Learn Cloud Security in Public Cloud the unbiased way from CyberSecurity Experts solving challenges at Cloud Scale. We can be honest because we are not owned by Cloud Service Provider like AWS, Azure or Google Cloud.
We aim to make the community learn Cloud Security through community stories from small - Large organisations solving multi-cloud challenges to diving into specific topics of Cloud Security.
We LIVE STREAM interviews on Cloud Security Topics every weekend on Linkedin, YouTube, Facebook and Twitter with over 150 people watching and asking questions and interacting with the Guest.
How do you perform incident response on a Kubernetes cluster when you're not even on the same network? In this episode, Damien Burks, Senior Security engineer breaks down the immense challenges of container security and why most commercial tools are failing at automated response.
While many CNAPPs provide runtime detection, they lack a "sophisticated approach to automating incident response or containment" in complex environments like private EKS . He shares his hands-on experience building a platform that uses a dynamically deployed Lambda function to achieve containment of a compromised EKS node in just 10 minutes, a process that would otherwise take hours of manual work and approvals .
This is a guide for any DevSecOps or cloud security professional tasked with securing containerized workloads. The conversation also covers a layered prevention strategy, the evolving role of the cloud security engineer, and career advice for those looking to enter the field.
Guest Socials - Damien's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Security Podcast
Questions asked:
(00:00) Introduction(02:15) Who is Damien Burks?(03:20) The State of Cloud Incident Response in 2025(05:15) Why There is No Sophisticated, Automated IR for Kubernetes(06:20) A Deep Dive into Kubernetes Incident Response(07:30) The Unique Challenge of a Private EKS Cluster(12:15) A Layered Approach to Prevention in a DevSecOps Culture(17:00) How to Automate Containment in a Private EKS Cluster(17:40) From Hours to 10 Minutes: The Impact of Automation(22:00) The Evolving & Complex Role of the Cloud Security Engineer(25:40) Do We Have Too Much Visibility or Not Enough?(29:00) Career Path: The Value of Learning to Code for DevSecOps(35:00) Damien's Hot Take: "Multi-Cloud Just Means Chaos"(44:20) Career Advice for Traditional IR Professionals Moving to Cloud(47:50) Final Questions: Video Games, Life's Journey, and Gumbo
Resources spoke about during the interview
Damien's Website
"The next five years are gonna be wild." That's the verdict from Forrester Principal Analyst Allie Mellen on the state of Security Operations. This episode dives into the "massive reset" that is transforming the SOC, driven by the rise of generative AI and a revolution in data management.
Allie explains why the traditional L1, L2, L3 SOC model, long considered a "rite of passage" that leads to burnout is being replaced by a more agile and effective Detection Engineering structure. As a self-proclaimed "AI skeptic," she cuts through the marketing hype to reveal what's real and what's not, arguing that while we are "not really at the point of agentic" AI, the real value lies in specialized triage and investigation agents.
Guest Socials - Allie's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Security Podcast
Questions asked:
(00:00) Introduction(02:35) Who is Allie Mellen?(03:15) What is Security Operations in 2025? The SIEM & XDR Shakeup(06:20) The Rise of Security Data Lakes & Data Pipeline Tools(09:20) A "Great Reset" is Coming for the SOC(10:30) Why the L1/L2/L3 Model is a Burnout Machine(13:25) The Future is Detection Engineering: An "Infinite Loop of Improvement"(17:10) Using AI Hallucinations as a Feature for New Detections(18:30) AI in the SOC: Separating Hype from Reality(22:30) What is "Agentic AI" (and Are We There Yet?)(26:20) "No One Knows How to Secure AI": The Detection & Response Challenge(28:10) The Critical Role of Observability Data for AI Security(31:30) Are SOC Teams Actually Using AI Today?(34:30) How to Build a SOC Team in the AI Era: Uplift & Upskill(39:20) The 3 Things to Look for When Buying Security AI Tools(41:40) Final Questions: Reading, Cooking, and Sushi
Resources:
You can read Allie's blogs here
The race to deploy AI is on, but are the cloud platforms we rely on secure by default? This episode features a practical, in-the-weeds discussion with Kyler Middleton, Principal Developer, Internal AI Solutions, Veradigm and Sai Gunaranjan, Lead Architect, Veradigm as they compare the security realities of building AI applications on the two largest cloud providers.
The conversation uncovers critical security gaps you need to be aware of. Sai reveals that Azure AI defaults to sending customer data globally for processing to keep costs low, a major compliance risk that must be manually disabled . Kyler breaks down the challenges with AWS Bedrock, including the lack of resource-level security policies and a consolidated logging system that mixes all AI conversations into one place, making incident response incredibly difficult .
This is an essential guide for any cloud security or platform engineer moving into the AI space. Learn about the real-world architectural patterns, the insecure defaults to watch out for, and the new skills required to transition from a Cloud Security Engineer to an AI Security Engineer.
Guest Socials - Kyler's Linkedin + Sai's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Security Podcast
Questions asked:
(00:00) Introduction(02:30) Who are Kyler Middleton & Sai Gunaranjan?(03:40) Common AI Use Cases: Chatbots & Product Integration(05:15) Beyond IAM: The Full Scope of AI Security in the Cloud(07:30) The Role of the Cloud in Deploying Secure AI(13:10) AWS AI Architecture: Bedrock, Knowledge Bases & Vector Databases(15:10) Azure AI Architecture: AI Services, ML Workspaces & Foundry(21:00) The "Delete the Frontend" Problem: The Risk of Agentic AI(23:25) A Security Deep Dive into Microsoft Azure AI Services(29:20) Azure's Insecure Default: Sending Your Data Globally(31:35) A Security Deep Dive into AWS Bedrock(32:30) The Critical Gap: No Resource Policies in AWS Bedrock(33:20) AWS Bedrock's Logging Problem: A Nightmare for Incident Response(36:15) AWS vs. Azure: Which is More Secure for AI Today?(39:20) A Maturity Model for Adopting AI Security in the Cloud(44:15) From Cloud Security to AI Security Engineer: What's the Skill Gap?(48:45) Final Questions: Toddlers, Kickball, Barbecue & Ice Cream
For the last 30 years, email security has been stuck in the past, focusing almost entirely on stopping bad things from getting into the inbox. In this episode, Rajan Kapoor, Field CISO at Material Security and former Director of Security at Dropbox, argues that this pre-breach mindset is dangerously outdated. The real challenge today is post-breach: protecting the sensitive data that already lives inside your mailboxes.
The conversation explores why we must evolve from "email security" to the broader concept of "workspace security" . Rajan explains how interconnected productivity suites like Google Workspace and Microsoft 365 have turned the inbox into a gateway to everything else Drive, accounts, and sensitive company data. We also discuss how the rise of AI co-pilots will create new risks, as they can instantly find and surface over-shared data that was previously hidden in plain sight .
Guest Socials - Rajan's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Security Podcast
Questions asked:
(00:00) Introduction(02:00) Who is Rajan Kapoor? Field CISO at Material Security(02:38) What is Email Security in 2025? The 30-Year-Old Problem(03:20) The Critical Shift: From Pre-Breach to Post-Breach Protection(04:20) The Rise of Workspace Security: Beyond the Inbox(06:00) Why Focusing on Email is "Not Even Half" The Problem(06:50) Are Microsoft 365 Security Challenges Different from Google's?(09:30) Rethinking the Approach to Email Security(11:40) How AI Co-Pilots Will Exploit Your Over-Shared Data(13:30) A Real-World Attack: From Email to Malicious OAuth App(17:00) How Should CISOs Structure Their Teams for Workspace Security?(19:25) The Role of CASB vs. API-Based Security for Data at Rest(23:10) How CISOs Can Separate Signal From Noise in a Crowded Market(24:45) Final Questions: Home Automation, Career Risks, and Ethiopian Food
You have the visibility, you see the alerts, but your security backlog is still growing faster than your team can fix it. So, are you actually getting more secure? In this episode, Snir Ben Shimol, CEO of Zest Security, argues that "knowing about an open door or an open window don't make you more secure... just make you more aware" .
We spoke about the traditional "whack-a-mole" approach to vulnerability management. Snir shared an analogy: when planning a trip, the most important question isn't who goes first, but "what is the vehicle?" . He explains how AI's ability to perform recursive analysis can find the "vehicle" for your remediation efforts, that one base image upgrade or single code change that can reduce 20-30% of your entire vulnerability backlog in one action .
Guest Socials - Snir's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions:
(00:00) Introduction(02:30) Who is Snir Ben Shimol?(03:20) What is Cloud Security in 2025? Moving from Visibility to Action(07:25) Why Visibility Isn't Making You More Secure(10:20) The Slow, Manual Process of Remediation Today: Losing the Battle(16:00) The "Vehicle vs. Priority" Analogy for Vulnerability Management(17:45) How AI Enables Recursive Analysis to Find the Most Impactful Fix(20:00) The Three Pillars of AI-Driven Cloud Security Resolution(22:30) Why Your CNAPP/CSPM Can't Solve the Remediation Problem(25:20) Why Traditional Prioritization (EPSS, KEV) is a Waterfall Approach(28:10) The "Buy vs. Build" Dilemma for AI Security Solutions(30:15) The Complexity of Building a Multi-Agent AI System for Security(41:45) How CISOs Can Separate Real AI Products from Marketing Fluff(44:50) Final Questions: Surfing, Communication, and Thai Food
The conversation around cloud security is maturing beyond simple threat detection. As the industry grapples with alert fatigue, we explore the necessary shift from a reactive to a proactive security posture, questioning if a traditional SecOps model is sufficient for modern cloud environments.
We spoke with Gil Geron, CEO of Orca Security, to examine the limitations of a SecOps-centric defense. SecOps teams are inherently reactive, they cannot be the sole guardians of cloud infrastructure. Instead, the conversation centers on a new blueprint: viewing cloud security as an end-to-end workflow that integrates development, deployment, and production runtime with a continuous feedback loop into policy.
The role of AI is also explored, not just as a threat, but as an opportunity to empower security teams and make knowledge more accessible. We spoke about the power of context in reducing alert volume, citing a case where millions of vulnerabilities were prioritized down to a handful of actionable fixes.
Guest Socials - Gil's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction(02:12) Who is Gil Geron? From Check Point to CEO of Orca Security(02:54) What is Cloud Security in 2025? The Evolution to a Modern Workflow(05:50) How AI is Impacting the Cloud Security Landscape: A Salvation, Not a Risk(08:40) The Limits of a Reactive Approach: Why SecOps Can't Be Your Only Defense(12:15) The Surprising Truth: 95% of Cloud Malware is Introduced, Not Hacked(13:40) The Role of Identity in Cloud Security: The New Networking(18:00) The Current Cloud Security Landscape: From "Thumb Mistakes" to Neglected Assets(22:20) How CISOs are Modernizing Security by Modernizing Engineering Workflows(23:50) Reducing SOC Fatigue: How Context Turns Millions of Alerts into a Handful of Fixes(26:20) Is Auto-Remediation Safe? Why It's an Orchestration Challenge, Not a Technical One(35:20) Shifting Left with Production Context: The Future of AppSec & Cloud Sec(38:00) How to Choose a Security Vendor: Finding Hope, Not Fear(42:01) Final Questions: Hiking, Team Pride, and French Fries
Thank you to our episode sponsor - Orca Security
Identity is the root cause of over 70% of all security incidents, yet many organizations still rely on fundamentally flawed authentication methods. In this episode, Jasson Casey, CEO and co-founder of Beyond Identity, explains why even common forms of MFA are insufficient and why any system that relies on a "secret moving" is vulnerable to attack.
The conversation dives deep into the architectural shift needed to truly secure identity: moving from probabilistic tools to deterministic proof. Jasson breaks down how to leverage the hardware-backed secure enclaves (like TPMs and the Secure Enclave) that already exist in our devices to create un-phishable, device-bound credentials that can't be stolen or copied.
We also explore how this approach provides a necessary defense against the next wave of AI-enabled threats, including deepfakes and hyper-realistic social engineering attacks that will make it nearly impossible for humans to spot the difference.
Guest Socials - Jasson's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction(02:10) Who is Jasson Casey?(04:00) What is the 2025 Version of IAM?(07:15) Why Hasn't The Identity Problem Been Solved?(08:00) The Fundamental Flaw: Relying on Secrets That Move(10:00) The Solution: Un-phishable, Hardware-Backed Identity(12:15) Why Your Current MFA is Insufficient and Easily Exploited(14:42) The Apple Pay Analogy: How Secure Identity Already Works in Your Pocket(18:58) The "Aha!" Moment: Reducing Help Desk & SOC Workload(25:25) The AI Adversary: How Deepfakes Will Break Authentication(30:00) The Answer to AI Threats: Cryptographically Attested, Device-Bound Proof(32:15) Challenges of Adopting a New World of Identity(34:30) Beyond Human Identity: Securing Workloads, Drones & IoT(36:20) Deterministic vs. Probabilistic: A New Blueprint for Security(45:20) Final Questions: Drones, Cooking, and Tex-Mex
Thank you to Beyond Identity for sponsoring this episode
The nature of Security Operations is changing. As cloud environments grow in complexity and data volumes explode, traditional approaches to detection and response are proving insufficient. This episode features an in-depth conversation with Kyle Polley, who leads the AI security team at Perplexity, about a modern blueprint for the Security Operations Center (SOC).
The discussion centers on a necessary architectural shift away from traditional SIEMs, which were not built for today's scale, toward a "data lake infrastructure built for detection and response". Kyle explains how this model provides the scalability needed to handle modern data loads and enables a more effective incident response process.
A cornerstone of this new model is the use of centralized AI agents. The conversation explores how these agents can be tasked with performing in-depth alert investigations, helping to reduce analyst burnout and allowing security teams to focus on more proactive, high-impact work. This approach moves beyond simple automation to create a system where AI augments and enhances the capabilities of the human team.
Guest Socials - Kyle's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction to Kyle Polley & The Future of SOCs(01:03) The Core Argument: Why You Must Build Your SOC Before Compliance(03:34) Beyond the Certificate: The Difference Between Being Compliant vs. Secure(04:20) Today's #1 AI Threat: The Challenge of Prompt Injection(06:00) The Architectural Flaw: Handling Untrusted Data in AI Systems(08:20) The "Security Data Lake": Moving Beyond the Traditional SIEM(15:00) The Future is Now: A Centralized AI Agent for Automated Investigations(20:06) Will AI Take My Job? How AI Elevates, Not Replaces, the Security Analyst(25:20) Redefining "Shifting Left" with Personal AI Security Agents(31:00) Can AI Reason? How Modern AI Agents Intelligently Query Logs(37:05) Rethinking Incident Response Playbooks in the Age of AI(41:00) The MVP SOC: A Practical Roadmap for Small & Medium Companies(46:08) Final Questions: Maintaining Optimism, Woodworking, and Tex-Mex(50:08) Where to Connect with Kyle Polley
Resources spoken about during the episode:
Easy Agents: an open-source framework
How to give every department their own AI Agent
What does the integration of AI into a Security Operations Center (SOC) practically look like? This episode explores the concept of the "Agentic SOC," moving beyond marketing terms to discuss its real-world applications and limitations.
Ashish Rajan is joined by Edward Wu, CEO of Dropzone AI, for an in-depth discussion on the current state of artificial intelligence in cybersecurity. Edward, who holds numerous patents in the field, shares his perspective on how AI is changing security operations. The conversation details how AI agents can function as a tool to support human analysts rather than replace them, and why the idea of a fully autonomous SOC is not yet a reality.
Guest Socials - Edward's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction: Why Agentic AI in the SOC Matters Now(03:03) Meet Edward Wu: 30 Patents and a Mission to Fix Alert Fatigue(04:03) What is an "Agentic SOC"? (AI Foot Soldiers & Human Generals)(06:27) Why SOAR & Playbooks Are Not Enough for Modern Threats(08:18) Reality vs. Hype: Can AI Create a Fully Autonomous SOC?(11:55) The New SOC Workflow: How AI Changes Daily Operations(14:10) Can You Build Your Own AI Agent? The Hidden Complexities(19:06) From Skepticism to Demand: The Evolution of AI in Security(22:00) Slashing MTTR: How AI Transforms Key SOC Metrics(28:42) Are AI-Powered Cyber Attacks Really on the Rise?(31:01) How Smart SOC Teams Use ChatGPT & Co-Pilots Today(32:38) The 4 Maturity Levels of Adopting AI in Your SOC(37:04) How to Build Trust in Your AI's Security Decisions(41:28) Beyond the SOC: Which Cybersecurity Jobs Will AI Disrupt Next?(46:44) What is the Future for Level 1 SOC Analysts?(49:11) Getting to Know Edward: Sim Racing & StarCraft Champion
Resources spoken about during the episode:
Take a self-guided demo of Dropzone.ai
Request a Demo
Download a Copy of the Gartner Hype Cycle for Security Operations 2025
Thank you to our episode sponsor Dropzone.ai
A $10 billion fraud vector is currently exploiting a common feature in many cloud-native applications: the SMS verification flow. This isn't a traditional breach. Instead of stealing data, adversaries use bots to trigger costs that are quietly absorbed into your company's operational budget, often showing up as an inflated cell phone or marketing bill.
We spoke to Frank Teruel, COO at Arkose Labs about how this fraud works at a technical level and why modern, automated cloud workflows can be a perfect hiding place for these costly attacks. He also shares a story of how a single cloud container was hijacked, costing a company half a million dollars in compute costs for crypto mining over one weekend.
This is a critical conversation for anyone working in cloud security, DevOps, and engineering who wants to understand the financial risks embedded in the very architecture of their applications.
Guest Socials - Frank's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) The $10 Billion Invisible Threat(02:40) Frank Teruel’s Journey into Digital Identity(03:35) Why Identity Remains a Weak Spot for Cybersecurity(05:35) The Evolution of SMS Fraud(07:20) The "$5M Surprise Bill" Story(08:55) What is SMS Toll Fraud?(11:19) Does WAF Catch SMS Fraud?(12:49) Cloud vs. On-Prem: Is One Safer From SMS Fraud?(14:00) Does Single Sign-On Help With This?(15:55) How a Gaming Attack Becomes a Bank Heist(24:54) How AI is Weaponized for Cloud Attacks(25:35) The $500k Cloud Bill from a Hijacked Container(31:18) The Attack Vectors Cloud Teams Underestimate(35:30) What Are "Smart Bots"?(36:46) Where to Start Building a Program Around Fraud?(40:16) Fun Questions: Grandkids, Cooking & Music
How do you modernize security in a 180-year-old company that operates critical national infrastructure? What does it look like when you discover tens or even hundreds of thousands of credentials hidden across your estate?
In this episode, we sit down with Christian Schwarz, Security Director for Network Services at BT Group , recorded at HashiDays London. Christian shares the immense challenge and strategic approach to standardizing secret management across one of the world's oldest telecommunication companies.
He details BT's journey away from the "moat and a castle" security model towards a future with no passwords for developers , reducing friction and enhancing security by design.
Guest Socials - Christian's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) - Why Standardizing Secrets is a Challenge
(02:24) - Introducing Christian Schwarz & His Role at BT
(05:50) - Beyond the "Castle & Moat": A New Approach to Security
(07:59) - The Challenge of Securing a 180-Year-Old Company
(10:04) - The Power of Storytelling and Discovering Hidden Credentials
(11:59) - The Starting Point: Threat Modeling Your Critical Infrastructure
(13:48) - The Upside of Standardization: Reducing Cognitive Load for Teams
(16:08) - Fun Questions: Cycling, Innovation, and Favorite Cuisines
Thank you to our episode sponsor HashiCorp
Is AI making application security easier or harder? We spoke to Amit Chita, Field CTO at Mend.io, the rise of AI agents in the Software Development Lifecycle (SDLC) presents a unique opportunity for security teams to be stricter than ever before. As developers increasingly use AI agents and integrate LLMs into applications, the attack surface is evolving in ways traditional security can't handle. The only way forward is a Zero Trust approach to your own AI models
Join Ashish Rajan and Amit Chita as they discuss the new threats introduced by AI and how to build a resilient security program for this new era.
Guest Socials - Amit's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Intro: The New Era of AI-Powered AppSec(03:10) Meet Amit Chita: From Founder to Field CTO at Mend.io(03:47) Defining AI-Powered Applications in 2025(05:02) AI-Native vs. AI-Powered: What's the Real Difference?(06:05) How AI is Radically Changing the SDLC: Speed, Scale, and Stricter Security(16:30) The Hidden Risk: Navigating AI Model & Data Licensing Chaos(20:50) SMB vs. Enterprise: Why Their AI Security Problems Are Different(23:00) Why Traditional Security Testing Fails Against AI Threats(26:03) Do You Need to Update Your Entire Security Program for AI?(29:14) The New DevSecOps: Keeping Developers Happy in the Age of AI(31:26) Real AI Threats: Malicious Packages & Indirect Prompt Injection(35:16) Is Regulation Coming for AI? A Look at the Current Landscape(38:00) The AI Security Toolbox: To Build or To Buy?(41:41) Fun Questions: Amit’s Proudest Moment & Favorite Restaurant
Thank you to our episode sponsor Mend.io
Is your organization struggling with secret management across bare metal, hybrid, and multi-cloud environments? Standard cloud-native tools often fall short when you need a single, standardized solution that bridges all your infrastructure.
Dan Popescu, Senior Site Reliability Engineer at Booking.com joins us to share how they built a cloud-agnostic secret management strategy using HashiCorp Vault. We dive deep into the technical challenges of providing identity to bare metal machines, rotating dynamic secrets in legacy and modern applications, and why a central "broker" for authentication is critical for security at scale.
Guest Socials - Dan 's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction(02:13) Dan's Background: From Cloud (AWS, GCP) to Bare Metal(03:06) The Core Challenges: Secret Exposure, Rotation & Access Control(04:45) Why Cloud-Native Fails at Scale: The Cost of 500k Requests/Min(07:32) What is a "Secret"? (It's More Than Just Passwords)(09:12) The Secret Lifecycle: Rotation, Revocation & Caching Issues(10:33) Securing Bare Metal: The Unique Challenge of On-Prem Secrets(15:44) Kubernetes & Container Secrets: Sidecars vs. Operators(18:36) The Pain of Moving from Static to Dynamic Secrets(20:40) How Do Machines Get an Identity? (Cloud IAM vs. Bare Metal)(24:28) A Practical Roadmap: Where to Start Standardizing Secrets(26:53) Key Learnings & Technical Pitfalls to Avoid(28:59) The Fun Section
Many organizations focus on keeping attackers out, but what happens when one gets in? We spoke to Ramesh Ramani, Staff Security Engineer at Block about the real challenge, which is preventing them from leaving with your data. In this episode, Ramesh details the innovative system his team built to automate egress access control at scale, moving beyond traditional, inefficient methods.
Ramesh explains how by establishing "sources of truth" for both internal applications and external partners, they created a centralized governance model. This system uses SPIFFE IDs to understand application identity, validates data-sharing requests against partner approvals, and provides a seamless, self-service experience for developers. Discover how this approach not only enhances security by preventing unauthorized data exfiltration but also improves incident response, allowing them to instantly revoke access to compromised third-party domains.
Guest Socials - Ramesh's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) - Introduction(00:55) - Ramesh Ramani's Journey: From Network Engineer to Cloud Security at Block(02:03) - The "Trapped Thief" Analogy: Why Egress Is a Critical, Overlooked Problem(04:07) - The Trigger for Automation: Why Traditional Egress Security Doesn't Scale(07:36) - The Secret Sauce: Using SPIFFE IDs for Application Identity Across Any Cloud(14:42) - How It Works: Requesting Access & Denying Leaks to Partners like ChatGPT(30:39) - The Foundation: Why You Must Start with a "Source of Truth" for Apps & Partners(31:23) - Incident Response: Instantly Cutting Off Access When a Partner is Compromised(33:58) - Rollout Strategy: How to Implement Egress Controls Without Burdening Other Teams(37:35) - The Fun Section: Tech, Family, RPGs, and the Best Vegetarian Ramen
Resources discussed during the episode:
BSidesSF 2025 - Centralizing Egress Access Controls Across a Hybrid Environment.
