

View Details

Interview with Hisham Alhakim about FedRAMP, FISMA, Nist, FIPS, SBOM, Zero Trust, collaboration with engineers.

View Details

In this episode we go deep into SOC2, Cryptography and how to get started building a security practice.

View Details

For this 11th episode of Access Control Podcast, a podcast providing practical security advice for startups, Developer Relations Engineer at Teleport Ben Arent chats with Elvis Chan. Elvis is Assistant Special Agent in charge assigned to the San Francisco FBI Field office. Chan manages a squad responsible for investigating national security cyber matters and has over 14 years of experience in the bureau.

View Details

How Figma protects internal tools using off the shelf AWS services with Max Burkhardt, a security engineer at Figma

View Details

In this ninth episode of Access Control, a podcast providing practical security advice for startups, Ben Arent chats with Mario Loria. Mario is a Senior SRE at Carta who has been leading their move to Kubernetes and other cloud native technologies. Carta helps companies and investors manage their cap tables, valuations, investments, and equity plans. As users of Carta, we hope their security is top notch. Today we’ll be chatting about orchestrating Kubernetes, training teams on cloud native, and optimizing for the developer experience!

View Details

In this eighth episode of Access Control, a podcast providing practical security advice for startups, Developer Relations Engineer at Teleport Ben Arent chats with Andrew Martin, CEO of Control Plane. Control Plane is a London-based Kubernetes consultancy. Helping architect, install, audit, and secure Kubernetes clusters using Cloud Native technologies. Andrew was previously a DevOps Lead at the UK Home office and has helped lead teams implementing high-volume critical national infrastructure projects for the UK government. We’ll deep-dive into securing Kubernetes and strategies for partnering with the public sector.

Andrew is co-author of O'Reilly’s Hacking Kubernetes, a great book in progress (and due November 21) to better understand the Kubernetes defaults, Kubernetes threat models and how you can protect against those attacks.

View Details

In this seventh episode of Access Control, a podcast providing practical security advice for startups, Ben Arent chats with Ben Sadeghipour ( AKA (https://twitter.com/NahamSec ), Head of Hacker Education at https://www.hackerone.com/ and Hacker by night. This episode is a deep dive into how startups can leverage the power of crowd sourced hackers to find bugs and security issues in your apps. Ben Sadeghipour has over 685 vulnerabilities found in major sites such as Snapchat, AirBnB and even the U.S. Department of Defense, Hacker One helps companies by providing tools to help with response assessments and running their bug bounty programs.

View Details

Key Topics on Access Control Podcast: Episode 6 – HIPAA Compliance for Startups

  • VerticalChange was founded to create impact for the social sector and help its agencies digitize manual processes.
  • VerticalChange provides a solution that combines CRM, analytics, and dynamic form-building.
  • Regulations like HIPAA, HITRUST, and FERPA are very strict, and agencies have to put in place many controls in order to comply.
  • Startups in the healthcare space need to have someone who understands HIPAA and is willing to put the time in to write all the policies and procedures that need to be in place to meet security and privacy rules.
  • Using a combination of CloudTrail, Auth0 logs, and Teleport logs, VerticalChange is able to create a log flow and see what people are doing within the application.

View Details

This episode is a deep dive with Julien Vehent about his book Securing DevOps: Security in the Cloud. We touch on security topics at Mozilla and Google GCP and provide updated advice on securing the cloud since its publication.

In this fifth episode of Access Control, a podcast providing practical security advice for startups, Ben Arent chats with Julien Vehent, Author of Securing DevOps and a security engineer at Google Cloud. Julien was previously on the Firefox Operations Security team, where he built and grew a remote DevSecOps team from the ground up. I picked up Julien's book a year ago, and it's loaded with practical tips for bringing security to DevOps, making Julien an ideal guest for today's episode. This episode isn’t sponsored by Julien or Manning Press, but I would highly recommend picking up a copy. We’ll have a link to the book in the show notes.

View Details

In this fourth episode of Access Control, a podcast providing practical security advice for startups, Developer Relations Engineer at Teleport Ben Arent chats with Adam Baldwin, aka evilpacket, Offensive Security at Auth0. Adam was previously the VP of security at npm and founder of ^Lift Security, an application and penetration testing company focused on the JavaScript Ecosystem. Adam is a two-time DEFCON Black Badge holder.

View Details

In this third episode of Access Control, a podcast providing practical security advice for startups, Ben Arent chats with Luca Carettoni, co-founder of Doyensec. Doyensec is an independent security research and development company focused on vulnerability discovery and remediation. The Teleport team has been working with Doyensec for the last two years and have worked together on security assessment for Teleport. In this episode, we’ll get a pentester's view on the current state of startup security.

View Details

In this second episode of Access Control, a podcast providing practical security advice for startups, Ben Arent chats with Dave Mangot, Principal at Mangoteque, a consultancy focused on helping companies become better at delivering software. Dave is prolific in the DevOps space and has helped improve the lives of thousands of IT Professionals through his best-selling video course, Mastering DevOps.

  • Not just developers and operations, but the entire business, needs to deliver value to customers.
  • DevOps is a movement — a way of looking at delivering software or delivering anything else.
  • Security is a huge, important part of delivering software — not building it in, early on, risks losing customers later when issues arise.
  • Efficiently increasing feedback loops and continual experimentation, to ensure testing prior to deployment, is a win for business goals.

View Details

In this first episode of Access Control, a podcast providing practical security advice for startups, Ben Arent chats with Donnie Hasseltine, CSO at Xenon Partner and CEO at TeamPassword & TeamsID. Donnie talks about his time working as a CSO at a boutique private equity firm, how they go about performing a security review before and during an acquisition. The chat deep-dives into how using a password manager can help secure your org to prevent phishing attempts and into Donnie’s transition from the US Army to cybersecurity to CSO and how to overcome imposter syndrome.