When you can't protect everything at once, how do you decide what matters most? This episode tackles the core challenge of security prioritization. Geet Pradhan, Senior Security Engineer at Lime joins the podcast to share his framework for building a SecOps plan when you're a small team. Learn why his team made AWS logs their number one priority , how to leverage compliance requirements to guide your strategy , and why he advises starting with a small list of 1-5 critical applications instead of 35. Tune in for a conversation about strategic security for the modern cloud environment.
Guest Socials - Geet's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(00:32) Meet Geet Pradhan: Senior Security Engineer at Lime
(01:17) What is Detection & Response in 2025?
(04:35) Defining the Cloud Detection & Response Pipeline
(09:42) Why SIEM-Only Alerts Don't Work for Remote Teams
(12:02) How to Choose Your First Log Sources
(17:00) Building Security Culture: How to Not Be "The Police"
(22:45) Where to Find Pre-Built Detection Rules & Alerts
(28:38) On-Prem vs. Cloud: Why The Threat Model Is Different
(36:53) Fun Questions
Resources spoken about during the interview:
Geet's BSides SF Talk
Nate Lee - Power of Persuasion
In many organizations, security exception management is a manual process, often treated as a simple compliance checkbox. While necessary, this approach can lead to unmonitored configurations that drift from their approved state, creating inconsistencies in an organization's security posture over time. How can teams evolve this process to support modern development without compromising on security?
In this episode, Ashish Rajan sits down with security expert Santosh Bompally, Cloud Security Engineering Team Lead at Humana to discuss a practical framework for automating exception management. Drawing on his journey from a young tech enthusiast to a security leader at Humana, Santosh explains how to transform this process from a manual task into a scalable, continuously monitored system that enables developer velocity.
Learn how to build a robust program from the ground up, starting with establishing a security baseline and leveraging policy-as-code, certified components, and continuous monitoring to create a consistent and secure cloud environment.
Guest Socials - Santosh's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction(00:39) From Young Hacker to Cybersecurity Pro(02:14) The "Tick Box" Problem with Exception Management(03:17) Exposing Your Threat Landscape: The Risk of Not Automating(05:43) Where Do You Even Start? The First Steps(08:26) VMs vs Containers vs Serverless: Is It Different?(11:15) Building Your Program: Start with a Security Baseline(14:44) What Standard to Follow? (CIS, PCI, HIPAA)(17:20) The Lifecycle of a Control: When Should You Retire One?(19:42) The 3 Levels of Security Automation Maturity(23:25) Do You Need to Be a Coder for GRC Automation?(26:16) Fun Questions: Home Automation, Family & Food
In this episode, Ashish Rajan talks with Harry Wetherald, Co-Founder & CEO of Maze, about the reality of modern vulnerability management. They explore why current tools like CNAPPs can generate up to 90% false positives and how AI agents can provide a real solution by thinking like a security engineer to identify genuine, exploitable threats. Learn about the challenges of building your own AI solutions and how this new approach can eliminate noise and build trust between security and engineering team
Guest Socials - Harry's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction(02:27) Who is Harry Wetherald?(04:45) The "Wall of Red": Why Security Tools Create 90% False Positives(06:21) The Mission: Solving Vulnerability Overload with AI(10:11) How an AI Agent Investigates a Vulnerability(16:09) The Hard Reality of Building Your Own AI Solution(18:14) Building for a Future of Evolving AI Models(20:00) What is the Role of an MCP (AI Copilot)?(27:31) Building AI Agents for Cloud Security(31:25) "Think Like a Hacker": Asking AI to Red Team Your Cloud(33:04) How AI Will Shape Security Programs in 2025 & Beyond(36:20) Fun Questions with Harry
Thank you Maze for sponsoring this episode.
AI is reshaping cybersecurity as we know it. From sophisticated AI-driven phishing attacks to the amplified risk of insider threats using tools like Copilot, the landscape is shifting at an unprecedented pace. How can security leaders and practitioners adapt?
Join Ashish Rajan and Matthew Radolec (Varonis) as they explore the critical challenges and opportunities AI presents. Learn why 86% of attacks involve credential misuse and how AI agents are making it easier than ever for non-technical insiders to exfiltrate data.
In this episode, you'll learn about:
Guest Socials - Matt's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(01:57) New Threat Landscape in Cloud & AI
(08:08) Use cases for regulated industries
(10:03) Impact of Agentic AI in the cybersecurity space
(12:22) Blind spots of going into AI
(18:06) Shared responsibility for LLM providers
(20:56) Lifting up security programs for AI
(27:82) How is incident response changing with AI?
(29:30) Cybersecurity areas that will be most impacted by AI
(34:43) The Fun Section
Thank you to our episode sponsor Varonis
Is Artificial Intelligence the ultimate security dragon, we need to slay, or a powerful ally we must train? Recorded LIVE at BSidesSF, this special episode dives headfirst into the most pressing debates around AI security.
Join host Ashish Rajan as he navigates the complex landscape of AI threats and opportunities with two leading experts:
🔥 In this episode, we tackle the tough questions:
Guest Socials - Jackie's Linkedin + Kane's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Intro: Slaying or Training the AI Dragon at BSidesSF?
(03:15) Meet Jackie Bow (Anthropic): Training AI for Security Defense
(03:41) Meet Kane Narraway (Canva): Securing AI Systems & Facing Risks
(04:51) Was Traditional Security Ops "Hot Garbage"? Setting the Scene
(06:32) The Real Risks: What AI Brings to Your Organisation
(07:27) AI in Action: Leveraging AI for Threat Detection & Response
(08:37) AI Hallucinations: Bug, Feature, or Security Blind Spot?
(09:54) Threat Modeling AI: The Core Challenges & Learnings
(13:29) Getting Started: Practical AI Threat Detection First Steps
(17:56) AI & Cloud: Integrating AI into Your Existing Environments
(25:38) AI vs. Traditional: Is Threat Modeling Different Now?
(29:52) Your First Step: Where to Begin with AI Threat Modeling?
(33:17) Fun Questions & Final Thoughts on the Future of AI Security
As Artificial Intelligence reshapes our world, understanding the new threat landscape and how to secure AI-driven systems is more crucial than ever. We spoke to Ankur Shah, Co-Founder and CEO of Straiker about navigating this rapidly evolving frontier.
In this episode, we unpack the complexities of securing AI, from the fundamental shifts in application architecture to the emerging attack vectors. Discover why Ankur believes "you can only secure AI with AI" and how organizations can prepare for a future where "your imagination is the new limit," but so too are the potential vulnerabilities.
Guest Socials - Ankur's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(00:30) Meet Ankur Shah (CEO, Straiker)
(01:54) Current AI Deployments in Organizations (Copilots & Agents)
(04:48) AI vs. Traditional Security: Why Old Methods Fail for AI Apps
(07:07) AI Application Types: Native, Immigrant & Explorer Explained
(10:49) AI's Impact on the Evolving Cyber Threat Landscape
(17:34) Ankur Shah on Core AI Security Principles (Visibility, Governance, Guardrails)
(22:26) The AI Security Vendor Landscape (Acquisitions & Startups)
(24:20) Current AI Security Practices in Organizations: What's Working?
(25:42) AI Security & Hyperscalers (AWS, Azure, Google Cloud): Pros & Cons
(26:56) What is AI Inference? Explained for Cybersecurity Pros
(33:51) Overlooked AI Attack Surfaces: Hidden Risks in AI Security
(35:12) How to Uplift Your Security Program for AI
(37:47) Rapid Fire: Fun Questions with Ankur Shah
Thank you to this episode's sponsor - Straiker.ai
The world of cloud security is evolving at breakneck speed. Are traditional tools and strategies enough to combat the sophisticated threats of tomorrow? In this episode, we're joined by Elad Koren, Vice President of Product Management from Palo Alto Networks, to explore the dynamic journey of cloud security.
Elad shares his insights on how the landscape has shifted, moving beyond the era of CSPM and CNAPP as standalone solutions. We delve into why a cloud-aware Security Operations Center (SOC) is no longer a luxury but a necessity, and what "runtime security" truly means in today's complex, multi-cloud environments.
The conversation also tackles the double-edged sword of Artificial Intelligence, how it’s empowering both attackers with new capabilities and defenders with advanced tools. Elad discusses the critical considerations for organizations undergoing digital transformation, the importance of AI governance, and provides actionable advice for companies at all stages of their cloud adoption journey, from securing code from day one to building holistic visibility across their entire infrastructure.
Guest Socials - Elad's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(01:38) How has Cloud Security Evolved?
(04:21) Why CNAPP is not enough anymore?
(07:13) What is runtime security?
(07:54) Impact of AI on Cloud Security
(11:41) What to include in your cybersecurity program in 2025?
(16:47) The Fun Section
Thank you to this episode's sponsor - PaloAlto Networks
Resources discussed during the episode:
PaloAlto Networks RSAC Announcement 1
PaloAlto Networks RSAC Announcement 2
Dive deep into the key takeaways from RSA Conference 2025 with our expert panel! Join Ashish Rajan, James Berthoty, Chris Hughes, Tanya Janca, and Francis Odum as they dissect the biggest trends, surprises, and "hot takes" from one of the world's largest cybersecurity events.
In this episode, we cover:
Guests include:
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction: Unpacking the RSA Conference 2025
(02:20) Meet the Experts: Panelist Introductions
(03:39) RSAC First Impressions: Scale, Excitement & Attendee Numbers
(07:52) Top Themes from RSA Conference 2025
(16:01) AI's Evolution: Native Applications & AppSec's Transformation
(33:30) Demystifying Runtime Security (Beyond DAST)
(40:23) RSA Surprises & Unexpected Takeaways
Join Ashish Rajan in this episodeas he dives deep into the evolving world of cloud security with Sergej Epp, formerly of Deutsche Bank and Palo Alto Networks, now with Sysdig.
Discover why traditional security approaches fall short in today's dynamic cloud-native environments, where workloads resemble swarms of drones rather than predictable trains. Sergej explains the critical shift from basic posture management (CSPM/CNAPP) towards runtime security, emphasizing the need for an "assume breach" mindset.
Learn about the staggering reality that over 60% of containers now live for less than a minute and the immense challenges this poses for detection, incident response, and forensics.
This episode covers:
Guest Socials: Sergej Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction: Cloud Security & The One-Minute Container Problem
(01:31) Meet Sergej Epp: 20+ Years in Cybersecurity (Deutsche Bank, Palo Alto, Sysdig)
(02:44) What is Cloud Native Today? From Train Stations to Airports with Drones
(05:34) Runtime Security Explained: Why It's Crucial Now
(11:05) The Evolution of Cloud Security: Beyond Basic Posture Management
(13:49) Incident Response Evolution: Tackling One-Minute Containers
(18:34) Who Needs Runtime Security? Platform Engineers, SOC Teams & More
(21:01) Runtime Security as a Platform: Beyond Detection to Prevention & Insights
(24:45) Cloud Security Program Maturity: From On-Prem to Cloud Native SOC
(29:20) AI in SOC Operations: Speeding Up Forensics & Context
Are you struggling to implement robust container security at scale without creating friction with your development teams? In this episode, host Ashish Rajan sits down with Cailyn Edwards, Co-Chair of Kubernetes SIG Security and Senior Security Engineer, for a masterclass in practical container security. This episode was recorded LIVE at KubeCon EU, London 2025.
In this episode, you'll learn about:
Guest Socials: Cailyn's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Intro: Container Security at Scale
(01:56) Meet Cailyn Edwards: Kubernetes SIG Security Co-Chair
(03:34) Why Container Security Matters: Risks & Exposures Explained
(06:21) Automating Container Security: From Scans to Admission Controls
(12:19) Essential Container Security Tools (Trivy, OPA, Chainguard & More)
(19:35) Overcoming DevSecOps Challenges: Working with Developers
(21:31) Proactive Security: Shifting Down, Not Just Left
(25:24) Fun Questions with Cailyn
Resources spoken about during the interview:
Cailyn's talk at KubeCon EU 2025
In this episode, Ashish sits down with Christian Philipov, Principal Security Consultant at WithSecure, to explore the stealth tactics threat actors are using in Azure and why many of these go undetected.
Christian breaks down the lesser-known APIs like Ibiza and PIM, how Microsoft Graph differs from legacy APIs, and what this means for defenders.
Guest Socials: Christian's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:09) A bit about Christian
(02:39) What is considered stealthy in Azure?
(04:39) Which services are stealthy in Azure?
(06:25) PIM and Ibiza API
(12:53) The role of Defender for Cloud
(18:04) Does the Stealthy API approach scale?
(19:26) Preventing Stealthy API attacks
(21:49) Best Practices for Prevention in Azure
(25:47) Behaviour Analysis in Azure
(29:31) The Fun Section
Resources spoken about during the interview:
Christian's fwd:cloudsec talk - Staying Sneaky in Microsoft Azure
Christian's Disobey Talk
Ever tried solving DNS security across a multi-cloud, multi-cluster Kubernetes setup? In this episode recorded live at KubeCon, Ashish chats with Nimisha Mehta and Alvaro Aleman from Confluent's Kubernetes Platform Team.
Together, they break down the complex journey of migrating to Cilium from default CNI plugins across Azure AKS, AWS EKS, and Google GKE. You’ll hear:
Guest Socials: Alvaro's Linkedin + Nimisha's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(01:55) A bit about Alvaro
(02:41) A bit about Nimisha
(03:11) About their Kubecon NA talk
(03:51) The Cilium use case
(05:16) Using Kubernetes Native tools in all 3 cloud providers
(011:41) Lessons learnt from the project
Resources spoken about during the interview
Confluent's Multi-Cloud Journey to Cilium: Pitfalls and Lessons Lea... Nimisha Mehta & Alvaro Aleman
The cloud security landscape may have just shifted — and we're here to break it down.
In this special panel episode, host Ashish Rajan is joined by an all-star group of cloud and cybersecurity experts to discuss one of the most important conversations in cloud security today: the changing nature of security architecture, SOC readiness, and how teams must evolve in a multi-cloud world.
Guests include:
We Cover:
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:05) A bit about our panelists
(04:24) Current Cloud Security Landscape
(09:36) Challenges with Multi-Cloud Security
(18:06) Runtime Security for Cloud
(23:34) Can SOC deal with CNAPP Alerts
(26:23) CISO planning their cybersecurity program
(32:38) Regulatory requirements in public sector
(36:27) Success Metrics for Modern Cloud Security Program
Detection rules aren’t just for fun—they’re critical for securing cloud environments. But are you using them the right way? In this episode, Ashish Rajan sits down with David French, Staff Adoption Engineer for Security at Google Cloud, to break down how organizations can scale Detection as Code across AWS, Azure, and Google Cloud.
David has spent over a decade working in detection engineering, threat hunting, and building SIEM & EDR products. He shares real-world insights on how companies can improve their detection strategies and avoid costly security missteps.
Guest Socials: David's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(03:06) What is Detection as Code?
(03:41) What was before Detection as Code?
(05:36) Business ROI for doing Detection as Code?
(07:49) Building Security Operations in Google Cloud
(12:41) Threat Detection for different type of workload
(14:54) What is Google SecOps?
(20:36) Different kinds of Detection people can create
(24:46) Scaling Detection across many Google Cloud accounts
(28:47) The role of Data Pipeline in Detection
(31:44) Detections people can start with
(34:14) Stages of maturity for detection
(36:43) Skillsets for Detection Engineering
(39:32) The Fun Section
In this episode we speak to Nick Jones, an expert in offensive cloud security and Head of Research at WithSecure to expose the biggest security gaps in cloud environments and why CNAPPs and CSPMs alone are not enough often.
With real-world examples from red team engagements and cloud security research, Nick shares insider knowledge on how attackers target AWS, Azure, and Kubernetes environments—and what security teams can do to stop them.
Guest Socials: Nick's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:40) A bit about Nick Jones
(03:56) How has Cloud Security Evolved?
(05:52) Why do we need pentesting in Cloud Security?
(08:09) Misconfiguration vs Vulnerabilities
(11:04) Cloud Pentesting in Different Environments
(17:05) Impact of Kubernetes Adoption on Offensive Cloud Security
(20:19) Planning for a Cloud Pentest
(29:04) Common Attacks Paths in Cloud
(33:05) Mitigating Common Risk in Cloud
(35:14) What is Detection as Code?
(41:17) Skills for Cloud Pentesting
(45:28) Fun Sections
What does it take to secure AI-based applications in the cloud? In this episode, host Ashish Rajan sits down with Bar-el Tayouri, Head of Mend AI at Mend.io, to dive deep into the evolving world of AI security. From uncovering the hidden dangers of shadow AI to understanding the layers of an AI Bill of Materials (AIBOM), Bar-el breaks down the complexities of securing AI-driven systems. Learn about the risks of malicious models, the importance of red teaming, and how to balance innovation with security in a dynamic AI landscape.
Guest Socials: Bar-El's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:24) A bit about Bar-el
(03:32) What is AIBOM?
(12:58) What is an embedding model?
(16:12) What should Leaders have in their AI Security Strategy?
(19:00) Whats different about the AI Security Landscape?
(23:50) Challenges with integrating security into AI based Applications
(25:33) Has AI solved the disconnect between Security and Developers
(28:39) Risk framework for AI Security
(32:26) Dealing with threats for current AI Applications in production
(36:51) Future of AI Security
(41:24) The Fun Section
AWS networking isn’t as simple as it seems and when you’re dealing with regulated industries like healthcare, the stakes are even higher.
In this episode we sit down with Kyler Middleton and Jack W. Harter from Veradigm — who have navigated complex AWS networking challenges while migrating from on-prem data centers to the cloud.
We speak about:
Guest Socials: Kyler's Linkedin + Jack's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(01:55) A bit about Kyler and Jack
(03:18) Security Challenges in Medical Industry
(06:01) Where to start when migrating from data centres to AWS?
(07:42) Networking Challenges for Regulated Industries
(11:26) Networking in On-Prem vs Cloud
(19:24) Security by Design considerations
(29:31) The Terraform pieces
(34:34) Network Firewall in Cloud
(39:46) Lessons learnt from the project
(46:21) The Fun Section
Resources:
Let's Do DevOps - Kyler's Website
Jack's Website
Day Two DevOps - Podcast Co-Hosted by Kyler
In this episode, we dive deep into Azure security, incident response, and the evolving cloud threat landscape with Katie Knowles, Security Researcher and former Azure Incident Responder. We spoke about common Azure incident response scenarios you need to prepare for, how identity and privilege escalation work in Azure, how Active Directory and Entra ID expose new risks and what security teams need to know about Azure networking and logging.
Guest Socials: Katie's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:27) A bit about Katie
(03:17) Domain Admin in Azure
(07:03) Common causes of incidents in Azure
(08:53) Identities in Azure
(11:44) Third Party Identities in Azure
(17:34) Azure Networking and Incident Response
(22:35) Common Incidents in Azure
(26:53) AI specific incidents in Azure
(28:45) Privilege escalation in Azure
(39:37) Where to start with Azure Research?
(48:20) The Fun Questions
🚀 How do you secure thousands of AWS accounts without slowing down developers? Netflix’s cloud security experts Patrick Sanders & Joseph Kjar join us to break down their identity-first security model and share lessons from scaling security across a massive AWS multi-account environment.
In this episode, we cover:
Guest Socials: Patrick's Linkedin +Joseph's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:05) A bit about Joseph
(02:32) A bit about Patrick
(02:38) Scaling security across multiple accounts
(03:29) Least Privilege is hard
(06:44) Why go down the identity path?
(08:49) Identity based approach for least privilege
(15:43) Security at scale for Multi Account in AWS
(23:54) Lessons from the project
(27:02) What would be classified as an easy migration?
(30:55) How the project has progressed?
(35:01) Automation Pieces that enabled the project
(37:54) Where to start with scaling security across Multi Accounts?
(39:21) Resource Access Manager and how it fits into migration
Resources discussed in this interview:
Accelerate insights using AWS SDK instrumentation Talk
Patrick and Joseph’s Talk - Netflix's massive multi-account journey: Year two
Joseph and Patrick's previous interview on Cloud Security Podcast
We spoke to Will Bengtson (VP of Security Operations at HashiCorp) bout the realities of cloud incident response and detection. From root credentials to event-based threats, this conversation dives deep into:
Guest Socials: Will's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(00:38) A bit about Will Bengtson
(05:41) Is there more awareness of Incident Response in Cloud
(07:05) Native Solutions for Incident Response in Cloud
(08:40) Incident Response and Threat Detection in the Cloud
(11:53) Getting started with Incident Response in Cloud
(20:45) Maturity in Incident Response in Cloud
(24:38) When to start doing Threat Hunting?
(27:44) Threat hunting and detection in MultiCloud
(31:09) Will talk about his BlackHat training with Rich Mogull
(39:19) Secret Detection for Detection Capability
(43:13) Building a career in Cloud Detection and Response
(51:27) The Fun Section
In this episode, we sit down with Sunil Rane, an experienced cybersecurity leader with over 20 years in cybersecurity across industries like healthcare, education, media, and consulting. Sunil shares unique insights into the diverse challenges faced by CISOs, from managing data sensitivity in healthcare to the lack of standardized frameworks in media, how to balance data availability and security without compromising operational efficiency, the complexities of being a custodian of data in consulting and how to manage cross-industry compliance and why communication and collaboration are critical for CISOs, from internal stakeholders to public sector regulators.
Guest Socials: Sunil's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:13) A bit about Sunil Rane
(03:25) Cybersecurity in education and healthcare
(09:12) Cybersecurity and consulting
(15:49) Cybersecurity challenges in public and private sector
(18:35) Cybersecurity in the media industry
(25:48) Skillset for becoming a CISO
(29:36) The Fun Section
In this episode we’re joined by Francis Odum, founder and lead research analyst at Software Analyst Cyber Research. Drawing from his extensive research and conversations with CISOs, security operators, and vendors, Francis shares his insights on the state of identity security and the rise of non-human identities (NHI) in the cloud, why solving the data problem is critical to reducing false positives, improving SOC efficiency, and cutting costs, the early but growing landscape of AI and LLM security and its intersection with DSPM and data governance and predictions for 2025 trends, including what should be ditched and what the cybersecurity industry should prioritize.
Guest Socials: Francis's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(01:56) A bit about Francis
(03:45) What is CNAPP in 2025?
(06:55) The Identity space in 2025
(10:34) The state of SOC in 2025
(19:23) The AI Security Ecosystem
(24:44) DSPM vs DLP
(29:48) What should we ditch in 2025?
(33:01) What should we see a lot more in 2025?
(41:39) A bit about Cloud Security Bootcamp
(42:58) The Fun Section
Resources spoken about during the episode:
Software Analyst Cyber Research
In this episode, host Ashish Rajan spoke to Mike Privette, founder of Return on Security, to explore the landscape of cybersecurity as we look toward 2025. Mike shared his unique insights on the economics of cybersecurity, breaking down industry trends, and discussing how AI is revolutionizing areas like governance, risk, compliance (GRC), and data loss prevention (DLP). They dive into the convergence of cloud security and application security, the rise of startups, and the ever-present "cat-and-mouse game" of adapting to investor and buyer needs.
Guest Socials: Mike's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security Podcast- Youtube
Cloud Security Newsletter
Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(00:27) A bit about Mike
(00:49) The story behind Return On Security
(01:40) How big is the cybersecurity landscape?
(04:36) Cybersecurity Trends from 2024
(07:03) AI Security in 2024
(08:10) Cybersecurity Trends in 2025
(13:16) Trends to look at when starting a company
(16:18) Trends for Startups
(17:37) Do new vendors enter the cybersecurity market?
(18:53) Whats a healthy cybersecurity industry?
(20:12) The world of startup acquisitions
(22:29) The Fun Section
In this episode of the Cloud Security Podcast, host Ashish Rajan speaks to James Berthoty, founder of Latio.Tech and an engineer-driven analyst, for a discussion on cloud security tools. In this episode James breaks down CNAPP and what it really means for engineers, if kubernetes secuity is the new baseline for cloud security and runtime security vs vulnerability management.
Guest Socials: James's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:26) A bit about James
(03:20) What in Cloud Security in 2025?
(04:51) What is CNAPP?
(07:01) Differentiating a vulnerability from misconfiguration
(11:51) Vulnerability Management in Cloud
(15:38) Is Kubernetes becoming the default?
(21:50) Is there a good way to do platformization?
(24:16) Should CNAPP include Kubernetes?
(28:07) What is AI Security in 2025?
(35:06) Tool Acronyms for 2025
(37:27) Fun Questions
In this episode our host Ashish Rajan sat down with Ross Haleliuk, author of Cybersecurity for Builders and creator of the Venture in Security blog, to explore the current state and future of the cybersecurity industry. From understanding the challenges of building a cybersecurity startup to the dynamics of security engineering and market trends for 2025. Ross and Ashish explore why the cybersecurity industry isn’t as crowded as it seems and the divide between companies that build in-house security and those that rely on vendors.
Ross also unpacks why sales and marketing aren’t “dirty words” in cybersecurity, why security engineering is “the present,” and how practitioners can balance business needs with technical aspirations.
Guest Socials: Ross's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(05:33) How Venture in Security started?
(09:33) Security Engineering in Cybersecurity
(18:18) Cybersecurity markets that will be top of mind in 2025
(24:15) GTM for Defender Tools
(30:09) Vulnerabilities vs Misconfiguration Tools
(37:56) How should product companies think about GTM?
(44:27) How to decide between different security tools?
(56:36) Cybersecurity for Builders book
(01:05:00) The Fun Section
Resources shared during the episode:
Venture in Security Blog
Cyber for Builders Book
Challenges in Security Engineering Programs - Rami McCarthy
Cybersecurity is not a market for lemons. It is a market for silver bullets
The Market for Silver Bullets
In this episode, Meg Ashby, a senior cloud security engineer shares how her team tackled AWS’s centralized VPC interface endpoints, a design often seen as an anti-pattern. She explains how they turned this unconventional approach into a cost-efficient and scalable solution, all while maintaining granular controls and network visibility. She shares why centralized VPC endpoints are considered an AWS anti-pattern, how to implement granular IAM controls in a centralized model and the challenges of monitoring and detecting VPC endpoint traffic.
Guest Socials: Meg's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:48) A bit about Meg Ashby
(03:44) What is VPC interface endpoints?
(05:26) Egress and Ingress for Private Networks
(08:21) Reason for using VPC endpoints
(14:22) Limitations when using centralised endpoint VPCs
(19:01) Marrying VPC endpoint and IAM policy
(21:34) VPC endpoint specific conditions
(27:52) Is this solution for everyone?
(38:16) Does VPC endpoint have logging?
(41:24) Improvements for the next phase
Thank you to our episode sponsor Wiz. Cloud Security Podcast listeners can also get a free cloud security health scan by going to wiz.io/csp
In this episode, recorded at Kubecon NA in Salt Lake City, we spoke about about Kubernetes security with Shauli Rozen, co-founder and CEO of ARMO Security. From the challenges of runtime protection to the potential of CADR (Cloud Application Detection and Response), Shauli breaks down the gaps in traditional CSPM tools and how Kubernetes plays a central role in cloud security strategy. The episode gets into the "Four C's" of cloud security: Cloud, Cluster, Container, Code, why runtime data, powered by eBPF, is critical for modern security solutions, the rise of CADR and how Kubernetes is reshaping the landscape of DevOps and security collaboration.
Guest Socials: Shauli's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:46) A bit about Shauli and ARMO
(02:26) Bit about open source project Kubescape
(03:59) What is Runtime Security in Kubernetes?
(06:50) CDR and Application Security
(08:57) What is ADR and CADR?
(09:55) How is CADR different to ASPM + DAST?
(12:18) Kubernetes Usage and eBPF
(15:35) Does your CSPM do coverage for Kubernetes?
(16:24) What to include in 2025 Cybersecurity Roadmap?
(19:09) Does everyone need CADR?
(21:35) Who is looking at the Kubernetes Security Logs?
(23:17) The future of Kubernetes Security
(25:26) The Fun Section
At HashiConf 2024 in Boston, our host Ashish Rajan had a great chat over some cannolis and a game of Jenga with AJ Oller, AVP of Engineering at The Hartford about how automation, mainframes, and compliance intersect to drive innovation in regulated industries like insurance. They spoke about why regulations aren't barriers but frameworks to prevent failure, the human side of engineering and how to manage change fatigue during transformations and how automation enhances security, disaster recovery, and operational efficiency.
Guest Socials:AJ' s Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:53) A bit about AJ Oller
(02:17) The Cannoli taste test
(04:38) Technology in the Insurance industry
(10:19)What is a platform?
(11:46) What skillsets do you need in platform team?
(14:19) Maturity for building platform teams
(19:5)8 Business case for investing in Automation
(24:49) Does Automation help with security regulations?
(28:10) Leaders communicating automation value to business
(30:37) Cheerleading for digital transformation
(32:32) The Fun Section
In this episode, Ashish spoke with Kushagra Sharma, Staff Cloud Security Engineer, to delve into the complexities of managing Identity Access Management (IAM) at scale. Drawing on his experiences from Booking.com and other high-scale environments, Kushagra shares insights into scaling IAM across thousands of AWS accounts, creating secure and developer-friendly permission boundaries, and navigating the blurred lines of the shared responsibility model.
They discuss why traditional IAM models often fail at scale and the necessity of implementing dynamic permission boundaries, baseline strategies, and Terraform-based solutions to keep up with ever-evolving cloud services. Kushagra also explains how to approach IAM in multi-cloud setups, the challenges of securing managed services, and the importance of finding a balance between security enforcement and developer autonomy.
Guest Socials:Kushagra's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:31) A bit about Kushagra
(03:29) How large can the scale of AWS accounts be?
(03:49) IAM Challenges at scale
(06:50) What is a permission boundary?
(07:53) Permission Boundary at Scale
(13:07) Creating dynamic permission boundaries
(18:34) Cultural challenges of building dev friendly security
(23:05) How has the shared responsibility model changed?
(25:22) Different levels of customer shared responsibility
(29:28) Shared Responsibility for MultiCloud
(34:05) Making service enablement work at scale
(43:07) The Fun Section
In this episode, host Ashish Rajan sits down with Prahathess Rengasamy, a cloud security expert with extensive experience at companies like Credit Karma, Block, and Apple. Together, they explore the challenges and best practices for scaling cloud security, especially in the complex scenarios of mergers and acquisitions.
Starting with foundational elements like CSPMs and security policies, Prahathess breaks down the evolution of cloud security strategies. He explains why cloud security cannot succeed in isolation and emphasizes the need for collaboration with platform and infrastructure engineering teams. The conversation delves into real-world examples, including managing AWS and GCP security post-acquisition and navigating the cultural and technical challenges that come with multi-cloud environments.
Guest Socials:Prahathess's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:02) A bit about Prahathess
(02:36) How does Cloud Security Scale?
(07:51) Where do we see just in time provisioning?
(10:05) Cloud Security for Mergers and Acquisitions
(14:31) Should people become MultiCloud Experts?
(15:28) The need for data insights
(16:54) Data sources to have as part of data insights
(21:06) Benefits of Data insights for Cloud Security Teams
(21:30) How to bring the new team along the cloud security journey?
(24:29) How to learn about data insights?
(26:35) How to maximize security efforts with data?
(36:21) The Fun Section
In this episode, Ashish gets into the critical topic of data perimeters in AWS with our guest, Tyler Warren, a Lead Cloud Security Engineer at USAA. As cloud environments continue to evolve, the importance of securing your data through trusted networks and identities has never been more crucial.
Tyler shares his insights on the challenges and strategies involved in building effective data perimeters, emphasizing the need for a holistic security approach that includes both preventative and detective controls. We explore how concepts like trusted resources, networks, and identities play a pivotal role in safeguarding your cloud infrastructure and why these elements should be at the core of your security strategy. Join us as we discuss practical steps for implementing and managing data perimeters, the significance of understanding your zones of trust, and how to scale your security measures as your cloud footprint grows.
Guest Socials:Tyler's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:28) A bit about Tyler
(04:22) Data Perimeter in Cloud Security
(08:18) Why was there a need to look into data perimeter?
(09:39) Should people look at data perimeter from the beginning?
(12:16) Starting point for data perimeter
(15:42) Defining boundaries of Zone of Trust
(21:25) Data perimeter in hybrid environments
(24:47) Challenges in setting up data perimeter
(31:31) Should you start in dev, test or prod?
(34:55) How often should you review your SCPs?
(36:05) What Skillsets does the team need?
(37:26) Are Data Perimeters Developer Friendly?
(40:06) Technical challenges with detective and preventative controls
(42:14) Getting stakeholders onboard
(46:56) Levels of maturity for data perimeter strategy
(49:30) The Fun Section
Resources spoken about during the interview:
AWS Data Perimeter at USAA: Things we knew, things we thought we knew and things you should know!
In this episode, we sat down with Lukasz Gogolkiewicz, an Australia-based Cybersecurity Leader and former pentester, to explore his journey from offensive security into cybersecurity leadership. Lukasz, also a speaker coach at BlackHat USA, brings valuable insights into what it takes to shift from being technical to managing compliance, governance, and broader security programs in industries like retail and advertising.
Throughout the conversation, we dive into the specific challenges of transitioning from a purely cloud-based tech company to a bricks-and-mortar retail operation, highlighting how the threat models differ dramatically between these environments. Lukasz shares his unique perspective on cybersecurity frameworks like NIST CSF 2.0, essential for building resilient programs, and offers practical advice for selecting the right framework based on your organization's needs.
Guest Socials:Lukasz's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(03:00) A bit about Lukasz
(04:32) Security Challenges for Tech First advertising company
(05:16) Security Challenges for Retail Industry
(06:00) Difference between the two industries
(07:01) Best way to build Cybersecurity Program
(09:44) NIST CSF 2.0
(13:02) Why go with a framework?
(16:26) Which framework to start with for your cybersecurity program?
(18:33) Technical CISO vs Non Technical CISO
(25:37) The Fun Section
Resources spoken about during the interview:
NIST CSF 2.0
CIS Benchmark
ASD Essential Eight
Mapping between the frameworks
https://www.cisecurity.org/insights/white-papers/cis-controls-v8-mapping-to-nist-csf-2-0
https://www.cisecurity.org/insights/white-papers/cis-controls-v8-mapping-to-asds-essential-eight
Verizon Data Breach Investigations Report (DBIR)
Lukasz Woodwork Channel
BSides Melbourne
What is the future of SOC? In this episode Ashish sat down with Allie Mellen, Principal Analyst at Forrester, to explore the current state of security operations and the evolving role of AI in cybersecurity. Allie spoke about why Cloud Detection Response (CDR) might be dead, how Generative AI is failing to live up to its hype in security use cases, and why automation will never fully replace human security analysts.
We get into the challenges faced by SOC teams today, the burnout issue among security analysts, and how adopting detection engineering and eliminating the outdated structures could transform the way security teams operate.
Guest Socials:Allie's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:48) A bit about Allie
(03:13) The role of analysts in cybersecurity
(05:56) What is EDR?
(06:30) What is XDR?
(08:42) The impact of GenAI
(10:19) How is GenAI going to impact SOAR?
(14:52) Where to start with SOC?
(24:08) Starting to build your SOC team
(27:32) How SOC should respond to new technology?
(31:48) Expectations from Managed SOC providers
(35:16) Detection challenges for Hybrid Environments
(38:01) Level 2 and 3 SOC in new world
(42:37) What training is required for the SOC team?
(48:49) How will this space evolve?
(51:48) The Fun Questions
Resources spoken about during the interview:
Cloud Detection and Response Tools Do Not Exist
In this episode Ashish Rajan sits down with Shashwat Sehgal, co-founder and CEO of P0 Security, to talk about the complexities of cloud identity lifecycle management. Shashwat spoke to us about why traditional identity solutions like SAML are no longer sufficient in today’s cloud environments. He discusses the need for organisations to adopt a more holistic approach to secure access across cloud infrastructures, addressing everything from managing IAM roles to gaining complete visibility and inventory of all cloud identities.
This episode goes into the growing challenges around managing human and non-human identities, and the importance of shifting from legacy solutions to cloud-native governance.
Guest Socials:Shashwat's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:47) A bit about Shashwat
(02:20) What is Identity Lifecycle Management?
(04:55) What is IGA and PAM?
(10:10) Complexity of Identity Management
(13:12) What are non human identities?
(15:56) Maturity Levels for Cloud Identity Lifecycle Management
(19:03) The role of SAML in Identity Management
(20:07) Identity Management of Third parties and SaaS Providers
(21:28) Who’s responsible for identity management in Cloud?
(23:28) Changing landscape of identity management
(27:46) Native Solutions for identity management
(30:03) Fun Questions
In this episode of the Cloud Security Podcast, Ashish sat down with Art Poghosyan, CEO and co-founder of Britive, to explore the changing world of identity and access management (IAM) in the cloud era. With over two decades of experience in the identity space, Art breaks down the challenges of traditional Privileged Access Management (PAM) and how cloud-native environments require a rethinking of security strategies.
From understanding the complexities of cloud infrastructure entitlements to unpacking the differences between on-premise and cloud-based PAM, Art explains why "Identity is the new perimeter" and how modern organizations must adapt. They dive deep into the importance of Just-in-Time (JIT) access, non-human identities, and the critical role identity plays as the first and last line of defense in cloud security.
Guest Socials:Art's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:53) A bit about Art
(02:51) What is IAM?
(04:02) What is Cloud Privilege Access Management?
(06:08) Why do we need CloudPAM in 2024?
(07:52) Non Human Identities
(08:39) Privilege in Cloud vs On Premise
(09:49) SAML vs PAM
(12:21) Just in Time provisioning in Cloud
(17:17) Making Access Management Developer Friendly
(19:12) What should security team be looking at ?
(21:22) Communicating IAM vulnerabilities
(23:45) Tactical steps to level up IAM
(27:20) Zero Trust and IAM
(30:56) Fun Questions
Why does Cloud Security Research matter in 2024? At fwd:cloudsec EU in Brussels, we sat down with Scott Piper, a renowned cloud security researcher at Wiz, to discuss the growing importance of cloud security research and its real-world impact. Scott spoke to us about the critical differences between traditional security testing and cloud security research, explaining how his team investigates cloud providers to find out vulnerabilities, improve detection tools, and safeguard data.
Guest Socials:Scott's Linkedin + Scott's Twitter
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:07) A bit about Scott Piper
(02:48) What is a Cloud Security Research Team?
(04:30) Difference between traditional and Cloud Security Research
(07:21) Cloud Pentesting vs Cloud Security Research
(08:10) What is request collapsing?
(10:26) GitHub Actions and OIDC Research
(13:47) How has cloud security evolved?
(17:02) Tactical things for Cloud Security Program
(18:41) Impact of Kubernetes and AI on Cloud
(20:37) How to become a Cloud Security Researcher
(22:46) AWS Cloud Security Best Practices
(26:35) Trends in AWS Cloud Security Research
(28:11) Fun Questions
(30:22) A bit about fwd:cloudsec
Resources mentioned during the interview:
Wiz.io - Cloud Security Podcast listeners can also get a free cloud security health scan
PEACH framework
Wiz Research Blog
Avoiding security incidents due to request collapsing
A security community success story of mitigating a misconfiguration
Cloudmapper
flaws.cloud
fwd:cloudsec
CTFs
The Big IAM Challenge
Prompt Airlines , AI Security Challenge
Kubernetes LAN Party
How does Edge Security fit into the future of Cloud Protection ? In this episode, we sat down with Brian McHenry, Global Head of Cloud Security Engineering at Check Point at BlackHat USA, to chat about the evolving landscape of cloud security in 2024. With cloud adoption accelerating and automation reshaping how we manage security, Brian spoke to us about the challenges that organizations face today—from misconfigurations and alert fatigue to the role of AI in application security.
We tackle the question: Is CSPM (Cloud Security Posture Management) still enough, or do we need to rethink our approach? Brian shares his thoughts on edge security, why misconfigurations are more dangerous than ever, and how automation can quickly turn small risks into significant threats.
Guest Socials:Brian's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(03:28) State of Cloud Market
(04:44) Is CSPM not enough?
(06:35) Edge Security in Cloud Context
(08:31) Where is edge security going?
(10:11) Where to start with Cloud Security Tooling?
(11:08) Transitioning from Network Security to Cloud Security
(13:11) How is AI Changing Edge Security?
(14:45) How is WAF and DDos Protection evolving?
(18:16) Should people be doing network pentest?
(19:57) North Star for WAF in a cybersecurity program
(20:55) The evolution to platformization
(23:13) Highlight from BlackHat USA 2024
How CI/CD Tools can expose your Code to Security Risks? In this episode, we’re joined by Mike Ruth, Senior Staff Security Engineer at Rippling and returning guest, live from BlackHat 2024. Mike dives deep into his research on CI/CD pipeline security, focusing on popular tools like GitHub Actions, Terraform, and Buildkite. He reveals the hidden vulnerabilities within these tools, such as the ability for engineers to bypass code reviews, modify configuration files, and run unauthorized commands in production environments.
Mike explains how the lack of granular access control in repositories and CI/CD configurations opens the door to serious security risks. He shares actionable insights on how to mitigate these issues by using best practices like GitHub Environments and Buildkite Clusters, along with potential solutions like static code analysis and granular push rule sets. This episode provides critical advice on how to better secure your CI/CD pipelines and protect your organization from insider threats and external attacks.
Guest Socials:Mike's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introductions
(01:56) A word from episode sponsor - ThreatLocker
(02:31) A bit about Mike Ruth
(03:08) SDLC in 2024
(08:05) Mitigating Challenges in SDLC
(09:10) What is Buildkite?
(10:11) Challenges observed with Buildkite
(12:30) How Terraform works in the SDLC
(15:41) Where to start with these CICD tools?
(18:55) Threat Detection in CICD Pipelines
(21:31) Building defensive libraries
(23:58) Scaling solutions across multiple repositories
(25:46) The Fun Questions
Resources mentioned during the call:
GitHub Actions
Terraform
Buildkite
Mike's BSidesSF Talk
In this episode of the Cloud Security Podcast, we bring together an incredible panel of experts to explore the evolving landscape of cloud security in 2024. Hosted by Ashish Rajan, the discussion dives deep into the challenges and realities of today’s multi-cloud environments. With perspectives ranging from seasoned veterans to emerging voices this episode offers a broad spectrum of insights from cloud security practitioners who are living and breathing cloud security everyday. We are very grateful to our panelist who took part in 1st of its kind edition for the State of Cloud Security - Meg Ashby, Damien Burks, Chris Farris, Rich Mogull, Patrick Sanders, Ammar Alim and Abdie Mohamed.
The conversation covers essential topics such as the pitfalls of multi-cloud adoption, the persistent security issues that remain even as cloud technologies advance, and the importance of specializing in one cloud platform while maintaining surface-level knowledge of others. The panelists also share their thoughts on the future of cloud security, including the increasing relevance of Kubernetes and edge security.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:22) How much has Cloud Security Changed?
(07:05) Is the expectation to be MultiCloud?
(19:07) What’s top of mind in Cloud Security in 2024?
(27:17) The current Cloud Service Provider Landscape
(39:26) Where to start in Cloud Security ?
(52:10) The Fun Section
Resources discussed during the episode:
fwd:cloudsec conference
Cloud Security Bootcamp
DevSecBlueprint YouTube Channel - Damien Burks
Rich Mogull’s Cloud Security Lab of the Week
What were the main themes at BlackHat USA 2024? With respect to Cloud Security, maybe with a sprinkle of AI Security. Our team was on the ground at BlackHat and DefCon32 this year, we heard many talks and panels, spoke to many practitioner, leaders and CISOs and had the pleasure of recording some great interviews (coming soon!). This conversation is a distillation of everything we heard and the themes we saw.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:15) A word from our episode sponsor, ThreatLocker
(04:35) Resiliency in Cybersecurity
(07:00) Commentary on upcoming US elections
(09:42) Identity Centric Security
(15:55) Cloud Security is getting more Complex
(23:47) Growing importance of Data Security
(25:42) Use Cases for AI Security
(31:25) Shared Responsibility and Shared Fate
(33:21) Is CSPM Dead?
(37:32) The Conclusion
Resources from the episode:
BlackHat USA Keynote - Democracy's Biggest Year: The Fight for Secure Elections Around the World
Generative AI Misuse: A Taxonomy of Tacticsand Insights from Real-World Data
RSAC 2024 Innovation Sandbox Finalist
BlackHat USA 2024 Startup Spotlight
In this episode, we sit down with Santiago, a Senior Security Engineer at Canva, to talk about the complexities of building and managing an incident response team, especially in high-growth companies. Santiago shares his experience transitioning from penetration testing to incident response and highlights the unique challenges that come with protecting a rapidly expanding organization.
We explore the differences between incident response in high-growth versus established companies, the importance of having the right personnel, and the critical skills needed for effective incident response.
Guest Socials:Santiago's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:58) A word from our sponsor - SentinelOne
(02:48) A bit about Santiago
(03:18) What is Incident Response?
(04:06) How IR differs in different organisations?
(04:48) Red Team vs Incident Response Team
(06:17) Challenges for Incident Response in Cloud
(07:16) Incident Response in a High Growth Company
(07:56) Skillsets required for high growth
(09:14) Cloud vs On Prem Incident Response
(10:03) Building Incident Response in High Growth Company
(11:39) Responding to incidents that are not high risk
(14:41) Transition from pentesting to incident responder
(17:20) Endpoint vulnerability management at scale
(25:32) The Fun Section
Resources from the episode:
Endpoint Vulnerability Management at Scale
Leadership Insights on Cloud Security in 2024. Ashish sat down with return guest Srinath Kuruvadi, a seasoned cloud security leader with over two decades of experience in the field. Together, they explored the current state and future of cloud security, discussing the importance of detection & incident response teams, building and maintaining a robust cloud security program, understanding the importance of stakeholder management, and the role of data security in mitigating risks. Srinath shared his perspective on the evolution of cloud security, the critical need for a prevention-first mindset while tackling the challenges of managing security in a multi-cloud environment
Guest Socials:Srinath's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:42) A bit about Srinath
(01:55) How has the Cloud Security space changed?
(05:27) Are CloudSec and AppSec merging?
(06:29) Are stakeholders more engaged with Cloud Security?
(08:10) Where are the boundaries for Cloud Security?
(10:06) Finding the right talent in Cloud Security
(12:31) Building a Multi Cloud Security Team
(15:06) The role of platform teams
(16:45) Maturity level for Cloud Security
(19:18) Current patterns in Cloud Security
(22:03) What should CSPs be taking more about?
What are you doing differently today that you're stopping tomorrow's legacy? In this episode Ashish spoke to Adrian Asher, CISO and Cloud Architect at Checkout.com, to explore the journey from monolithic architecture to cloud-native solutions in a regulated fintech environment. Adrian shared his perspective on why there "aren't enough lambdas" and how embracing cloud-native technologies like AWS Lambda and Fargate can enhance security, scalability, and efficiency.
Guest Socials:Adrian's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:59) A bit about Adrian
(02:47) Cloud Naive vs Cloud Native
(03:54) Checkout’s Cloud Native Journey
(05:44) What is AWS Fargate?
(06:52) There are not enough Lambdas
(09:52) The evolution of the Security Function
(12:15) Culture change for being more cloud native
(15:23) Getting security teams ready for Gen AI
(18:16) Where to start with Cloud Native?
(19:14) Where you can connect with Adrian?
(19:39) The Fun Section
How to secure AWS cloud using AWS Lambda? We spoke to Lily Chau from Roku at BSidesSF about her experience and innovative approach to tackling security issues in AWS environments. From deploying IAM roles to creating impactful playbooks with AWS Lambda, Lily shared her take on automating remediation processes. We spoke about the challenges of managing cloud security with tools like CSPM and CNAPP, and how Lily and her team took a different approach that goes beyond traditional methods to achieve real-time remediation.
Guest Socials:Lily Twitter
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:56) A bit about Lily
(02:27) What is Auto Remediation?
(03:56) Example of Auto Remediation
(05:19) CSPMs and Auto Remediation
(06:58) Make Auto Remediation in Cloud work for you
(09:49) Where to get started with Auto Remediation?
(11:52) What defines a High Impact Playbook?
(12:58) Auto Remediation for Lateral Movement
(14:35) What is running in the background?
(16:41) What skillset is required?
(19:08) The Fun Section
Resources for the episode:
Lily's talk at BsidesSF
How can you protect your data with Confidential Compute and Containers? Ashish spoke to Zvonko Kaiser, Principal Systems Software Engineer, Confidential Containers and Kubernetes at Nvidia about confidential containers, confidential computing, and their importance in protecting sensitive data. They speak about the various threat models, use cases, and the role of GPUs in enhancing compute power for AI workloads
Guest Socials:Zvonko's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:45) A word from our sponsor SentinelOne
(02:18) A bit about Zvonko
(02:24) Encryption for Confidential Computing
(04:20) Confidential Computing vs Confidential Containers
(05:45) What sectors focus on Confidential Computing?
(07:09) Common Threats in Confidential Computing
(08:55) What is a Secure Enclave?
(10:05) Value of Attestation for Confidential Computing
(11:35) Lift and Shift Strategy for AI
(13:59) The role of GPU in confidential Computing
(15:37) Shared Responsibility with Confidential Computing
(17:10) Confidential Computing project you can get involved in
(18:16) The fun section
How to implement infrastructure as code? Ashish spoke to Armon Dadgar. Co-Founder and CTO at HashiCorp at Hashidays London. Armon speaks about his journey from co-creating Terraform, the first open-source language in the IaC space, to addressing the complex challenges enterprises face in cloud environments today. They speak about why having a platform team from the beginning is crucial for large enterprises, the evolution of IaC, the importance of standardization in managing cloud applications, and how automation plays a key role in maintaining security.
Guest Socials:Armon's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
00:00 Introduction
01:54 A bit about Armon
02:32 How has infrastructure as code evolved?
03:43 The role of Terraform
04:38 Infrastructure and Security Lifecycle Management
06:51 Best Practice for Infrastructure Lifecycle Management
09:11 Best Practice for Security Lifecycle Management
09:38 What is a Platform Team?
11:02 When should people start thinking about a platform team?
13:02 What is Zero Trust?
14:52 Challenges with IaC
17:35 How GenAI is impacting IaC?
20:04 Starting an open source project?
24:53 The Fun Section
What is the future of AI Security and Data Protection? At AWS re:Inforce in Philadelphia this year, Ashish spoke to Dan Benjamin, Head of Data, Identity and AI Security at Prisma Cloud about the new category of AI-SPM (Artificial Intelligence Security Posture Management) and why does it fit within all the other toolings organisations have. They spoke about the importance of building an AI and data inventory, understanding AI access, and the critical role of DSPM (Data Security Posture Management) in creating effective AI security controls.
Guest Socials:Dan's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
00:00 Introduction
02:09 A bit about Dan
02:29 What is AISPM?
03:16 How should CISOs tackle AI Security?
06:16 Right Controls around AI Services
07:32 AISPM vs CSPM
09:52 The role of DSPM
10:25 Tackling data security in world of AI
13:28 Maturity Curve for CISOs to consider
16:36 Security Teams for AI Security
19:51 The Fun Section
Can Threat Detection be enhanced with AI? Ashish sat down with Dave Johnson, Senior Threat Intelligence Advisor at Feedly, at BSides SF 2024, where Dave also presented a talk.
Dave shares his journey in cyber threat intelligence, including his 15-year career with the FBI and his transition to the private sector. The conversation focuses on the innovative use of large language models (LLMs) to create Sigma rules for threat detection and the challenges faced along the way. Dave spoke about his four approaches to creating Sigma rules with AI, ultimately highlighting the benefits of prompt chaining and Retrieval Augmented Generation (RAG) systems.
Guest Socials:Dave's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:44) A word for our episode sponsor, Panoptica
(02:39) A bit about Dave Johnson
(03:33) What are Sigma Rules?
(04:36) Where to get started with Sigma Rules?
(05:27) Skills required to work with Sigma Rules
(06:32) The four approaches Dave took to Sigma Rules
(11:29) Are Sigma Rules complimentary to existing log systems?
(12:18) Challenges Dave had during his research
(14:09) Validating Sigma Rules
(16:01) Working on Sigma Rule Projects
(18:54) The Fun Section
Resources spoken about during the episode:
Dave's Website
SigmaHQ GitHub
How can AI impact Cloud Security Operations? Ashish sat down with Ely Kahn, VP of Cloud Security and AI at SentinelOne to talk about the evolving landscape of cloud security and the future of Security Operations Centers (SOC). Ely spoke about the shift from centralized to decentralized SOC operations, the increasing complexity in cloud security and its benefits.
Guest Socials:Ely's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:10) A bit about Ely
(02:47) Has Cloud Security become simpler or more complex?
(05:09) How has the threat landscape for cloud evolved?
(08:00) Who is managing all the alerts?
(09:53) What will happen to SOAR?
(11:03) How AI will impact Cloud Security in 2024?
(18:36) Is there a skillset change coming?
(20:06) The Fun Section
Is having a CSPM enough for Cloud Security? At RSA Conference 2024, Ashish sat down with returning guest Jimmy Mesta, Co-Founder and CTO of RAD Security, to talk about the complexities of Kubernetes security and why sometimes traditional Cloud Security Posture Management (CSPM) falls short in a Kubernetes-centric world.
We speak about the significance of behavioural baselining, the limitations of signature-based detection, the role of tools like eBPF in enhancing real-time security measures and the importance of proactive security measures and the need for a paradigm shift from reactive alert-based systems to a more silent and efficient operational model.
Guest Socials:Jimmy's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(03:12) A bit about Jimmy Mesta
(03:48) What is Cloud Native Security?
(05:15) How is Cloud Native different to traditional approach?
(07:37) What is eBPF?
(09:12) Why should we care about eBPF?
(11:51) Separating the signal from the noise
(13:48) Challenges on moving to Cloud Native
(15:58) Proactive Security in 2024
(17:02) Whose monitoring Cloud Native alerts?
(23:10) Getting visibility into the complexities of Kubernetes
(24:24) Skillsets and Resources for Kubernetes Security
(27:54) The Fun Section
Resources spoke about the during the interview:
OWASP Kubernetes Top Ten
What are the practical steps for orienting yourself in a new cloud environment? Ashish sat down with Rich Mogull and Chris Farris to explore the intricacies of effective cloud security strategies. Drawing on their extensive experience, Rich and Chris speak about critical importance of moving beyond just addressing vulnerabilities and embracing a more comprehensive approach to cloud security.Rich and Chris share their professional experiences and practical advice for anyone who finds themselves "airdropped" into an organization's cloud environment. They also discuss the development of the Universal Threat Actor Model and how it can help prioritize security efforts in a chaotic landscape of constant alerts and threats.
Guest Socials: Rich's Linkedin + Chris's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:26) A bit about Chris Farris
(03:10) A bit about Rich Mogull
(03:45) First Cloud Service they worked on!
(06:27) Where to start in an AWS environment?
(10:50) Cloud Security Threat Landscape
(15:25) Navigating through the CSPM findings
(18:14) Using the Universal Cloud Threat Model
(23:16) How is Cloud Ransomware different?
(25:44) Surprising attacks or compromises in Cloud
(29:43) Where are the CSPM Alerts going?
(36:30) Cloud Security Landscape in 2024
(45:37) The need for Cloud Security training in 2024
(46:58) Good starting point to learn Cloud Security
(52:13) The Fun Section
Resources spoken about during the episode:
The Universal Cloud Threat Model
AWS Customer Security Incidents by Rami McCarthy
Breaches.cloud
CloudSLAW
What's the best way to navigate least privilege complexities in a multi cloud environment? And how is the role of identity management evolving? We spoke to Jeff Moncrief from Sonrai Security on why identity is the new network in the cloud-driven world. We speak about the challenges of implementing least privilege in cloud environments, the misconceptions surrounding identity roles, and the critical importance of segmenting access across public clouds just as rigorously as we did on-premises.
Guest Socials: Jeff's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:59) A bit about Jeff
(03:01) How is identity different in the Cloud?
(05:40) Misconceptions about least priviledge in the cloud
(08:50) Cloud Native solutions for Permission Attack Surface Management
(15:36) Common themes when addressing privilege in Cloud
(17:22) Starting point when dealing with identities
(20:03) Frameworks when working through least privilege
(23:21) Showing ROI on doing least privilege
How is eBPF impacting Kubernetes Network Security? In this episode, recorded LIVE at Kubecon EU Paris 2024, Liz Rice, Chief Open Source Officer at Isovalent took us through the technical nuances of eBPF and its role in enabling dynamic, efficient network policies that go beyond traditional security measures. She also discusses Tetragon, the new subproject under Cilium, designed to enhance runtime security with deeper forensic capabilities. A great conversation for anyone involved in Kubernetes workload management, offering a peek into the future of cloud-native technologies and the evolving landscape of network security.
Guest Socials: Liz's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:46) A bit about Liz Rice
(02:11) What is eBPF and Cilium?
(03:24) SC Linux vs eBPF
(04:11) Business use case for Cilium
(06:37) Cilium vs Cloud Managed Services
(08:51) Why was there a need for Tetragon?
(11:20) Business use case for Tetragon
(11:32) Projects related to Multi-Cluster Deployment
(12:45) Where can you learn more about eBPF and Tetragon
(13:50) Hot Topics from Kubecon EU 2024
(15:07) The Fun Section
(15:35) How has Kubecon changed over the years?
Resources spoken about during the interview:
Cilium
Tetragon
eBPF
How can we leverage AI for more secure and efficient code and how will it impact devsecops? Ashish spoke to Michael Hanley, CSO and SVP of Engineering at GitHub, about the transformative impact of GitHub Copilot and AI on software development and security. Michael speaks about GitHub's internal use of Copilot for over three years and its role in enhancing developer satisfaction and productivity by removing mundane coding tasks. They speak about the broader implications for DevSecOps, the future of AI in coding, and strategic tips for integrating AI tools within organizations.
Guest Socials: Michael's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:19) A bit about Michael Hanley
(04:25) Making Security Easy for Developers
(07:17) What is GitHub Copilot?
(10:01) Whats the Future of AI for Security and Developers?
(13:36) Security Recommendations for using AI
(16:35) How is data stored in GitHub Copilot?
(17:40) How is AI impacting DevSecOps?
(21:50) The balance between Security and Innovation
(24:18) The evolution of education with AI
(27:30) Strategic Approach for CISOs implementing AI Pair Programmers
(30:08) Bridging the gap between Security and Engineering
(34:37) The Fun Questions
Resources spoken about during the episode:
https://resources.github.com/copilot-trust-center/
https://www.github.careers/careers-home
In this episode from KubeCon Paris 2024, we spoke to Loris Degioanni, Co-Founder and CTO of Sysdig about Open Source Project, Falco that celebrated its graduation this year at KubeconEU, Loris shared with us this proud moment and journey from writing the 1st lines of code to its critical role in protecting Kubernetes environments, and the future roadmap post-graduation. We spoke about the gap between traditional security measures and the dynamic needs of modern infrastructures.
Guest Socials: Loris's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
00:00 Introduction
01:13 A bit about Loris
01:44 What does graduation mean for Falco?
02:58 What is Falco?
04:59 eBPF and Falco
06:01 Why eBPF is secure?
07:11 Runtime Security in Kubernetes
10:32 ROI for leaders for Runtime Security Tools
12:50 Preventative Security vs Runtime Security
14:08 Runtime Security in Modern Environments
16:42 Whats the Future for Falco?
18:31 The Fun Questions
What is it like to build a successful business based on risk? In this episode Ashish spoke to Fredrick Lee, CISO at Reddit. FLee shared his deep insights into the essential role of risk in driving business success and innovation. With a career that spans across notable tech giants like Square (now Block), Twilio, and Gusto, Lee brings a wealth of experience in both hardware and software security landscapes. Without embracing risk, businesses risk stagnation in a world where competitors are always ready to innovate. From discussing the cost-effective strategies in cybersecurity to exploring the formation and goals of Reddit's S.P.A.C.E team (Security, Privacy, Automation, Compliance, and Engineering), this episode gets into the challenges and opportunities presented by the modern tech environment
Guest Socials: Fredrick Lee's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(04:42) A bit about Fredrick Lee
(07:42) How cloud changed cybersecurity?
(11:37) Threat Landscape in Software vs Hardware
(15:12) Threat Landscape in B2B vs B2C
(17:27) Navigating the First Steps as a New Company's CISO
(20:26) The role of compliance in Cybersecurity
(24:12) The role of privacy in Cybersecurity
(26:11) The role of AI in cybersecurity
(30:36) A bit about AI Cybersecurity Podcast
(31:09) What it means to be a CISO?
(34:34) Building CISO Roadmaps: Balancing Short-Term and Long-Term Goals
(36:49) Where to start with CISO Roadmap?
(39:02) What keeps Fredrick motivated about his CISO role?
(40:36) Whats next for current CISOs?
(42:50) The Fun Questions
Lets talk about the Evolution of Email Security. We have been speaking about Email Security for years but why has it not been solved? We spoke to Abhishek Agrawal, Co-founder of Material Security about the fact that despite of decades of advancements, email security remains a critical concern, with sophisticated attacks continually bypassing traditional controls. We explored the fascinating landscape of productivity suites like Microsoft 365 and Google Workspace, underscoring their importance beyond just communication tools. What are the critical aspects of threat management, posture management, and the necessity of a focused approach towards securing this often-overlooked segment of our digital infrastructure management.
Guest Socials: Abhishek's Linkedin Abhishek's Twitter
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions
(00:00) Introduction
(03:57) A bit about Abhishek
(04:49) What is a Productivity Suite?
(05:48) Why Email Security is still a focus in 2024?
(11:43) Where to start with Productivity Suite Security?
(15:03) The role of Cloud Native Tools in Productivity Suite Security
(19:38) Where can security leaders start with Productivity Suite Security
(24:39) Where can people learn more about Productivity Suite Security
(26:44) Fun Questions
How do you build a Robust Detection Framework? Ashish spoke to Andrew Tabona, SVP of Cyber Threat Management and Incident Response at a Fortune 500 company about challenging the conventional wisdom of applying on-premise incident response plans to cloud environments. They speak about the critical metrics of mean time to detect, respond, and recover, and why mastering the fundamentals is key to effective cloud security.
The conversation also covers practical strategies for building a detection framework, the importance of a balanced approach to log ingestion, and the nuanced differences in incident response between cloud and traditional on-premise environments.
Guest Socials: Andrew Tabona
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(03:20) A bit about Andrew Tabona
(04:26) What is Threat Detection and Response?
(06:14) Why incident response is different in Cloud?
(09:18) Benefits of doing Incident Response in Cloud?
(10:29) Is CSPM your incident response tool?
(12:33) Where to start with Detection in Cloud?
(16:35) Getting buy in from other teams for threat detection
(20:15) Should you build or buy a cybersecurity solution?
(22:34) Responding to incidents in a Cloud Context
(26:01) Containing incidents in a Cloud Context
(28:34) What kind of access do IR teams need?
(30:36) Balancing the signal to noise ratio
(32:10) Where to start with Threat Detection and Response
(34:37) Challenges an organisation might face
(35:58) Threat Detection and Response in MultiCloud
(37:52) Showing ROI of Cybersecurity to the business
(38:57) Where to learn about IR and Threat Detection?
(41:09) Fun Section
(44:14) Where you can connect with Andrew
What is GitHub Copilot? Its a AI-powered coding assistant that's redefining how developers write code. We spoke to Joseph Katsioloudes, a security specialist from the GitHub Security Lab. We spoke about how GitHub Copilot has been designed to serve not just developers but security professionals and others involved with code, enhancing productivity, satisfaction, and security across the board.
Guest Socials: Joseph Katsioloudes
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) A bit about Joseph
(01:07) What is GitHub Copilot?
(02:42) Use case for GitHubCopilot from a security perspective
(04:16) Cloud Development Kits (CDKs) for GitHub Copilot
(05:48) Business Motivation for GitHub Copilot adoption
(07:41) Should we trust AI generated code ?
(08:31) Using GitHub Copilot
(12:00) Data Privacy with Github Copilot
(13:28) GitHub Copilot for Regulated Industries
(14:51) What is GitHub Copilot X?
(16:02) What is GitHub Workspace?
(18:20) The Fun Section
How is your Cloud Incident Preparedness? Is your CSPM enough? Ashish spoke to Ariel Parnes, Co-Founder and COO at Mitiga about the concept of "Assume Breach" and its importance in developing a proactive cloud security framework. If you are looking to understand the nuances of of cloud incident response and being prepared for them, the effectiveness of current tools, and the future of cloud security operations strategy, then this episode is for you.
Guest Socials: Ariel Parnes
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:46) A bit about Ariel Parnes
(04:02) Cybersecurity in the world of Cloud
(06:07) What is Cloud Incident Preparedness?
(08:40) Reality of Cloud Incident Preparedness
(11:16) Does a CSPM help with Incident Preparedness?
(13:54) Should logs be sent to SIEM?
(15:59) Whats a good starting point for Incident Preparedness?
(18:31) Gaining deep visibility in your cloud environment
(19:50) Do you need a Security Data Lake?
(25:56) Demonstrating ROI for Security Operations
(28:28) Importance of Human Factor in Security Operations
(30:51) Low Hanging fruits to strengthen cloud operations
(32:31) The Fun Questions
Do you need an essential guide for Threat Modeling your Cloud Environment, then this episode is definitely for you. Ashish sat down with Tyson Garrett from TrustOnCloud. We explore why and how organizations should approach threat modeling in cloud to enhance their security posture. Tyson and Ashish go through the practical steps required for effective threat modeling, including identifying and prioritizing threats, and the continuous adaptation required to address the dynamic nature of cloud services.
Guest Socials: Tyson Garrett
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:50) A bit about Tyson Garrett
(04:27) What is Threat Modeling in Cloud?
(06:29) Threat Modeling the right way in the Cloud
(08:23) Threat Modeling in Cloud vs On Prem
(11:05) Examples of Threat Modeling
(13:41) Threat Modeling AI Services from Cloud Providers
(21:58) Including Threat Modeling in Security Programs
(25:09) Threat Modeling Cloud at Scale
(28:08) Different Approaches for Threat Modeling
(30:21) Challenges with Threat Modeling in Cloud
(33:42) Best Practices for Threat Modeling in Cloud
(39:59) Showing ROI on Threat Modeling
(42:57) Maturity Levels of Threat Modeling
(45:21) Starting point for learning about Threat Models
(46:12) The Fun Questions
(48:41) Where can you connect with Tyson
Resources spoken about during the episode
TrustOnCloud has kindly offered a Free ThreatModel of your choice to our listeners - you can register here to pick yours
What is the role of AI in Legal Research and Data Security? We spoke to Matt McKeever, CISO and Head of Cloud Engineering at LexisNexis, a company that uses GenAI and Custom LLM models to help its customers with legal research, guidance and drafting. Matt spoke to us about intersection of cloud engineering, cybersecurity and the revolutionary impact of Generative AI (GenAI) in the legal sector. He shared how LexisNexis leverages GenAI to enhance legal research, draft legal documents and summarize cases efficiently. We learn about the importance of data security in AI applications, especially in the legal industry and the role of custom Large Language Models (LLMs) in securing and processing legal data.
Guest Socials: Matt McKeever
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCampQuestions asked:(00:00) Introduction (00:26) LexisNexis use case for GenAI(02:37) Amazon's Generative AI services(03:24) Cybersecurity Threats when using GenAI(05:14) Where to get started with Security in GenAI?(06:53) Balancing Security and Innovation(08:20) Business reason for GenAI(09:13) Lessons from working with GenAI(11:14) Having Custom Large Language Model(13:42) Impact of AI on Cloud Security Roles (14:50) Get Started with Custom Large Language Model(15:48) Fun Questions (17:49) Where to connect with Matt McKeever?
Are you familiar with Sidecars in Kubernetes? We spoke to Magno Logan about the complex world of Kubernetes security and the silent but deadly vulnerabilities associated with sidecar containers. Magno shares his extensive research and insights on how attackers can exploit these vulnerabilities to stay hidden within a Kubernetes environment, posing significant threats beyond the commonly discussed crypto mining attacks. Magno spoke about common attack paths targeting Kubernetes clusters, from exploiting application vulnerabilities to leveraging exposed Kubernetes services and compromised valid accounts.
Guest Socials: Magno Logan
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:26) A bit about Magno Logan
(01:49) Kubernetes Common Threats Explained
(02:23) Kubernetes Cluster Attack Entry Points
(04:28) How attackers maintain persistent access in Kubernetes?
(05:30) Container Escape Explained
(07:03) Maintaining Persistence in Kubernetes Clusters
(08:18) What are Sidecars?
(10:43) How to secure your sidecars?
(12:33) Where can people learn more about this
(13:57) The Fun Section
Resources spoken about on the podcast
Mitre Att&ck Containers Matrix
Microsoft Threat Matrix
Navigating modern application security in a world of Cloud, DevSecOps and now AI is getting rather complex. We spoke to Idan Plotnik, who has 24 years of cybersecurity experience under his belt and is the Co-Founder of Apiiro about world of Application Security Posture Management (ASPM) and their relevance in both large and small organizations. Idan speaks about the challenges faced in managing vast quantities of repositories and tackles common misconceptions about ASPM, confirming that it's not intended to replace existing security pipelines.
Guest Socials: Idan Plotnik
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:(00:00) Introduction (04:58) A bit about Idan Plotnik(05:56) Application Security tools explained (08:09) Why Application Security Orchestration Correlation (ASOC) didn't work?(09:14) Difference between Cloud Security and Application Security Tools(14:51) Why is there a growing need for Application Security Tools today?(19:07) Do Small to Medium size businesses need Application Security Tools?(21:46) Managing Cybersecurity Tools(26:08) API Security for Applications (30:29) Dealing with Regulatory Requirements in Cybersecurity(34:16) Evolving Goals in Application Security(35:49) Deciphering MTTR in Cybersecurity(37:54) The Fun Questions(39:37) Where you can connect with Idan?
We caught up with Troy Hunt and Scott Helme at NDC Security Oslo 2024 to talk about best practices when it come to decoding TLS, password security and data breaches in cloud and AI.
Troy Hunt, known for his work with haveibeenpwned.com, spoke to us about the complexities of cloud deployment and paradox of data input versus privacy risk in Large Language Models (LLMs), Cloud. Scott Helme, a security researcher and founder of securityheaders.com, spoke about the importance of early security training in the development lifecycle for applications built in 2024. We dissected the critical yet often overlooked aspects of cybersecurity in cloud and ai.
Guest Socials: Troy Hunt + Scott Helme
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:37) Evolving Landscape of Password Management
(04:17) Analyzing Data Breach Trends:
(05:48) Latest Security Protocols with TLS and Encryption
(08:24) Debating Encryption Key Management
(10:59) AI's Role in Data Breaches:
(13:59) Best Practices for Enterprise Password Management
(16:01) Best Practices for Password Management in Small to Medium Sized Businesses
(18:04) Top 5 security best practices
(19:58) Understanding Security Headers
(27:14) The Fun Section
What is a good multicloud strategy in 2024? We spoke to Vivek Menon, CISO for Digital Turbine about the maturity and security capabilities of major cloud service providers, AWS and GCP.
Vivek spoke about the journey from on-premise to multi-cloud landscapes, the strategic approaches to cloud security in 2024, and the unique challenges that teams face across different cloud platforms. Vivek shared his insights into IAM, misconfigurations, and the value of dedicated cloud-specific teams provide a roadmap for organizations aiming to enhance their cloud security posture.
Guest Socials: Vivek's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(01:58) A bit about Vivek Menon
(02:53) Transitioning from On-Premise to Multi-Cloud
(05:35) What is mobile ad tech?
(06:44) Why AWS and GCP?
(08:09) Challenges in Multi-Cloud Environments - The people piece
(09:37) Challenges in Multi-Cloud Environments - The process piece
(10:42) Managing identities in a MultiCloud Environment
(12:52) Managing Misconfigurations in a MultiCloud Environment
(13:58) Multi-Cloud Security- Build In-House or Buy Tools
(17:44) Starting Point for MultiCloud Policy
(18:54) AWS vs. Google Cloud: Comparing Cloud Security Maturity
(20:28) What makes security in Google Cloud stand out
(21:18) CISO Guide: Initiating a Cloud Security Strategy in 2024
(25:01) The Fun Section
(27:03) Where can you connect with Vivek
Dive into the world of AI and Kubernetes with Shopify's Shane Lawrence in this episode of the Cloud Security Podcast. Shane, shares his experience in the security team at Shopify and working on the intersection of AI, Large Language Models (LLMs), and Kubernetes security. Shopify is looking to pioneer the use of AI to streamline developer operations, enhance productivity, and bolster security measures in multi-tenant Kubernetes environments.
This episode will be valuable for you if you work in Kubernetes, Security and looking for how AI can build efficiency in your team.
Guest Socials: Shane's Linkedin (Shane's Linkedin)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction to AI and Kubernetes
(01:32) Shane Lawrence and Shopify's AI Journey
(02:21) AI and Developer Efficiency in Kubernetes
(04:39) AI-Driven Automation for Security
(06:34) Challenges of AI in Kubernetes Environment
(11:22) Case Studies for AI in Kubernetes
(13:43) The Future of Kubernetes and AI
(15:59) Learning and Experimenting with AI in Kubernetes
(17:49) Closing Thoughts and Fun Q&A
How can you build a robust cloud security program in AWS, particularly as a startup and small to medium-sized businesses navigating AWS in 2024? We spoke to Chris Farris, who is the event chair for fwd:cloudsec, a known cloud security expert and one of the first AWS Heroes for security.
Chris shared his insights on how to build a security strategy that is both practical and effective in today's dynamic cloud environment. From discussing the importance of AWS organizations and Identity Centre to breaking down the complexities of cloud security posture management. You will hear actionable advice and best practices.
Guest Socials: Chris's Linkedin (@chrisfarris)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions Asked:
(00:00) Introduction
(02:59) A bit about Chris Farris
(03:30) fwd:cloudsec Conference
(04:19) AWS Hero program for Cloud Security
(05:23) Building Effective Cloud Security Programs
(11:39) Top Recommendations for AWS Cloud Security
(13:34) What is AWS IAM Identity Center?
(18:02) How to Set Up AWS IAM Identity Center?
(20:13) Cloud Security in different industries
(29:31) The role of a Cloud Security Engineer
(34:30) Cloud Security Breaches
(38:02) Educational Resources in Cloud Security
(42:41) The Fun Section
Resources spoken about in this episode:fwd:cloudsecAWS IAM Identity CenterLeveraging AWS SSO (aka Identity Center) with Google Workspaces breaches.cloud
Is Offensive Security part of your 2024 Security Roadmap? We caught up with Sam Kirkman, Director at NetSPI EMEA at BlackHat Europe 2023 about what an Offensive Security Roadmap going into 2024 should look like. Offensive security is much more than pentesting. We spoke about how to build a capable team, different maturity stages of building such a program and resources you can lean on while you are on this journey across different industries.
Guest Socials: Sam's Linkedin (@sam-kirkman-cybersecurity)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:53)A bit about Sam Kirkman
(03:53) What is offensive security?
(04:52) The attack landscape
(07:34) Offensive Security Roadmap
(09:43) Components of Offensive Security Roadmap
(11:04) Whats a good starting point?
(12:55) Skillsets required in the team
(16:57) Different stages of maturity
(19:09) Where can people learn more about this?
(22:03) Where you can connect with Sam
You can learn more about NetSPI and offensive security here
Cloud Security environments looks very complex in 2023, and it will continue to evolve in 2024 now with AI. At AWS re:Invent 2023 this year, we sat down with Alex Jauch, Senior Director of Product Management at Outshift to talk about the complexities in Cloud Security, the role of GenAI and what can be items to consider for your 2024 Cloud Security Program.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions Asked:(00:00) Introduction (01:34) A bit about Alex(02:02) Current Cloud Security Landscape(04:43) The cloud security acronyms(08:44) Dealing with complex infrastructure (12:31) Impact of GenAI on Security (15:26) Do you have GenAi in Production?(16:55) We are all one team! (19:04) 2024 Security Program(20:39) Whats not being spoken about?(22:11) The fun section(26:00) Where you can connect with Alex!
Kubernetes is shaping the future of cloud native technology with interest from security folks, businesses and developers - what does the future of Kubernetes Security look like? At Kubecon NA 2023, we spoke to Emily Fox who is the chair of CNCF's Technical Oversight Committee and Software Engineering Lead at RedHat about how Zero Trust plays out in the Kubernetes environment, challenges and solutions in securing the software supply chain within Kubernetes, the impact of AI workloads on Kubernetes and future of Edge Computing and Kubernetes.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Podcast- Youtube
- Cloud Security BootCamp
Questions Asked:(00:00) Introduction (02:23) A bit about Emily (02:51) What is Supply Chain Security?(03:51) What triggered this conversation?(05:10) Supply Chain Security in Managed Kubernetes(06:07) What is Zero Trust?(07:24) Implementing Zero Trust (09:29) The role of Security and Compliance(11:13) Compliance as code in Kubernetes(13:22) What is Edge?(17:41) The impact of AI on Security (20:39) Detection for AI and Kubernetes(22:29) How are the skillsets changing?(25:00) Security for Open Source Projects(28:01) The fun section
Kubernetes security explained : We spoke to Cailyn Edwards, CNCF Ambassador and Senior Security Engineer at Shopify. Interview was recorded at Kubecon NA 2023. We asked her about the complexities of Kubernetes Network Security in a multi-tenant environment. During the interview, she shared the nuances of Kubernetes network security in multi-tenant setups, tools and tactics for securing Kubernetes environments, insights from her journey at Shopify and tips for advancing the security maturity of Kubernetes networks.
Thank you to our episode sponsor Vanta - You can check them out at vanta.com/cloud
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction (02:25) A bit about Cailyn (03:08) How is Kubernetes Networking different?(04:20) Foundational pieces of Kubernetes Networking(06:21) Whats missing in Kubernetes Networking?(07:47) What is Multi Tenancy?(10:20) What are some of the common threat models?(13:16) How are people responding to threats? (14:41) Where to start learning about this?(16:26) Best practices for Kubernetes Networking(18:16) What becomes more important with maturity?(21:14) Resources to learn more about Kubernetes Security (22:30) The Fun Section
Resources shared during the episode:
Kubernetes Security Checklist - https://kubernetes.io/docs/concepts/security/security-checklist/
Pentesting your own cluster with Liz Rice - https://www.youtube.com/watch?v=fVqCAUJiIn0
Cloud Security Podcast just got back from AWS re:invent 2023, there was a lot of chat around, you guessed it - GenAI but along with that there were plenty of security updates and announcement. Shilpi and Ashish broke them all down for you and what it all actually means for all security practitioners.
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(04:49) GenAI at AWS re:Invent
(06:01) No new security service announced
(06:48) Updates from CEO and CTO Keynotes
(11:29) What is Amazon Inspector?
(12:10) Amazon Inspector Security Updates
(15:09) What is AWS Security Hub?
(15:52) AWS Security Hub Security Updates
(18:52) What is Amazon GuardDuty?
(20:10) Amazon GuardDuty Security Updates
(22:49) What is Amazon Detective?
(23:45) Amazon Detective Security Updates
(26:22) What is IAM Access Analyser?
(28:06) IAM Access Analyser Security Updates
(30:33) What is AWS Config?
(31:25) AWS Config Security Updates
(32:35) Other Security Updates
(33:46) 3 Layers of AI
(35:21) What is Amazon CodeWhisperer?
(36:36) Amazon Application Composer
(37:34) Guardrails for Bedrock
(38:13) Amazon Q
(41:17) Zero Trust
(41:45) Ransomware
(44:29) Security Talks
(45:54) Input filtering and validation for WAF
(50:31) Enterprise IAM and data perimeter
(53:00) Conclusion and find out more!
You can check out the Top announcements of AWS re:Invent 2023 + AWS re:Invent 2023 - Security Compliance & Identity
eBPF is recent graduate in the CNCF family and this means that the world of Cloud and Kubernetes, networking looks very different with more security capabilities. Cilium the project from Isovalent has been gaining traction for network security for kubernetes as blindsides have been called out in the managed kubernetes deployments. This episode was recorded at KubeCon NA with Thomas Graf from Isovalent to share what the blindsides are and why eBPF provides better network security capability for kubernetes deployments of any scale.
Guest Socials: Thomas's Linkedin (@ThomasGraf)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(03:42) A bit about Thomas
(04:11) Traditional Networking in Kubernetes
(06:52) What is Cilium?
(07:52) What is eBPF?
(08:46) What do people use Cilium for?
(11:31) Starting with network security in Kubernetes
(13:02) Complexities with Scale
(16:02) How do projects graduate?
(17:02) The eBPF documentary
(17:27) Opensource to Company
(18:52) Practitioner to Founder
(19:57) Building an open source project
(21:13) The Fun Questions!
You can check out the The eBPF Documentary here
Kubernetes security cannot just be Kubernetes but it is like security of a datacenter within another datacenter. In this episode with Tim Miller we spoke about CNAPP, how to approach kubernetes security.
Thank you to our episode sponsor Outshift by Cisco
Guest Socials: Tim's Linkedin (@timothyemiller)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(02:42) A bit about Tim Miller
(03:35) What is CNAPP?
(04:30) Traditional Kubernetes Security
(05:18) Where to put a CNAPP?
(06:20) CSPM vs CNAPP
(09:00) Attack Path Analysis
(11:05) Kubernetes Attack Path
(12:43) The team you need
(14:06) Resources to learn more
(16:24) Fun Question
SaaS Applications support large companies, small startups. We inevitably accumulate SAAS applications to manage our employees, payroll, communication with things like Workday, Slack, Salesforce and now even things like ChatGPT. But how do you find out what you have and if they are secure. We spoke about all things SSPM with Max Feldman who has done Product Security for years at companies like Slack, Salesforce and now AppOmni.
Thank you to our episode sponsor AppOmni
You can get a copy of their SaaS Security Posture Management Report 2023 here
Guest Socials: Max's Linkedin (@maxfeldman14)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(04:20) A bit about Max
(04:48) What is a SaaS application?
(05:45) What is SSPM?
(09:33) When to consider a SSPM?
(15:45) SaaS and the Cloud
(16:39) SaaS Attack Surface
(19:34) CASB vs SSPM
(24:00) Is ChatGPT a SaaS application?
(25:07) SSPM vs CSPM + CNAPP
(27:33) SSO and Onboarding
(29:21) Starting a SaaS Security Program
(36:48) Challenges with SaaS Security Program
(41:50) Where you can find Max!
Threat detection is often limited to popular cloud services, so whats happening to all the "not so popular or commonly known" cloud services in your environment? We are speaking to Suresh Vasudevan, CEO of Sysdig about challenges typically companies find with this space and what should be the approach for threat detection. If you feel you are looking at threats from all cloud services you might want to hear this episode to know you actually are.
Thank you to our episode sponsor Vanta and Sysdig
You can find out more about Sysdig here!
Find out more about Vanta here!
Guest Socials: Suresh's Linkedin (@suvasudevan)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Questions asked:
(00:00) Introduction
(03:41) A bit about Suresh
(05:14) How was threat detection done traditionally?
(07:33) How does threat detection translate to cloud?
(08:47) Uncommon services attack vector examples
(11:00) Uncommon services explained
(11:31) Problems with threat detection in cloud
(16:53) How to approach prioritisation?
(19:48) Bridging Cloud and Applications
Resources discussed during the episode!
LabRat
AmberSquid
Scarleteel
The 2023 Global Threat Research
Not Escaping Containers but escaping Clusters - Managed Kubernetes distributions such as Amazon EKS, Google Kubernetes Engine (GKE) and Azure Kubernetes Service (AKS) attack vectors can allow you to reach the underlying AWS Account etc. In conversation with Christophe Tafani-Dereeper & Nick Frichette, from Datadog on how this is possible in Amazon EKS and achieving potentially the same in GKE & AKS too.
Thank you to our episode sponsor Sagetap
Guest Socials: Nick's and Christophe's Linkedin (Nick Frichette + Christophe Tafani-Dereeper)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCampQuestions asked:(00:00) Introduction
(04:11) A bit about Christophe
(04:37) A bit about Nick
(05:03) What is managed Kubernetes?
(06:26) Security of managed Kubernetes
(09:02) Comparison between different managed Kubernetes
(10:41) Service accounts and managed Kubernetes
(14:22) What is container escape?
(18:20) IMDSv2 for EKS
(19:51) IMDSv2 in EKS vs AKES and GKE
(22:01) Benchmark compliance for Kubernetes architecture
(24:49) Low hanging fruits for container escape
(27:17) Shared responsibility for managed Kubernetes
(29:34) Fargate for Managed Kubernetes
(32:00) Different ways to run containers
(33:37) Escaping Managed Kubernetes cluster
(38:39) Find more about this attack path
(42:38) Escalation priviledge in EKS cluster
(44:19) Reducing the Kubernetes attack service
(44:58) MKAT for Kubernetes Security
(48:23) Preventing AWS AuthConfig
(50:11) Propagation Security
(54:55) The fun section
(57:47) Resources for latest Kubernetes updates
Resources spoken about during the episode
Nick Frichette's Blog - Hacking the Cloud
Christophe Tafani-Dereeper' Blog
Corey Quinn's - 17 ways to run containers on AWS
MKAT
cloudseclist newsletter
You know that feeling when you are unsure if you AWS secret that leaked is still available for use. There is no easy way to check this apart from looking in AWS to see if anyone used it. Turns out there could be another way.We have Ziad Ghalleb from GitGuardian to share free tool they released to help people look up if their secret was exposed on Github
Thank you to our episode sponsors GitGuardian and Sysdig
Guest Socials: Ziad's Linkedin (@ghallebziad)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCampQuestions asked:(00:00) Introduction
(04:53) A bit about Ziad
(05:47) What are secrets?
(07:37) Has my secret leaked
(08:46) How would users know?
(10:31) Whats the risk?
(15:43) What do orgs do for secrets?
(18:01) Keeping tab on your secrets
(20:33) Secrets management maturity
(22:43) Scaling Secrets management program
(25:20) Where to learn more ?
Resources spoken about during the episode
hasmysecretleaked
Secrets Detection Learning Center
Nick McLaren is a Senior Cloud Security Engineer at an Enterprise and he transitioned to this role from a Cloud Security Engineer at a Startup. On this episode he shared with us, how the roles differ between an enterprise and startup, what skills you require to become a senior cloud security engineer and what a day look like in a life of cloud security engineer.Thank you to our sponsors for the this episodeVanta - You can check them out at vanta.com/cloudSnyk - Check them out at Snyk.io/csp
Guest Socials: Nick's Linkedin (Nick McLaren)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(02:15) A message from our sponsor
(03:07) A bit about Nick
(04:30) Startup vs Enterprise
(09:12) Senior cloud security engineer
(11:34) Communicating with the business
(13:18) Agile Methodology
(17:03) A day in the life of cloud security engineer
(19:33) Knowing multi-cloud
(20:43) Learning Azure from AWS
(21:50) Dealing with Third parties
(24:36) you dont need to know everything
(25:51) Getting into Cloud Security
(27:55) Knowing coding and terraform
(29:37) The Fun Questions
BlackHat 2023 and Defcon 31 Roundup were the breeding ground for new and existing hackers to come together and share what to look out for in 2023 and 2024. The skills that stood out were- Identity- Cloud Infrastructure Security- CI/CD Security- Preventative Security- Data Security Do you agree?
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Video
(00:00) Introduction
(00:57) Identity
(03:54) Data Security
(06:33) Cloud Infrastructure Pentesting
(08:38) Preventative Cloud Security
(10:57) CI/CD Security
Michael Piacente has been helping companies find Security Executives (CISO) for a long time for some household name companies like Lyft, Instacart, Airbnb and more . In episode we speak about his current passion for Cloud Native CISOs what they are and what kind of skills should they work on to become CISO in the Cloud native world most organizations are moving ahead with in full force.
Thank you to Sagetap for sponsoring this episode, you can find out more about them on - https://www.sagetap.io/
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Michael's Linkedin (Michael Piacente)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(03:57) A bit about Michael Piacente
(07:20) Why the focus on Cloud Native CISOs?
(09:52) What is a Cloud Native CISO?
(12:47) Different type of leadership roles in Security
(18:30) How are CISOs compensated?
(21:27) How CISOs can protect themselves?
(25:31) Have the roles & responsibilities changed?
(27:33) Importance of personal branding
(34:48) Trajectory after becoming a CISO
Link to participate in Hitch Partner's Annual Survey
Understanding Software Supply Chain security threats for Terraform which has been the default for Infrastructure as Code is important. in this episode Mike Ruth is sharing his experience of working on securing Terraform Cloud/Terraform Enterprise - no open source was harmed in the making of this episode.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Mike's Linkedin (Mike Ruth)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(03:27) A bit about Mike Ruth
(04:01) What is Terraform?
(05:38) Terraform in the context of supply chain
(07:24) Flavors of Terraform
(09:07) Deploying Terraform
(12:25) Terraform Architecture
(14:48) Research findings that Mike and Oca made
(25:52) Securing Terraform Architecture
(28:13) Policy Enforcement
(29:13) What is a Module?
(30:15) Security best practices for Terraform Deployment
(31:53) Learning about Terraform security
(34:44) Maturity for Terraform
(37:45) The Fun Questions
Mike spoke about Terraform Cloud Security Model during the interview.
See you at the next episode!
DSPM or Data Security Posture Management with Yotam Segev from Cyera: Most security teams have known about data challenges in their organization and some of them are put in the too hard to solve right now bucket. Yotam came on the show to talk about who should own and manage data security programs and what can a data security roadmap look like for leaders who are working on the data problem today.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Yotam's Linkedin (Yotam Segev)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(04:32) Why is data security getting attention?
(05:46) How was data security done before?
(06:43) Cloud native way of managing data
(07:31) What triggers a data security project?
(08:35) At what stage should you start data security?
(10:06) Challenges with starting data security projects
(13:02) What does success look like?
(15:02) Does the CISO own data security?
(16:03) The right skill set for data security
See you at the next episode!
Is it code to cloud or cloud to code with Harshil Parikh from Tromzo: A lot of leaders today face the inevitable question of should i start with the code or the cloud first. Harshil Parikh from Tromzo was kind enough to share his CISO experience on the topic on what each of these are and what can CISOs priortise in their programs.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Harshil's Linkedin (Harshil Parikh)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(02:51) Harshil's path into cybersecurity
(04:30) What is code to cloud?
(05:19) What is cloud to code?
(06:29) How was cybersecurity done traditionally?
(08:28) What should CISOs prioritise?
(09:43) How different sectors are impacted?
(10:56) Where should CISOs start?
(12:30) Application vs Cloud vs Product Security
(14:44) Is application security becoming cloud security?
(16:43) What does maturity look like?
(20:18) The fun questions
See you at the next episode!
Josh Lemos former CISO of Block and the current CISO of GitLab comes from a pentester background and made his way to become a CISO. We were lucky enough to interview him during the hacker summer camp on his journey, his experience in AI, takeaway from BH CISO summit and types of CISOs & more.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Josh's Linkedin (Josh Lemos)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(01:47) A bit about Josh Lemos
(03:48) What does cloud security mean to Josh?
(04:53) What to look out for with AI/ML?
(07:03) CISO perspective on AI/ML
(08:13) What should a CISO roadmap look like in 2023?
(10:39) Takeaways from BlackHat CISO Summit
(12:24) CISO for B2B vs B2C
(13:43) Hardware vs Software Security
(14:41) Skills needed to become a CISO
(15:48) What is cloud pentesting?
(17:20) Fun Questions
See you at the next episode!
Karl Fosaaen, the author of Penetration Testing "Azure for Ethical Hacker" and the VP of Research at NetSPI, came as a guest to share why the penetration Test of a Web Application hosted on Azure Cloud in 2023 is quite different to just a simple/traditional web app pentesting and the skills you need to pentest Azure environments.
Cloud Penetration testing is misunderstood to be just config review in Microsoft Azure Cloud just like in AWS and Google Cloud. In this video, we have Karl Fosaaen was kind enough to answer the following questions and methods.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Karl's Linkedin (Karl Fosaaen)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(02:32) A bit about Karl Fosaaen
(03:26) How is pentesting in Azure different from AWS?
(04:35) Cloud pentesting is not just config review
(05:42) Cloud pentesting vs Network pentesting
(06:25) Cloud Pentest - Next evolution of Network Pentest?
(07:14) Boundaries of cloud pentesting
(09:07) Do you need prior approval for Azure Pentest?
(09:32) Working with Microsoft Security Research Centre
(10:35) Process of pentesting in Azure
(11:57) Low hanging fruits to start off with!
(13:37) How to persist and escalate?
(14:58) Managed Identities in Azure
(16:23) Impact of peripheral services to Azure
(18:33) Scale of deployments in Azure
(21:02) Getting access to permissions for Azure Entra
(22:36) Scaling your pentest tools
(23:34) TTPs or Matrix you can use
(25:30) Getting into Azure Pentesting
(26:56) Transitioning from network to azure pentesting
(28:37) Connect with Karl
Resources:
The NetSPI Blog to learn more about offensive cloud security
Mitre - Cloud Attack Matrix
ATRM
Karl's Book - Penetration Testing Azure for Ethical Hackers: Develop practical skills to perform pentesting and risk assessment of Microsoft Azure environments
See you at the next episode!
Can Honeytokens be used in your supply chain security? Turns out we can! We spoke to Mackenzie Jackson ( @advocatemack ) from @GitGuardian about the benefits of using Honeytokens, which organisations can benefit from them and whats involved in deploying them and next steps once they are triggered.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Mackenzie Jackson ( @advocatemack )
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction (02:01) A bit about Mackenzie Jackson (02:37) What are Honeytokens? (03:35) Traditional threat detection (05:29) Honeytoken in action (07:02) Deployments for Honeytokens (09:46) Role of Honeytoken in Supply Chain (11:02) Deploying and managing Honeytokens (13:12) Incident response with Honeytokens (15:01) What companies should use Honeytokens? (16:05) What if the key is deleted !
Resources:
You can find out more about Honeytokens & GitGuardian here!
See you at the next episode!
Penetration Test of a Web Application hosted on Google Cloud in 2023 is quite different to just a simple/traditional web app pentesting.
Cloud Penetration testing is misunderstood to be just config review in Google Cloud. In this video, we have Kat Traxler who is a cloud security researcher, SANS Course author and has worked in the Google Cloud space to even build open source tools that can be used to perform cloud security testing.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Kat Traxler ( Kat Traxler's Linkedin )
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(04:17) A bit about Kat Traxler
(05:56) Pentesting in GCP vs AWS
(08:07) Config review vs cloud pentesting
(09:24) Cloud pentest vs Traditional Pentest
(10:28) Starting to do GCP pentesting
(12:35) Common services used in GCP
(14:10) Low hanging fruits in GCP
(15:25) What are default service accounts?
(17:52) You may already have google cloud
(20:00) How to persist access in Google Cloud?
(21:56) Shared responsibility in GCP
(24:01) Common TTPs in GCP
(28:05) Is there SSRF in GCP?
(30:19) Open source tools for cloud pentest
(33:59) Fun questions
Resources that Kat shared during the episode
See you at the next episode!
Cloud Security Pentest is not just a Cloud configuration review ! Blackhat 2023 & Defcon 31 conversations included Cloud Security Podcast asking traditional and experienced pentesters about their opinion on cloud security pentesting and the divide was between it being a config review or a product pentest. For this episode we have Seth Art from Bishop Fox to clarify the myth.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Seth Art's Linkedin (Seth Art Linkedin)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Question
(00:00) Introduction
(05:17) A bit about Seth Art
(06:44) Network vs Infrastructure Security Pentest
(08:00) Internal vs External Network Security Pentest
(10:26) Assumed vs Objective Based Pentest
(12:51) Is network pentest dead?
(14:04) How to approach network and cloud pentests?
(20:12) Cloud pentest is more than config review
(24:04) Examples of cloud pentest findings
(30:07) Scaling pentests in cloud
(32:25) Traditional skillsets to cloud pentest
(36:58) A bit about cloudfoxable
(39:31) Cloud pentest and Zero Trust
(40:54) Staying ahead of CSP releases
(44:31) Third party shared responsibility
(47:35) 1 fun question
(48:36) Boundary for cloud pentest
(52:21) Last 2 fun questions
These are some of the resources that Seth shared during the episode along with the tools he has created
See you at the next episode!
Google cloud hacking or pentesting is very different to other popular cloud service providers like aws or azure. In this episode we had Shannon McHale (Mandiant now Google Cloud) to talk about how she approaches pentesting a google cloud environment and how you can too.
Episode YouTube: Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Shannon McHale's Linkedin (Shannon's Linkedin)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(03:38) A bit about Shannon McHale
(05:31) What is Red Teaming?
(06:42) Red Teaming in the Cloud
(07:50) Methodology behind Red Teaming
(09:32) Pentesting in Goole Cloud
(10:28) Low hanging fruits in Google Cloud
(14:36) GCP storage
(16:09) Red Team Assessment in Google Cloud
(17:08) The importance of Metadata
(18:17) Recommendations for Blue Teamers
(22:03) How to get started in Red Teaming?
(26:06) Tools or Research that stood out for Shannon
(27:42) GCP Resources that can be exposed
(29:15) Resources to learn about Cloud Red Teaming
(30:37) The Fun Questions
These are some of the resources Shannon found helpful to learn about Pentesting in Cloud along with her own GitHub link
See you at the next episode!
CISOs in organizations that are going through digital transformation have a responsibility of educating the board on how Cloud Security is measured and improved on to manage the risk posture of the organization. We had Phil Venables, CISO of Google Cloud share from his experience of serving as a CISO for so many years on how to best share cybersecurity and cloud security metrics with the c-suite and the board.
Episode YouTube Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Phil Venable's Linkedin (Phil's Linkedin)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(03:02) A bit about Phil Venables
(04:17) Are boards talking about Cloud Security?
(05:47) Security Metrics to show to the board
(07:48) Are Security Metrics seasonal?
(10:23) Aligning security metrics to business goals
(13:59) Educating the board about Cloud Security
(15:50) CISOs should be braver
(18:42) 3 Security Metrics to start with
(25:25) Setting the risk appetite as a organisation
(27:11) Essential attributes for a CISO
(29:14) What makes a successful security program?
(32:18) Skillsets required to become a CISO
(36:49) The fun questions
See you at the next episode!
Google Cloud Security Assessment from a pentester's lens. Anjali from NotSoSecure will be sharing her research into Google Cloud IAP & finding ways to assess the use of Google Cloud IAP in your environment and what are some of the low hanging fruits that you can remove today to reduce any potential risk from the service to your Google Cloud environment.
Episode YouTube Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Anjali S's Linkedin (Anjali S)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(04:31) A bit about Anjali Shukla
(05:23) What is GCP IAP?
(07:18) Why is IAP so important?
(09:55) IAP and Identity Federation
(11:34) SSH vs Jump Box
(13:57) GCP IAP vs AWS Cognito
(16:22) Misconfigurations in GCP IAP
(23:17) Potential security scenarios
(25:45) Cloud Security Assessment in GCP
(28:13) Doing your own cloud security assessment
(30:49) The Fun Questions
See you at the next episode!
AWS Landing zones are well known but not as much in the Google Cloud space. In this episode we have Jimmy Barber shares how controls can be automated in GCP to create landing zone to manage security across a large google environment.
Episode YouTube Video Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Jimmy Barber's Linkedin Jimmy Barber
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(03:10) A bit about Jimmy Barber
(05:42) Transitioning from on-prem to cloud
(07:26) How are things different in GCP?
(09:01) Building blocks of working with GCP
(14:15) What is a landing zone in GCP?
(17:23) Building landing zone in existing GCP environments
(20:04) Using Cloud Native services vs others
(22:59) Security gaps in GCP
(25:15) Non technical challenges moving to cloud and GCP
(28:45) Doing security in GCP
(31:18) Where to start learning about GCP
(32:37) The Fun Section
These are some of the resources Jimmy found helpful when learning GCP Security
See you at the next episode!
Cloud Security Podcast - Yes - AWS Cloud folks are starting to look after Google Cloud security now in a lot of organisations. Caleb Tennis from Sequoia Capital joins us to share his personal experience on how from being an AWS professional he started looking after Google Cloud Identity and how to secure their Google Cloud Environment.
Episode YouTube Video - https://youtu.be/k1FrVEe1tGc
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Caleb Tennis's Linkedin Caleb Tennis
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(04:51) A bit about Caleb Tennis
(07:27) Caleb's first impressions of GCP
(08:53) Google Cloud Blind Spots
(12:35) Where to start security GCP?
(15:23) Managing identities in GCP
(20:17) Temporary Credential in Google Cloud
(24:54) Managing identity with scale
(29:59) Is there enough Google Cloud Usage
(31:14) Google Cloud logging and monitoring
(35:48) What does Scale look like in Google Cloud?
(37:53) Hardest things to learn in GCP
(41:08) Learning GCP Security
(42:58) The Fun Section
See you at the next episode!
Cloud Security Podcast - Cybersecurity Threat hunting explained for Google Cloud. Day Johnson is a threat detection engineer and in this episode of Cloud security for Google Cloud security we spoke about how to start doing threat detection in Google Cloud, the common threats and attack vectors in GCP
Episode YouTube Video - https://youtu.be/FCVG7-lFu0Q
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Day Johnson's Linkedin (Day - Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(02:37) A word from our sponsor snyk.io/csp
(03:11) A bit about Day Johnson
(04:12) Common Threats in GCP
(06:04) Starting Threat Detection in GCP
(07:57) Transitioning to GCP from AWS
(10:53) Threat modelling by Service
(14:27) Where to start with threat detection in GCP
(18:17) Common Threat Vectors in GCP
(21:53) Automatic Threat Detection
(23:13) Services to be mindful of
(26:10) Compute Image Creation
(28:07) Get started in Detection Engineering
(32:45) Helpful resources for Threat Detection
(36:00) The fun questions
These are some of the resources Day found helpful for threat detection in GCP along with some resources he mentioned + his talk
See you at the next episode!
Cloud Security Podcast - AWS Network Security, IAM Security or even Organization security for what can happen in your AWS Environments can be achieved using Data perimeter. John Burgress (John - Linkedin) from Stripe spoke about this topic at @fwdcloudsec and shared additional insights on the thinking he had when building data perimeters are guardrails. There were lot more gems dropped so def check out the episode.
Episode YouTube Video - https://youtu.be/Hs9ZEaVG7Ww
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: John Burgress (John - Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(03:13) A word from our sponsors
(03:38) A bit about John Burgess
(04:26) Data perimeter in the Cloud
(05:10) Defining data perimeter in AWS
(06:50) Where to start building AWS data perimeter
(08:21) The defense in depth approach 09:09 Approach to enable developers
(10:40) Starting point for building data perimeter
(11:41) Limitations with Data Perimeter
(13:06) Implementing data perimeter for segregation
(15:52) Working with Terraform Modules
(16:34) Goals behind data perimeter controls
(18:31) Proactive detection for third party
(20:00) Data perimeter for other CSPs
(20:42) Challenges in establishing data perimeter
(23:06) Dealing with multiple organisations
(23:35) Learn more about data perimeter
(24:06) The fun section
These are some of the resources John found helpful for data perimeter:
See you at the next episode!
Cloud Security Podcast - NIST Incident response framework has 4 steps including one for Containment. AWS Incident Response being API enabled allows for automating a lot of incident response activity especially containment. In this episode with Damien Burks (Damien - Linkedin) spoke about his @fwdcloudsec talk where he shared how he automated Incident Response in AWS environments of Citi. There were lot more gems dropped so def check out the episode.
Episode YouTube Video - https://youtu.be/IrLuHMLQs_w
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Damien Burks (Damien - Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction (00:13) A word from our sponsors - Snyk.io/csp (01:16) A bit about Damien Burks (02:24) Incident Response in the cloud context (03:50) Is incident response different in the cloud? (05:22) Average time for an incident response (07:33) AWS services for incident response automation (08:55) AWS Eventbridge (11:56) The phases of incident response (13:42) Containment Phase: Starting point and challenges (17:54) Organisation with Multiple Accounts (20:09) How to structure the process (21:04) Containment for EC2 instance (23:54) Enjoying this cloud security topic so far?
(25:17) Containment for S3 Bucket (27:57) Where to start with incident response (30:18) Preparing for Incidents (32:08) Fun Questions
See you at the next episode!
Cloud Security Podcast - Automating a Security Baseline in Cloud with Olivia Siow (Olivia's Linkedin) and David Levitsky (David's Linkedin). In this episode Olivia and David shared their experience of how they were able to empower developers to always do the right thing through positive reinforcements like making default libraries as part of the AWS Account build to scale security across their organisation. There were lot more gems dropped so def check out the episode.
Episode YouTube Video - https://www.youtube.com/watch?v=8kpiDcowl2A
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Olivia Siow (Olivia's Linkedin) and David Levitsky (David's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(04:16) A bit about Olivia Siow
(04:31) A bit about David Levitsky
(04:54) Cloud Security Baseline
(06:38) Do all organisations need a cloud security baseline?
(07:16) Does cloud security baseline help with scaling?
(07:34) Success Metrics for establishing cloud security baseline
(10:41) The cultural side of building a baseline
(11:40) Anatomy of AWS Cloud Account at Scale
(12:58) Building Blocks of Cloud Security Baseline
(16:54) Non Technical Challenges
(19:24) Organisation Challenges
(21:41) Would larger organisations have multiple baselines?
(23:34) Baseline for Multicloud or hybridcloud
(26:10) Use case with terraform cloud and route 53
(30:26) What telemetry is important
(32:36) Segregating Logs in a cloud context
(33:58) Can be done with any cloud and tool of choice
(34:43) Baseline vs CNAPP + CSPM
(37:56) Team skill requirement
(39:16) The fun section
(45:13) Where can you connect with Olivia and David to continue the conversation
See you at the next episode!
Cloud Security Podcast - AWS ReInforce 2023 or AWS Re:inforce 2023 highlights in a recap from the 2 Day affair for all things AWS Cloud Security! We were lucky enough to be there. This is a recap of the major announcements and highlights from major themes around the event.
Episode YouTube Video - https://www.youtube.com/watch?v=UhVBvnmmfnQ
Cloud Security Podcast Website - www.cloudsecuritypodcast.tv
FREE CLOUD Security BOOTCAMP - www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Podcast Twitter - @CloudSecPod @CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security News
Cloud Security BootCamp
Timeline
(00:00) Introduction
(02:20) What is AWS re:inforce?
(04:33) Neha Rungta explains Verified Access
(05:38) Neha Rungta explains Verified Permissions
(07:53) What verified permissions means for you!
(09:35) Amazon EC2 Connect Endpoint
(11:08) Amazon GuardDuty Updates
(12:42) Amazon Inspector Code Scan for Lambda function
(14:26) Amazon Inspector SBOM Export
(17:35) Amazon Code Whisperer
(18:00) Amazon Code Guru
(20:15) Finding groups in Amazon Detective
(22:25) Dual Layer Encryption for AWS S3
(23:18) AWS Global Partner Security Initiative
(26:12) Key Themes from AWS re:inforce
(26:45) Shared Responsibility Model
(27:56) Cloud Security Newsletter
(30:04) Generative AI
(31:29) Amazon Bedrock
(34:04) Shift from ransomware to wiperware
(35:29) Nancy Wang explains AWS Backup Vault Lock
(37:18) Nancy explains double encryption with S3 Bucket
(38:41) Nancy explains how vault helps with data loss.
(40:20) AWS Backup Vault Lock
(41:55) Zero Trust and Identity
(45:03) DevSecOps
(46:47) How GenAI will impact cloud security roles?
(49:32) Amazon Security Lake
(52:26) Quantum Computing
See you at the next episode!
Cloud Security Podcast - Tanya Janca and Caroline Wong were on a panel with @AshishRajan at @RSAConference 2023. The Topic for the panel discussed what's the space of application security with cloud security or is it more they need to be separate camps.
Episode YouTube Video - https://www.youtube.com/watch?v=WSIykXAy6Z4
Cloud Security Podcast Website - www.cloudsecuritypodcast.tv
FREE CLOUD Security BOOTCAMP - www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Tanya Janca (@shehackspurple)
Guest Twitter: Caroline Wong (@CarolineWMWong)
Podcast Twitter - @CloudSecPod @CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security News
Cloud Security BootCamp
See you at the next episode!
AI Security Podcast - ChatGPT and other Generative AI use Large Language Model (LLM) but can these AI systems be attacked? ☠ 🤔 . In this 3 part AI Security series from Cloud Security Podcast Original episode, we're going to talk about the importance of AI security and how to protect your Language Model aka llm program from attack. How can LLMs be attacked by malicious threat actors - beyond the phishing email that everyone has been talking about.Who is this episode for?If you work with LLMs used by AI system or working on securing of internal LLM being built; then you would this video helpful in understanding the types of attacks that be used against a LLM.
Useful Resources are listed here:- NIST AI Risk Management Framework - https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf - Attack Mitre for LLM - Atlas https://atlas.mitre.org/ - OWASP Top 10 LLM - https://owasp.org/www-project-top-10-for-large-language-model-applications/descriptions/- The AI Attack Surface Map v1.0 - Daniel Miessler, Unsupervised Learning - https://danielmiessler.com/blog/the-ai-attack-surface-map-v1-0/
YouTube Link to the Episode - https://youtu.be/Yl9qqt9C5lE
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Podcast Twitter - @CloudSecPod @CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security News
Cloud Security BootCamp
Spotify TimeStamp for Episode
(00:00) Intro(00:49) LLM Explained(01:40) LLM Application Input Prompts(03:01) Data used by LLM Applications(04:58) LLM Applications Themselves(08:15) Infrastructure used to host LLM Application(11:11) What about Responsive AI(12:05) Ways to protect LLM Applications against these attacks(13:00) Useful Resources for AI Security(13:30) How do you defend against AI Attacks?(13:38) Outro - Thank you for watching & Subscribing
See you at the next episode!
Cloud Security Podcast - What is DevSecOps in 2023 especially in a world of Cloud and AI which is top of mind for both application security, developers, cybersecurity professionals. In this episode we will share how the updated definition of DevSecOps in 2023 has been redefined with Cloud and AI, also how does one measure success for DevSecOps.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Podcast Twitter - @CloudSecPod @CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
Cloud Security News
Cloud Security BootCamp
Spotify TimeStamp for Episode
(00:00) Intro
(02:01) Did Cloud enable DevSecOps
(03:43) Speed of Security in DevSecOps built on Cloud
(05:05) What is DevSecOps explained for 2023
(05:51) DevSecOps RoadMap
(08:25) DevSecOps Program Components in 2023
(10:55) Chatgpt Joke on Developers and DevSecOps
(11:43) How do you measure DevSecOps success?
(12:21) Generative AI impact on DevSecOps
(14:02) Thank you for watching & Subscribing
See you at the next episode!
Cloud Security Podcast - we are continuing with our "Kubernetes Security & KubeCon EU 2023" and for the final episode in this series Kubernetes Security Panel from KubeCon EU 2023. Kubernetes Security has evolved since it's inception with many defaults being more secure and some still insecure or has it not evolved at all. Andrew Martin (Control Plane), Matt Jarvis (Snyk), Kerim Satirli (Hashicorp) were on the Kubernetes Security Panel organized by Cloud Security Podcast.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Andrew Martin (Control Plane), Matt Jarvis (Snyk), Kerim Satirli (Hashicorp)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(04:28) A bit about Kerim, Andy and Matt
(05:13) What is Kubernetes?
(06:49) How do you describe Cloud Native Security?
(10:21) How Kubecon and Kubernetes has changed over the years?
(15:56) The growing presence of security in Kubecon
(22:10) Cloud Security and Cloud Native Security
(23:00) Maintenance of Kubernetes
(24:17) Shared Responsibility Model
(27:37) Single Cluster vs Multi Cluster
(34:34) Failure of Workload Identity
(36:11) Recommendations for learning
(42:06) Disaster Recovery for Kubernetes
(47:51) ChatGPT - Problem, Solution or Fad?
See you at the next episode!
Cloud Security Podcast - we are continuing with our "Kubernetes Security & KubeCon EU 2023" and for the fiveth episode in this series Eve Ben Ezra from The New York Times. GitOps, OPA Conftest, ArgoCD are some of the components to add security to a Cloud Native Security Pipeline! - Eve Ben Ezra from The New York Times shared how we can use these tools to create a Dev Friendly Security Pipeline.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Eve Ben Ezra (Eve Ben Ezra's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(03:10) A bit about Eve
(04:05) Eve's 2nd Kubecon
(04:43) About Eve's talk at Kubecon
(05:29) What is GitOps?
(06:28) What is Argo CD?
(07:19) What is OPA?
(07:34) Why NYTimes has a development platform?
(09:14) Challenges with implementing a shared infrastructure
(11:17) Feedback is one of the challenges
(12:19) Using OPA gatekeeper
(13:30) When should developers get feedback in GitOps operational framework?
(14:52) What does local feedback to developers look like?
(15:54) What is Conftest?
(16:24) How do people get started with OPA?
(18:32) Making security more accessible for developers
(23:02) Managed or self hosted Kubernetes deployment
(24:09) How to get started with this?
(25:08) Starting with OPA vs Starting with CICD
(25:35) Where can you start learning about Kubernetes?
(28:10) The difference between CI and CD
See you at the next episode!
Cloud Security Podcast - we are continuing with our "Kubernetes Security & KubeCon EU 2023" and for the fourth episode in this series Mackenzie Jackson from GitGuardian. Mackenzie Jackson from GitGuardian was part of a report that found 10 Million secrets stored across the entire Github space on the internet. In this interview we go into how secrets have evolved from just being username/password to API Tokens, AWS Access Keys and whole lot more.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Shane Lawrence (Shane's Linkedin) and Daniele Santos (Dani's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction (03:42) A bit about Mackenzie Jackson(04:16) What are secrets?(05:28) How are we dealing with secrets?(07:35) Mackezie talks about GitGuardian's Secret Sprawl Report (11:43) Managing history in Github (12:37) Mackenzie talks about ggcanary (14:09) Common types of secrets found in scans(15:42) Responsibility of Github and CSP providers (17:12) Are people ready to respond to honey token alarms?(20:33) Breaches causes by leaked secrets (23:34) Fun facts found in Secrets Sprawl Report (24:25) Secret sprawl is going to happen (25:09) Where do people start?(26:06) Implementing Git Hook as a security measure(28:08) How to get people to care about secrets(30:06) Where can people learn about secrets protection?(31:25) Where you can reach Mackenzie for more questions on secrets?
See you at the next episode!
Cloud Security Podcast - we are continuing with our "Kubernetes Security & KubeCon EU 2023" and for the fourth episode in this series Shane Lawrence and Daniele Santos from Shopify explained how kube-audit an open source tool from Shopify. They spoke about how they have used the audit tool to improve security with a developer security lens.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Shane Lawrence (Shane's Linkedin) and Daniele Santos (Dani's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(02:52) A bit about Shane
(03:45) A bit about Dani
(04:23) Which kubecons have Shane and Dani attended?
(05:03) A bit about Dani and Shane's talk at Kubecon EU
(06:42) Misconfigurations in Kubernetes
(09:48) Dani talks about the Kubernetes Security Report
(10:13) Use case for Kubernetes Misconfiguration
(11:45) What is Azure Escape?
(12:51) What is container escape?
(15:26) What is kubeaudit?
(15:49) Contributing to kubeaudit
(16:40) The maturity of kubeaudit
(19:04) How would kubeaudit help with an azure escape?
(19:41) The developer experience
(21:34) How shopify uses kubeaudit
(24:59) Getting started with kubeaudit
(25:53) Challenges with implementing kubeaudit
(27:19) Maturity of kubernetes security and kubecon
(30:02) Learning about kubernetes
(34:07) Areas of security not being spoken about enough
(36:16) Open Source and Software supply chain risks
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Kubernetes Security & KubeCon EU 2023" and for the third episode in this series, we spoke to Liz Rice ( Liz's Linkedin). Liz Rice from Isovalent speaks about how Network Security can be done in Kubernetes. Kubernetes network security with eBPF, Cilium can be raised to be better than selinux seccomp tcpdump - yes the linux networking security tools. Yes you read that right.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Andrew Martin (Andrew's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(00:15) A word from our sponsor snyk.io/csp
(03:36) A bit about Liz Rice
(04:36) Liz's path into Cloud Native
(06:22) What is EBPF?
(08:12) Use case for EBPF in on premise
(10:37) SC Linux and EBPF
(11:28) Why we are solving this now with Kubernetes?
(13:22) EBPF in managed vs unmanaged Kubernetes?
(15:37) Implementation of EBPF
(17:38) Access Management and Network Security
(21:02) Challenges with multi cluster Kubernetes deployment
(24:03) Key management in multi cluster
(25:11) Current gaps in Kubernetes security
(27:41) Developer first in the cloud native space
(32:47) The future of EBPF
(34:36) Where can you learn more about EBPF
(36:25) The fun questions
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Kubernetes Security & KubeCon EU 2023" and for the second episode in this series, we spoke to Andrew Martin (Andrew's Linkedin). Kubernetes Security Best practices built using the OWASP Top 10 for Kubernetes is not enough to deal with new and unknown attack vectors for your Kubernetes deployment. In this episode we have Andrew Martin on how you can deal with Kubernetes attack vectors including supply chain issues.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Andrew Martin (Andrew's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(00:15) A word from our sponsors - head over to snyk.io/csp to find out more
(02:50) A bit about Andrew Martin
(03:33) What is cloud native security?
(06:31) What is Kubernetes Security?
(10:23) Kubernetes Security vs Cloud Native Security
(11:52) Why is Kubernetes so popular?
(16:20) What are the components of Kubernetes security?
(21:43) Container security in Kubernetes landscape
(26:34) Common attack vectors for Kubernetes
(32:16) Impact of cloud in attack vectors
(35:38) Managed Kubernetes
(38:13) Rationale for using multi cluster
(41:11) Should everyone use Kubernetes?
(44:18) Is Serverless still relevant ?
(47:38) Where can people learn about Kubernetes security?
(53:01) The fun questions
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Kubernetes Security & KubeCon EU 2023" and for the first episode in this series, we spoke to Kirsten Newcomer (Kirsten's Linkedin). Kirsten Newcomer from Red Hat has been championing Kubernetes security and the role DevSecOps will play in helping improve security for Kubernetes implementations.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Kirsten Newcomer (Kirsten's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(02:42) Word from our sponsors about Snyk Launch - find out more at snyk.io/events/snyklaunch
(03:08) A bit about Kristen Newcomer
(04:13) How has Kubernetes security evolved ?
(06:57) Is Kubernetes still popular?
(07:45) Why is Kubernetes still popular?
(0:58) Challenges with security Kubernetes
(15:35) How to work effectively with Kubernetes
(18:50) Adoption of IaC for security
(24:30) Maturity of Kubernetes Security
(29:24) Challenges with auditing Kubernetes
(31:55) How to approach Kubernetes security?
(35:08) Zero Trust and Kubernetes
(39:01) Is SBOM bringing more attention to Kubernetes?
(42:51) Where do people start with Kubernetes?
(45:41) Managed vs unmanaged Kubernetes?
(47:05) How you can reach out to Kristen!
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Cloud Security - the Leadership View" and for the final episode in this series, we spoke to Guy Podjarny ( GuyPo's Linkedin).If you are working on building or securing Cloud resources, can you truly imagine solving the next log4j or AWS/Azure/GCP vulnerability without including the help of Platform Engineers or IT engineers? This is the bigger picture of what we CyberSecurity people have to do day in day out. We work with wider team members
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Guy Podjarny ( GuyPo's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
A word from our sponsors - you can visit them on snyk.io/csp
(00:00) Introduction
(03:49) A bit about Guy Podjarny
(04:51) What is DevSecOps today?
(07:15) 3 Phases of DevSecOps
(07:44) DevSecOps vs ShiftLeft
(09:15) The maturity of DevSecOps
(11:52) The notion of start left
(13:36) Threat modelling and developers
(14:38) What is Cloud Security?
(16:03) The notion of App Cloud
(17:43) Gartner acronyms and cloud security
(22:21) Security champion program in cloud
(28:33) Future of IaaS, PaaS and SaaS
(32:22) Challenges with Security Championship Program
(42:19) Generative AI and DevSecOps in Cloud
(47:45) Fun Questions
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Cloud Security - the Leadership View" and this week in this series, we spoke to Larry Whiteside Jr ( Larry's Linkedin ) If you are working on building a CyberSecurity Program in 2023 with Cloud in mind then this episode with Larry who shared his approach to building a CyberSecurity program along with war stories of implementing CyberSecurity in an on-premise world is the episode you need to hear.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
FREE CLOUD BOOTCAMPs on www.cloudsecuritybootcamp.com
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Larry Whiteside Jr ( Larry's Linkedin )
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(02:50) A word from our sponsors - you can visit them on snyk.io/csp
(04:05) Larry talks about his 1st CISO role
(06:01) Cybersecurity Programs in a Pre Cloud World
(09:07) What were the challenges for CISOs in the past?
(11:05) Cybersecurity Program in 2023
(14:01) There was no NIST CFA
(14:59) Why frameworks are important
(16:59) What is a cybersecurity program?
(21:32) Components of cybersecurity program
(23:02) Has cloud changed things?
(30:01) The value of certifications
(33:14) GRC Automation and Shift Left
(42:53) The auditor's perspective
(44:50) Does GRC need to know coding?
(49:07) Cloud Security Program Playbook
(52:52) The Fun Section
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Cloud Security - the Leadership View" and first up on this series, we spoke to Bianca Lankford (Bianca's Linkedin) about what does it take to build a Cloud Security program that runs behind your favourite TV Show on an OTT Media Platform like Warner Brother Discovery Cloud . In this episode Bianca Lankford, from Warner Brother Discovery, share her experience on building Cloud Security Program and the importance of developers in the solving the Cloud Security challenge.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Socials: Bianca Lankford (Bianca's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(03:06) snyk.io/csp
(03:45) A bit about Bianca
(04:27) Challenge of Scale in Media Industry
(06:38) Cloud based security program vs on prem
(08:04) How cloud security can enable businesses
(11:11) Cloud Security Program in Media Industry
(13:45) Getting leadership buy in for cloud security program
(17:05) Explaining cloud security as a business risk
(18:33) Pillars of cloud security program at scale
(20:12) Multi Cloud Security Program
(20:52) Skills required for multi cloud security team
(22:25) The future of application security and cloud security
(24:01) Metrics of operationalising cloud security program at scale
(25:32) Time to detection in Cloud
(26:32) Navigating cloud security program through changing compute
(28:09) Security guardrails vs security gate
(30:53) Stages for a cloud security program
(32:35) The Fun Section
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Building on the AWS Cloud" and next up on this series, we spoke to Chad Lorenc (Chad's Linkedin) about AWS Security Reference Architecture, Cloud Adoption Framework & Security Maturity Model are 3 ways to level up the maturity you have in Cloud . In this episode Chad Lorenc, from AWS shared lessons and talk about How AWS Customers can prepare to use 3 models to Crawl, Walk & Run their security practice.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Chad Lorenc (Chad's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(03:35) A word from our sponsors - check them out at snyk.io/csp
(03:51) A bit about Chad
(05:38) How things are different in the Cloud
(07:59) The Maturity framework of AWS
(11:20) How maturity scales in AWS
(13:17) Anti-Patterns when building maturity in Cloud
(15:35) Framework examples on how to build maturity models
(19:27) Mapping maturity models to business objectives
(20:19) The role of cloud native tools
(26:23) Patterns in AWS to watch out for
(28:38) Challenges for security leaders trying to get into cloud
(35:07) Foundational pieces for building maturity in AWS
(37:50) How to implement AWS Control tower?
(43:09) Give developers more freedom in cloud
(47:34) Benchmark scales for security maturity
(51:27) Resources to help you build your own maturity roadmap
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Building on the AWS Cloud" and next up on this series, we spoke to Patrick Sanders (Patrick's Linkedin) & Jospeh Kjar (Joseph's Linkedin), Snr Cloud Security Engineer at Netflix on what does it take to reimagine multi-account deployments gave them both security and speed.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Patrick Sanders (Patrick's Linkedin) & Jospeh Kjar (Joseph's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(03:06) snyk.io/csp
(03:41) A bit about how Patrick and Joseph got into the Cloud Space
(06:00) Building blocks of scalable AWS infrastructure
(09:14) Should there be a seperate account for forensics
(12:44) Diff AWS Org for dev and prod?
(13:45) How to ensure dedicated IR account is secure?
(15:10) 1st step to building a new startup in AWS
(17:39) Should non prod and prod accounts be seperate?
(21:29) How do you ensure visibility into your AWS organisation?
(25:04) Integrate FIM into AWS
(26:29) Layers for a multi account strategy
(28:23) Challenges from going from one account to multi account
(34:03) Bringing identity to the application
(38:25) The importance of IMDS
(42:07) The security benefit of using IMDS
(45:34) Managed identity in AWS
(46:40) Why developer experience is important?
(49:49) What do cloud security engineers do ?
(53:05) Where you can find Joseph and Patrick?
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Building on the AWS Cloud" and next up on this series, we spoke to Alexis Robinson (Alexis's Linkeidn), Senior Manager, Regulatory Compliance at AWS. FEDRAMP AWS environment can be made easy with the right security assessment framework for your organization. Alexis shared lessons and talk about How AWS Customers can prepare to increase their chances of getting FedRamp certified.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Alexis Robinson (Alexis's Linkeidn)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security BootCamp
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(05:35) A bit about Alexis
(08:20) What is FedRAMP and why people care about it?
(11:05) Scope of companies included in FedRAMP?
(13:12) Zero Trust Architecture and FedRAMP
(14:07) The concept of Controlled Inheritance
(15:43) Working with Authorising Officials
(16:44) Working with Security Control Officers
(17:46) AO Checklist to full compliance
(20:42) Conflicts in FedRAMP
(25:59) Common pitfalls to avoid on FedRAMP Journey
(31:38) The anti-patterns in getting FedRAMP Compliant
(35:34) FedRAMP is not just GovCloud
(38:12) Requirements with FedRAMP
(39:48) Where do people fall short with FedRAMP?
(41:26) How to make FedRAMP more developer friendly?
(44:17) How is FedRAMP different for Govcloud?
(47:21) What skillsets do you require in a team for FedRAMP?
(49:07) How to learn about FedRAMP
(53:09) Fun Questions
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Building on the AWS Cloud" and next up on this series, we spoke to Mrunal Shah (Mrunal's Linkedin), Head of Container Security at Warner Bros. Discovery. We talk about how to build a Container or K8s security program while best practices are maintained and team have the right capability and tools. 4 Cs - Cloud, Container & Cluster, Code can be foundational to this
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Mrunal Shah (Mrunal's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Intro
(02:01) https://snyk.io/csp
(02:30) Mrunal's Professional Background
(03:04) Why containers are popular (technical reasons)
(04:05) Why containers are popular (leadership reasons)
(05:39) Challenges with running a Container Security Program (Leadership)
(06:34) Team skill challenge in a Container Security Program
(08:57) When to pick AWS ECS vs AWS EKS?
(10:53) ECS or EKS for building Banking Applications?
(13:12) Would Kubernetes/ Containers be preferred for security reasons?
(15:04) What would Amazon's responsibility be for security with ECS/EKS?
(16:13) What is bad about working with Containers in AWS?
(19:40) Is there a need for anti-virus in a container world?
(20:36) Balance of security when working with containers?
(22:08) Threat Detection and Prevention in a Container Security Program
(22:57) Using AWS Services for Threat Detection with Containers?
(25:14) Runtime Threat Discovery vs Agentless Threat Discovery for containers in Cloud?
(29:11) Prevention on the left vs Detection on the right of SDLC
(29:22) Cluster Misconfig vs Service Misconfigurations?
(30:19) Vulnerability Management vs Misconfiguration Management?
(31:50) Inspector in a Container Security Program?
(32:36) Detective in a Container Security Program?
(35:36) Can AWS Services help when Non-AWS services are in use?
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Breaking the AWS Cloud" and next up on this series, we spoke to Seth Art (Seth's Linkedin) Cloud Penetration Testing Lead (Principal) at Bishop Fox. AWS cloud project to pentest AWS cloud architecture are not spoken about much - this stops today. We have Seth who works in the Cloud Penetration testing space to talk about open source tools and what Cloud pentesting is all about.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Seth Art (Seth's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(04:24) A bit about Seth
(06:10) Web App Pentesting vs Cloud Pentesting
(08:11) Working with scale of multiple AWS accounts
(10:20) What can you expect to find with Cloud Pentesting?
(12:14) Foundational pieces about approaching pentesting in Cloud
(15:19) How to start a Cloud Pentest?
(18:25) The importance of IAM
(23:43) Common services in AWS to look at
(25:58) Mistakes people make for scoping
(29:18) The role of shared responsibility in Cloud Pentesting
(32:38) Boundaries for AWS pentesting
(35:13) Nmap between 2 EC2 instances
(36:37) How do you explain the findings?
(40:26) Skillsets required to transition to Cloud Pentesting
(45:41) Transitioning from Kubernetes to Cloud Pentesting
(48:55) Resources for learning about Cloud Pentesting.
(49:47) The Fun Section
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Breaking the AWS Cloud" and next up on this series, we spoke to Nishant Sharma (Nishant's Linkedin), Director, Lab Platform, INE. If you have tried pentesting in AWS Cloud or want to start today with AWS Goat, then this episode with Nishant, behind AWS Goat will help you understand how you can upskill and maybe even show others how to be better at pentesting AWS Cloud.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Nishant Sharma (Nishant's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(03:51) snyk.io/csp
(04:51) What is Cloud Pentesting?
(06:19) Cloud pentesting vs Web App & Network
(08:37) What is AWS Goat?
(13:12) Do you need permission from AWS to do pentesting?
(14:03) Pentesting an application vs pentesting AWS S3
(15:40) What is AWS Goat testing?
(18:14) Cloud penetration testing tools
(19:59) How useful is a metadata of a cloud instance?
(22:24) AWS Pentesting and OWASP Top 10
(25:31) How to build internal training for Cloud Security?
(29:43) Keep building knowledge on AWS Goat
(30:33) Using CloudShell for AWS pentesting
(34:09) ChatGPT for cloud pentesting
(36:28) Vulnerable serverless application
(39:40) Pentesting Amazon ECS
(43:01) How do you protect against ECS misconfigurations?
(47:38) What is the future plan for AWS Goat?
(50:28) Fun Questions
See you at the next episode!
Cloud Security Podcast - This month we are talking about "Breaking the AWS Cloud" and next up on this series, we spoke to Gafnit Amiga (Gafnit's Linkedin), VP of Security Research at Lightspin who recently discovered the AWS Elastic Container Registry Public (ECR Public) vulnerability. She spoke to us about how she goes about doing cloud security research and what AWS ECS and ECR is.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Gafnit Amiga (Gafnit's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(02:28) snyk.io/csp
(02:57) A bit about Gafnit
(05:15) What is AWS ECS and ECR?
(08:18) Why do people use ECS and ECR?
(09:58) The ECR vulnerability Gafnit discovered
(15:16) Vulnerability scanning for containers in AWS ECR
(16:42) How do you find undocumented APIs in AWS?
(17:58) Attack techniques in AWS
(22:43) How to protect your AWS accounts?
(25:14) Focus areas for Cloud Security Research in 2023
(25:48) Finding vulnerability through research
(29:00) Resources for Cloud Security Research
(31:04) The Fun Section
See you at the next episode!
Cloud Security Podcast - If Hacking the Cloud is on your mind for 2023 then in this "Breaking the AWS Cloud" month we are kicking things with Nick Frichette (Nick's Linkedin), a Senior Security Researcher from DataDog who is also maintains the site Hacking the Cloud linking offensive security research for AWS, Azure, GCP.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Nick Frichette (Nick's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Introduction
(02:38) snyk.io/csp
(03:26) A bit about Nick
(04:15) How is Security research different?
(05:55) How to approach cloud security research?
(07:24) How to pick the service you want to research?
(08:51) What is AWS AppSync?
(09:30) What is Confused Deputy Vulnerability?
(10:16) The AppSync Vulnerability
(12:09) Cross Account in AWS
(13:41) Blue Teaming Controls when doing research
(14:22) Framework for detective controls
(16:01) What to do if you find an AWS vulnerability?
(17:20) Legal constraints of security research
(20:13) Where to get started in Cloud Security Research?
(22:45) Are some misconfigurations becoming less common?
(24:59) What is IMDSv2 and how is it different to IMDSv1?
(27:00) Why is SSRF bad?
(28:52) Cloud Pentesting Platforms
(29:57) The story being hacking the cloud
(31:25) Who should think about breaking the cloud?
(34:02) Cloud Security Research Tools
(36:38) How to access AWS environment for research?
(39:12) Security Lab Resources
(40:04) The Fun Questions
See you at the next episode!
In this episode of the Virtual Coffee with Ashish edition, we spoke with Shilpi Bhattacharjee (Cloud Security Podcast, Producer). We spoke about Announcements from AWS Reinvent for - new security products announced, updates to existing security products, security addition to existing products and products to lookout for.
--Announcing Cloud Security Villains Project--
We are always looking to find creative ways to educate folks in Cloud Security and the Cloud Security Villains is part of this education pieces. Cloud Security Villains are coming, you can learn how to defeat them in this YouTube Playlist link
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Justin Garrison (Personal Website)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
In this episode of the Virtual Coffee with Ashish edition, we spoke with Justin Garrison (Personal Website) from AWS to talk about what scenarios make sense to choose AWS EKS vs AWS ECS vs AWS Fargate vs bare metal Kubernetes & everything you need to understand for implementing AWS EKS in your environment.
--Announcing Cloud Security Villains Project--
We are always looking to find creative ways to educate folks in Cloud Security and the Cloud Security Villains is part of this education pieces. Cloud Security Villains are coming, you can learn how to defeat them in this YouTube Playlist link
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Justin Garrison (Personal Website)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00 introduction
(02:31 snyk.io/csp
(03:10 Justin's path into Tech
(08:14) What is AWS EKS?
(10:32) EKS vs ECS vs Fargate
(14:52) Why pick EKS vs ECS vs Fargate?
(23:05) Security Kubernetes API vs on-prem deployment?
(34:26) What's involved in deploying EKS?
(38:50) EKS clusters when scaling Kubernetes
(42:52) How clusters are structured?
(47:02) Cluster availability when upgrading
(49:00) Why people struggle with EKS?
(51:31) How can people learn more about EKS?
(52:57) The Fun Section
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ashish Desai (Ashish Desai's Linkedin) about how much of the on-premise can work in Cloud, what the online world is saying versus the reality of what businesses are experiencing.
--Announcing Cloud Security Villains Project--
We are always looking to find creative ways to educate folks in Cloud Security and the Cloud Security Villains is part of this education pieces. Cloud Security Villains are coming, you can learn how to defeat them in this YouTube Playlist link
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Ashish Desai (@ashishlogmaster)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Intro
(05:50) Ashish Desai's Professional Background
(06:21) Academic Freedom and no firewall
(07:12) What are the roles and responsibilities of an AWS cloud security architect?
(09:27) Difference between managing permissions between onpremise vs Cloud service provider
(13:02) Running Windows 2003 on AWS EC2 Bare Metal
(13:28) Running Old Virtual Servers on AWS
(14:13) Cloud is secure by default
(14:54) CI/CD with Github and Terraform is not common
(15:28) Do people use CI/CD?
(15:37) Traditional on-premise staff is your new cloud engineer
(16:50) Business are not fully advanced
(17:47) Failed Kubernetes Deployment in production example
(18:45) Managed and Bare Metal Kubernetes can only maintain 1 replica
(19:10) What is 1 replica in Kubernetes?
(20:36) Problem with stateful app running on Kubernetes
(21:35) Change Management in Cloud
(21:57) Deployment phases in Cloud
(22:34) Why was ServiceNow required?
(24:39) Why ServiceNow couldn't keep up?
(26:33) Native Solutions bypass Change Management
(28:43) Role of Security Architect in a New Cloud World
(29:53) DevExperience is holding Cloud Adoption success
(32:08) CyberProfessionals to know atleast 1 language to be succesful
(32:27) Do Architect need to know how to code in Enterprise context?
(33:24) Knowing Code to understand the lay of the land
(35:22) Has the Architecture Frameworks changed in the Cloud world?
(37:15) What other skillsets outside of coding is required to be successful in Cloud
(39:54) Should we care about being Cloud agnostic?
(40:41) Architecture for Operational side of Cloud Security?
(43:51) Practical things for advancing Cloud skills?
(48:36) Can anyone come out of uni and become a Cloud Security Architect
(50:32) Resources for education on Cloud security architects
(51:36) Fun Section
In this episode of the Virtual Coffee with Ashish edition, we spoke with Kat Traxler (Kat's Linkedin)about the skillset, certification and knowledge base required to become a cloud security architect in 2023.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Kat Traxler (Kat's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(02:28) https://snyk.io/csp
(02:46) A bit about Kat
(05:35) What does a security architect do?
(06:46 )The difference in the Cloud Security Architect role
(11:08) The building blocks of building an application in AWS
(13:41) Are there DMZs in Cloud Architecture?
(15:54) Cybercriminal and Cloud exploitation
(19:04) How to keep with rapid changes in cloud?
(20:08) AWS pre:invent update
(21:39) Why is IAM important in Cloud?
(25:03) Do cloud security architects need to know coding and automation?
(27:38) How important are certifications?
(31:49) Getting in cloud security with no experience
(33:41) What are important skills for architect?
(35:33) SANS certifications for Cloud Security Architects
(37:04) How important is ist to have multi cloud knowledge
(40:44) Frameworks to build cloud architecture
(42:59) Do you need to know software development?
(44:19) Roadmap to become a cloud security architect
(45:32) What is the most difficult thing related to architecture?
(49:32) The Fun Section
In this episode of the Virtual Coffee with Ashish edition, we spoke with Rodrigo Montoro (Rodrigo's linkedin)about threat modelling and incident response involving the uncommon AWS services which still may be widely used in your organisation and increase your attack surface.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Rodrigo Montoro (Rodrigo's linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(02:10) https://snyk.io/csp
(03:19) A bit about Rodrigo
(04:37) Detection in On-Premise
(06:51) The role of API in Cloud
(08:06) Common Services in AWS
(15:22) Managing unused services
(17:38) Incident response for AWS Appstream ?
(20:57) integration of services with Cloudtrail
(27:14) AWS Pass role
(31:38) Incident Response for services
(34:00) Pre-signed URL
(36:23) How to get started in AWS threat detection?
(39:10) Where can people learn more about this?
(41:37) How to do AWS threat detection at Scale?
(43:30) The Fun Section
In this episode of the Virtual Coffee with Ashish edition, we spoke with Nandesh Guru (Nandesh's Linkedin)about ransomware and supply chain attack mechanisms in AWS and how the world of CSPM have evolved to address the increasing complexities of cloud security
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Nandesh Guru (Nandesh's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(02:09) https://snyk.io/csp
(03:11 )A bit about Nandesh
(05:01) 4 Components of Supply Chain Risks
(06:47)Example of AWS Supply Chain Attack
(10:08) Evaluating code scanning tools
(12:30) What is ransomware?
(13:06) Ransomware in AWS
(14:55) Attacks on encryption in AWS
(19:27) What is a CSPM?
(20:46) The role of CSPM and CNAPP in supply chain attacks
(22:56) Is CIS Benchmark still a good starting point?
(26:38) The evolution of CSPMs
(29:47) Complexity of Cloud Security
(32:59)Where can you learn more about supply chain risks?
(33:50) Fun Questions
In this episode of the Virtual Coffee with Ashish edition, we spoke with Christophe Parisel (Christophe's Linkedin)about what how to transition from being a technical architect on premise to a cloud security architect and then a cloud native security architect.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Christophe Parisel (Christophe's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(02:21) https://snyk.io/csp
(03:18) A little bit about Christophe
(05:08) What is Cloud Native?
(07:27) Why Cloud Native is important?
(09:34) Responsibilities of Cloud Native Architect
(13:15) Solution Architect vs Cloud Native Architect
(15:32) Culture to move into Cloud Native Environment
(18:09) Designing an application in Cloud
(21:41) Designing an application using Kubernetes Cluster
(24:39) Learning Kubernetes as an Architect
(28:09) Common services people should standardise
(31:50) Frameworks for Kubernetes Architecture
(34:06) Logging with Kubernetes at Scale
(38:24) Challenge with transitioning to Cloud Native Security Architect
(39:43)Should we trust the cloud?
(43:37) Bottlerocket in Kubernetes
(46:00) Certifications for Cloud Native Security Architect
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jim Bugwadia (Jim's Twitter)about policy management and compliance as code for Kubernetes and how you can use open source tools like Kyverno and OPA for policy management
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Jim Bugwadia (Jim's Twitter)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(03:20) https://snyk.io/csp
(05:23) What is Kubernetes Control Plane?
(06:51) What is an admission controller?
(08:01) What do you need policy management in Kubernetes?
(10:13) Pod Security and Policy management
(11:57) Policy Management in Managed Kubernetes
(13:54) Scaling Policy Management for Kubernetes
(19:34) Common use cases for policy management
(25:30) Compliance in Kubernetes
(32:04) Levels of Maturity in Kubernetes Policy Management
(36:47) Future of policy as code
(38:46) Kyverno vs OPA
(43:39) Kyverno vs gatekeeper
(45:15) Where to start with policy management?
(46:11) Where you can find Jim
In this episode of the Virtual Coffee with Ashish edition, we spoke with Luke Hinds (Luke's Twitter)the open source Sigstore project and how it is helping with software signing and protecting the software supply chain
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Luke Hinds (Luke's Twitter)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(01:39) https://snyk.io/csp
(05:21) What is the software supply chain and why is it important?
(08:20) Common supply chain attacks in Kubernetes
(09:53) Codecov attack
(11:14 )Kubernetes and API
(14:10) Vulnerability scanning tools
(16:38) Explaining the importance of supply chain security
(19:19) What is a signing service
(19:56 )The SLSA framework
(20:42) Importance of signing service
(23:35) What is Sigstore?
(27:57) What is Lets Encrypt
(31:48) The aim of sigstore
(34:39) What is Co-Sign
(36:40) Co-Signing and non-repudiation
(46:29) Where to start
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jimmy Mesta (Jimmy's Twitter)aboutOWASP Kubernetes Top 10 and best practices for securing Kubernetes
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Jimmy Mesta (Jimmy's Twitter)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(01:39) https://snyk.io/csp
(03:55) What is Kubernetes?
(05:15 )Kubernetes vs Containers
(06:38) Kubernetes and Docker
(09:08) Unmanaged Kubernetes
(11:14) Managed Kubernetes
(13:39) Security for Kubernetes Clusters
(15:42) OWASP top 10 Web Application
(17:59) Starting to build Kubernetes Cluster or Pod
(23:09) Security Misconfigurations in Kubernetes
(28:42) Supply Chain Vulnerabilities in Kubernetes
(32:06) RBAC and Policy Enforcement
(33:32) Logging and Monitoring in Kubernetes
(34:30) Broken Authentication
(35:17) Missing network segment approach
(36:07) Secrets Management Failure
(37:09) Misconfigured Cluster Components
(38:15) Outdated and vulnerable kubernetes component
(42:37) Asset Inventory for Kubernetes Cluster
(44:53) Threat Modelling in Kubernetes
(46:20)Cert management in Kubernetes
(48:02) Learn more about securing Kubernetes
Modern Cloud Security Programs hire for builders who can develop tools that help developers walk down a Paved road where security is not a blocker but at the same time prevents developers from making security mistakes. In this episode we spoke with Travis McPeak who shared his experience from his time at Netflix to talk about Modern Cloud Security Teams look like and work on day to day at scale for a large development team and how others can take some insights from this for their own Cloud Security Programs.
This episode is better on video - YouTube Link
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Travis McPeak
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Azure Cloud Security Architecture (Day 0) ,Custom Azure Role definitions, Azure Privilege Access Management etc can be complex to build. Continuing from part 1 In the part 2 of our This is My Cloud Security Architecture Series Episode we have Sai, a Cloud Security Architect walking us through how to start with an Azure Security Architecture on Day 0 of your Cloud Security Architect role. Part -2 of the episode will go into Day 1+ of managing and scaling what we have created in Day 0.
This episode is better on video - YouTube Link - Part 2
Part 1 of the This is My Cloud Security Architecture Series is here - YouTube Link - Part 1
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Sai Gunaranjan (Sai's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Data Lakes as an asset to collect and build threat actors or hiring for Data Scientists/Analyst are not typical things in Cloud Security well unless the organisation is dealing with PetaBytes of data. At a large scale company these are data problem not a security problem at that point even if the problem is in security team. In this episode with Jonathan Rau, CISO of Lightspin we spoke about his previous experience of creating and growing a SecDataOps team with Cloud Security and Ops in IHSMarkit. We spoke about what is this SecDataOps, What is Security Data Lake and if Cloud Native tools are enough for these problems.
This episode is better on video - YouTube Link
Cloud Security Meetup Amsterdam - Tech Fashion Theme - Sep,2022
Cloud Security Meetup NewYork - Tech Fashion Theme - Sep,2022
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: Jonathan Rau
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Azure Cloud Security Architecture, Azure Policies can be complex to build. In the part 1 of our This is My Cloud Security Architecture Series Episode we have Sai, a Cloud Security Architect walking us through how to start with an Azure Security Architecture on Day 0 of your Cloud Security Architect role. Part -2 of the episode will go into Day 1+ of managing and scaling what we have created in Day 0.
This episode is better on video - YouTube Link
Cloud Security Meetup NYC - Cloud Security Meetup NewYork - Tech Fashion Theme
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Sai Gunaranjan (Sai's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jack Naglieri (Jack's Twitter) about what Security Monitoring can look like for a Cloud Native Company
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Jack Naglieri (Jack's Twitter)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(02:40) https://snyk.io/csp
(02:51) Corey's professional background
(03:34) Jack's introduction
(06:15 )What is Cloud Native?
(07:41) What is a modern security stack?
(09:50) Why Cloud Native Security Monitoring?
(12:36) The current market for security monitoring
(15:45) Cloud Native monitoring for on-prem
(18:10) How to start with Cloud Native Security Monitoring?
(21:01) Security monitoring in cloud vs traditional
(22:51) Challenges with Cloud Native Security Monitoring
(25:25) How can SMBs tackle Cloud Native Security Monitoring?
(26:52) Are cloud native tools more cost effective than traditional ones?
(28:30) Heterogeneous log correlation
(30:09) What is a security data lake?
(35:25) Does the modern security team need data skills?
In this episode of the Virtual Coffee with Ashish edition, we spoke with Corey Ball (Corey's Twitter) aboutwhat does API in a modern software stack looks like and how these can be attacked and protected
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Corey Ball (Corey's Twitter)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(02:40) https://snyk.io/csp
(02:51) Corey's professional background
(03:11) Corey's journey to be cybersecurity author
(04:36) What is API and why its important in 2022?
(06:44) Is API is the backend or frontend pf applications?
(08:36) What are people doing wrong with APIs?
(12:16) Best Practice for API Security?
(13:20) Most surprising things being seen in API Security?
(14:35) How do you find API keys?
(16:07) API gateway as a security control point
(18:25) OWASP Top 10 API Security
(20:00) Monitoring and detecting for API Security
(20:57) How to approach pentesting APIs?
(22:35) Learn about API hacking
(25:22) API Security in the Cloud
(29:05) Rest API vs GraphQL
(34:27) Pentest by consuming application documentation
(36:10) Which APIs should be public?
Special Episode by Shilpi and Ashish sharing their recap, highlights, big takeaways, Cloud Talks and Training from Hacker Summer Camp - Blackhat Defcon Diana Initiative BSides Vegas 2022.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jeevan Singh (Jeevan's Linkedin) aboutThreat Modelling STRIDE Threat Modelling can be used for self service Application running in Cloud and allowing Security Teams to go on holiday without worrying about Digital Supply Chain.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Jeevan Singh (Jeevan's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Spotify TimeStamp for Interview Questions
(00:00) Ashish's Intro to the Episode
(02:15) https://snyk.io/csp
(02:40) Jeevan's Professional Background
(04:23) What is threat modelling
(05:35) Flicking the Threat Modelling switch
(06:47) Common AppSec Mistake
(09:58) What is Threat Modelling Important?
(11:46) Tainted Flow Analysis and Threat Modelling
(13:00) Where does this fit in CI/CD?
(14:25) Security Teams going on vacation made possible
(15:34) Impact of teaching developers how to run Threat Model
(16:33) First time running Observe Phase of Threat Modelling with Developers
(17:13) Developers are better at Threat Model than Security
(19:09) Level of programming expertise for Threat Modelling
(21:32) Fixing Threats vs Finding relevant controls for the threat
(22:00) Bad example of role of Threat Modelling in Business
(23:41) Should Threat Model be done in Dev?
(24:54) Example of Threat Model for an App hosted in Cloud?
(27:27) Threat Model Skeleton for Cloud Native Apps
(30:12) Does complexity increase with multi-cloud/hybrid environments?
(32:27) What’s involved in rolling a Threat model program in an organisation?
(36:26) Who is the minimum representation in Threat modelling session?
(38:30) Advice for folks who are starting threat modelling today in their organization
(41:59) Cultural Change required for Threat Modelling
(43:19) Example of getting Management agreement
(44:58) Jeevan's 4 Stage of Threat model talk - https://www.youtube.com/watch?v=DtvjJL8xcPY
(45:28) Time-boxing Threat Model Sessions
(48:21) Maintaining Quality of Risk identified during threat modeling
(50:21) Keeping developers updated on latest security vulnerabilities
(54:07) Jeevan’s Favourite Threat Model Type
(55:09) Where can people learn threat modelling?
(56:12) Fun Section
In this episode of the Virtual Coffee with Ashish edition, we spoke with Karthik Ramamoorthy (Karthik's Linkedin) aboutContainer security with NIST Framework for financial services organizations.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Karthik Ramamoorthy (Karthik's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Special Episode by Shilpi and Ashish sharing their recap, highlights, big takeaways, meh moments and in person experience from AWS ReInforce 2022.
Twitter Space with Cloud Security Community about the AWS Re:Inforce 2022 Recap & Highlights
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Cassandra Young (@muteki_rtw)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Cassandra Young (@muteki_rtw)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Special Episode by Shilpi and Ashish announcing the partnership with Snyk and what does this mean for the podcast community - you and also for Ashish and Shilpi. The new Architecture series we are announcing in the coming weeks and a lot more. We hope you continue to enjoy the vendor neutral content from Cloud Security Practitioners we bring to you.
Here is an Interview with Guy Podjarny (Founder of Snyk) that we did as part of the announcement!
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest : Snyk
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Kyler Middleton (Kyler's Linkedin)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Kyler Middleton (Kyler's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
Zero Trust is top of mind but is it achievable? In this "What to LookOut for in 2022" series - we interviewed experts at RSA and BSidesSF about what Zero Trust is important today and the paradoxes in achieving it.
Watch the video for this episode on You Tube - ZERO TRUST AND THE TRIPLE PARADOX
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guests Linkedin: Thank you to Anudeep Parhar, Daniel Tranner, Dylan Owen & Bill Malik for participating in this episode.
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Kinnaird McQuade (Kinnaird's Twitter)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Kinnaird McQuade (Kinnaird's Twitter)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
The Digital Supply Chain is broken and getting challenging to fix. In this "What to LookOut for in 2022" series - we interviewed experts at RSA and BSidesSF on the Broken Digital Supply Chain and ways in which we can fix it.
Watch the video for this episode on You Tube - Fix the Broken Digital Supply Chain
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter + Linkedin: Ashish Rajan (@hashishrajan) + Shilpi Bhattacharjee (@shilpibhattacharjee)
Guests Linkedin: Thank you to Mikko Hypponen, Shamla Naidoo, Clint Gibler, Ryan F, Mike Ruth, Paul Calatayud, Shay Levi, Dylan Ayrey, Aaron Brown, Mackenzie Jackson & Dan Gordon for participating in this episode.
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
The Digital Supply Chain is broken and getting challenging to fix. In this "What to LookOut for in 2022" series - we interviewed experts at RSA and BSidesSF on the Broken Digital Supply Chain and why it has become a challenge.
Watch the video for this episode on You Tube - 3 THINGS THAT BROKE THE DIGITAL SUPPLY CHAIN
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guests Linkedin: Thank you to Keatron Evans, Clint Gibler, Ryan F, Mike Ruth, Paul Calatayud, Shay Levi, Dylan Ayrey, Aaron Brown & Dan Gordon for participating in this episode.
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke withHeather Ceylan (@heatherceylon) & Ariel Chavan (@ariel-c-ab445a50) from Zoom.
Watch the video for this episode on You Tube - Digital Transformation in 2022
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guests Linkedin: Heather Ceylan (@heatherceylon) & Ariel Chavan (@ariel-c-ab445a50)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Sean Catlett (Sean's Linkedin)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Sean Catlett (Sean's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Akash Ganapathi (Akash's Linkedin)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Akash Ganapathi (Akash's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Tanya Janca(Tanya's Twitter)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Tanya Janca (@shehackspurple)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Steve Orrin (Steve's Linkedin)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Steve Orrin (Steve's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke withSai Gunaranjan (Sai's Linkedin)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Sai Gunaranjan (Sai's Linkedin)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Andrew Brown, ExamPro
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Andrew Brown (@andrewbrown)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Yoav Alon, CTO, Orca Security
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Yoav Alon(@yoavalon)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jimmy Mesta, Co-Founder, KSOC
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: Jimmy Mesta
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Paul Schwarzenberger, Cloud Security Engineer, Celidor
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: Paul Schwarzenberger (@paulschwarzen)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Or Azarzarfrom LightSpin
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Or Azarzar
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ian Lewis from Google Cloud
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Ian Lewis
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Sakshyam Shahfrom Teleport
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Sakshyam Shah
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke withPushkar Joglekar, Sr. Security Engineer, VMWare Tanzu
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Pushkar Joglekar @PuDiJoglekar
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with William Morgan, ex Twitter, CEO Buoyant
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter:William Morgan, ex Twitter, CEO Buoyant
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jasmine Henry & George Tang from JupiterOne
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin:Jasmine Henry & George Tang
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
n this episode of the Virtual Coffee with Ashish edition, we spoke with Eliav Livneh , Lead Security Researcher at Hunters
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin:Eliav Livneh (@eliav-livneh)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Barak Schoster Goihman, Senior Director, Chief Architect at Palo Alto Networks (BridgeCrew)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin:Barak Schoster (@barakschoster)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Mike Chambers @mikechambers, AWS Hero AI/ML
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin:Mike Chambers @mikechambers
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Sunil Potti @sunilpotti VP/GM, Google Cloud
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin:Sunil Potti @sunilpotti
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jonathan Brodie Senior Cloud Security Engineer, ITV
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter:Jonathan Brodie
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Antoni Tzavelas (@antoniscloud) Google Cloud Certification Trainer, Antoni Training
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Antoni Tzavelas (@antoniscloud)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Brad Richardson (@Richarjb) Red Team and Vulnerability Management
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Brad Richardson (@Richarjb)
Podcast Twitter - @CloudSecPod@CloudSecureNews
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jason Dyke (@jasonadyke) a Staff Security Engineer at Blocks (@Blocks).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Jason Dyke (@jasonadyke)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Gal Helemski (@Linkedin-Gal Helemski) CoFounder, CTO & CPO at PlainID (@plainID_authZ).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Gal Helemski (@Linkedin-Gal Helemski)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 26 Jan 2022
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ian Mckay (@iann0036), a AWS Community Hero, AWS APN Ambassador who has a lot of popular open sources projects in the AWS security space.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Ian Mckay (@iann0036)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 19 Jan 2022
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Dylan Ayrey (@insecurenature) is a Professional Hacker and Co-Founder of Truffle Security (@trufflesec)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Dylan Ayrey (@insecurenature)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Stu Hirst (Linkedin-Stu Hirst) is the Chief Information Security Officer (CISO) of Trustpilot (@Trustpilot).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Stu Hirst (Linkedin-Stu Hirst)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 12 Jan 2022
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Fred Wilmot (@fewdisc) is an ex-Veteran and Chief Information Security Officer (CISO) of JumpCloud (@JumpCloud).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Fred Wilmot (@fewdisc)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 5 Jan 2022
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Or Weis (@OrWeis) co-founder and CEO of Permit.io (@permit_io).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Or Weis (@OrWeis)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 22 December 2021
Cloud Security News this week 15 December 2021
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
Cloud Security News this week 8 December 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
Cloud Security News this week 2 December 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
Cloud Security News this week 24 November 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Andrew Krug (@andrewkrug) is a AWS Re:invent speaker and Cloud Security Evangelist at DataDog (@DataDogHQ).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Andrew Krug (@andrewkrug)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 17 November 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ran Ribenzaft (@ranrib) is an AWS Serverless Hero, Forbes under 30 and the co-Founder of Epsagon (@Epsagon).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Ran Ribenzaft (@ranrib)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 10 November 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jon Zeolla (@jonzeolla ) is a Cloud Native Contributor, co-founder CTO of Seiso.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Jon Zeolla (@jonzeolla )
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
Cloud Security News this week 27 October 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Maximilian Burkhardt (@maxb) is a Staff Security Engineer at Figma (@Figma)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Maximilian Burkhardt (@maxb)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast - www.cloudsecuritypodcast.tv
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Chris Hughes (@Linkedin-Profile) is a host of the Resilient Cyber Podcast.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Chris Hughes (@Linkedin-Profile)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast
- Cloud Security Academy
Cloud Security News this week 27 October 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Nathan Case ( Linkedin Profile ) is a Senior Director, Security Operations at Resilience.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Nathan Case ( Linkedin Profile )
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast
- Cloud Security Academy
Cloud Security News this week 22 October 2021
Hope you have been enjoying your Cloud Security News this week and in our special third instalment for this week we bring you our best bits from Hashiconf Global 2021, conference held by Hashicorp. Hashicorp is a software company who provide open source tools and products - some of their popular products Vagrant, Terraform, Vault and boundary - You can view the conference and the talks here
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
Cloud Security News this week 21 October 2021
It's a month full of conferences and as promised we are back with our 2nd episode this week to bring you the cloud security highlights from KubeCon. In this episode we will share some of our team’s favourite from Kubecon 2021 North America
If you aren't quite familiar with the wonderful world of Kubernetes, there are a few weird and wonderful open source acronyms in today’s episode. TUF refers to The Update Framework, SPIFFE refers to Secure Production Identity Framework for Everyone SPIFFE, SPIRE is the SPIFFE’s Runtime Environment). Now that we are all across cool Kube words - lets into the talks
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
Cloud Security News this week 20 October 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Om Moolchandani (@omaitrika) is a CISO and CTO at Accurics (@AccuricsSec)..
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Om Moolchandani (@omaitrika)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast
- Cloud Security Academy
Cloud Security News this week 14 October 2021
It's an eventful month for all things cloud as Google Cloud Next 21 and Kubecon are happening this week. Ashish from Cloud Security Podcast was co-hosting the Capture the Flag today with Magno Logan from Trend Micro, you can check it out here.
In next week’s episode we will be bringing to you the best bits from Kubecon and Google Cloud Next 21.
You can view these events virtually at the links below
Google Cloud Next 21
Kubecon
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram -Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Gaurav Kumar (@gauravphoenix) is the Founder of Dassana (@DassanaSecurity).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Gaurav Kumar (@gauravphoenix)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast
- Cloud Security Academy
Cloud Security News this week 06 October 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
Instagram - Cloud Security News
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with David McCaw (Linkedin - David McCaw) is a Co-Founder of Dasera (@DaseraInc).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: David McCaw (Linkedin - David McCaw)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast: https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
- Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Cloud Security News this week - 29 September 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Tanya Janca (@shehackspurple) is an Author, Security Trainer and Founder of We Hack Purple (@WeHackPurple).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Tanya Janca (@shehackspurple)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast: https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
- Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Abisola Dayspring Johnson aka Day (@CyberwoxAcademy) is a Threat Analyst at Optiv (@Optiv) and the Founder of Cyberwox Academy helping aspiring CyberSecurity students to get into CyberSecurity.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Abisola Dayspring Johnson aka Day (@CyberwoxAcademy)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast: https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
- Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Cloud Security News this week - 22 September 2021
Episode Show Notes on Cloud Security Podcast Website.
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes, check out:
Cloud Security Podcast:
Cloud Security Academy:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Kaif Ahsan (@KaifAhsan1) is a Security Engineer at Atlassian (@Atlassian).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Kaif Ahsan (@KaifAhsan1)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast: https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
- Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Gerald Auger (@Linkedin- Gerald Auger) is a CyberSecurity PhD holder, Content Creator at Simply Cyber(@SimplyCyber) and a CyberSecurity Practitioner for over 15yrs .
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Gerald Auger (@Linkedin- Gerald Auger)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast: https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
- Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Cloud Security News this week - 15 September 2021
In this episode of the Virtual Coffee with Ashish edition, we spoke with Lisa Hall (@Lisa_H_), the Head of Security, PagerDuty(@PagerDuty).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Lisa Hall (@Lisa_H_)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast: https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
- Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Cloud Security News this week - 8 September 2021
In this episode of the Virtual Coffee with Ashish edition, we spoke with Zinet Kemal (Linkedin - Zinet-Kemal) is an Associate Cloud Security Engineer at Best Buy (@BestBuy)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: Zinet Kemal (Linkedin - Zinet-Kemal)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Podcast: https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
- Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Cloud Security News this week - 1 Sep, 2021
Follow us on @CloudSecPod
You may also like Cloud Security Podcast
In this episode of the Virtual Coffee with Ashish edition, we spoke with Igor Rincon (@igor.rincon) creator of Ultimate Hacking Championship (@HackingEsports) & one of the host of UHC - Magno Logan (@magnologan).
Link to Magno's Kubernetes Security Challenge walkthrough
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Twitter: Igor Rincon (@igor.rincon), Magno Logan (@magnologan)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
- Cloud Security Academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Karthik Prabhakar (@worldhopper) is an Advisor to AccuKnox (@AccuKnox).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: Karthik Prabhakar (@worldhopper)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Cloud Security News this week - 25 Aug, 2021
Follow us on @CloudSecPod
You may also like Cloud Security Podcast
In this episode of the Virtual Coffee with Ashish edition, we spoke with John Kinsella (@johnlkinsella) is a Cloud Native Contributor, co-host of Security Weekly and CTO of CySense.
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: John Kinsella (@johnlkinsella)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Colby Funnel (Linkedin - @Colby) is a Development Manager at Atlassian(@Atlassian).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: Colby Funnel (Linkedin - @Colby)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Omer Singer (Linkedin-Omer Singer) is the Head of Cyber Security Strategy at Snowflake - The Data Cloud (@SnowflakeDB).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Host Twitter: Ashish Rajan (@hashishrajan)
Guest Linkedin: Omer Singer (Linkedin-Omer Singer)
Podcast Twitter - Cloud Security Podcast (@CloudSecPod)
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ted Young (@tedsuo) is a contributor along with AWS, Google Cloud, Microsoft Azure in the Observability eco-system. He is also the Director of Developer Education at LightStep (@LightStepHQ)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Linkedin: Ted Young (@tedsuo)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Chris Hughes (Linkedin - Chris Hughes) & Dr. Nikki Robinson (Linkedin @dr-nikki-robinson) are the host of Resilient Cyber Podcast (@Resilient Cyber Podcast).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Linkedin: Chris Hughes (Linkedin - Chris Hughes) & Dr. Nikki Robinson (Linkedin @dr-nikki-robinson)
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ely Khan (@elykahn) is the Principal Product Manager at AWS (@AWS).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Linkedin: @elykahn
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Scott Piper (@0xdabbad00) is a AWS Security Legend who has written AWS Security tools for the community and among other things is a Consultant and Trainer at Summit Route..
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Linkedin: @0xdabbad00
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Patrick Pushor (@CloudChronicle) is the Technical Evangelist at Orca Security (@OrcaSec).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Linkedin: @CloudChronicle
Podcast Twitter - @kaizenteq
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Srinath Kuruvadi (@Srinath Kuruvadi) is the Head of Cloud Infrastructure Security at Netflix (@Netflix).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Linkedin: @Srinath Kuruvadi
Podcast Twitter - @kaizenteq
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Chris Cochran (@chriscochrcyber) and Ronald Eddings (@ronaldeddings) are the host of a CyberSecurity Podcast called Hacker Valley Studio (@TheHackerValley).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Twitter: @TheHackerValley
Podcast Twitter - @kaizenteq
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Kat Traxler (@nightmarejs) is the Cloud Security Engineering Lead, Best Buy(@BestBuy).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: @hashishrajan
Guest Twitter: @nightmarejs
Podcast Twitter - @kaizenteq
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jack Rhysider (@jackrhysider) is the host of Award Winning CyberSecurity Podcast Darknet Diaries (@DarknetDiaries).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/JackRhysider
Podcast Twitter - @kaizenteq
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this Mid Week special episode of the CISO Perspective edition, we spoke with Andy Ellis (@csoandy) is the Operating Partner at YL Ventures (@YLVentures) and the ex-CISO of Akamai (@Akamai).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/csoandy
Podcast Twitter - @kaizenteq
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Dylan Ayrey (@insecurenature) is a Professional Hacker and Co-Founder of Truffle Security (@TruffleSecurity-Linkedin)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/insecurenature
Podcast Twitter - @kaizenteq
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our YouTube Channel:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Brad Geesaman (@bradgeesaman) is a Senior Cloud Native and Kubernetes Security Professional and the Co- Founder of Darkbit (@Darkbit).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: @bradgeesaman
Podcast Twitter - @kaizenteq
If you want to watch videos of this episode and past CSP episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Dan “POP“ Papandrea (@danpopnyc) is the CNCF Ambassador, Director of Open Source Community and Ecosystem (@sysdig) and Podcast Host for @PopcastPop
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/danpopnyc
Podcast Twitter - @kaizenteq
If you want to watch videos of this episode and past CSP episodes:
In this Study Hall - Ashish goes through Kubernetes Components to start understanding the Kubernetes Architecture
READ the Multi-part Medium Article here - Ultimate Guide to Kubernetes Security
For Similar Topics covered in other episode of Cloud Security Podcast visit: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Podcast Twitter - @kaizenteq
To ASK questions from our Guest SUBSCRIBE TO OUR YOUTUBE LINK HERE to JOIN our next LIVE STREAM - : https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
In this episode of the Virtual Coffee with Ashish edition, we spoke with Magno Logan (@MagnoLogan) is the Security Researcher, Trend Micro(@TrendMicro)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/magnologan
Podcast Twitter - @kaizenteq
If you want to watch videos of this episode and past CSP episodes:
In this Study Hall - Ashish goes through Kubernetes Components to start understanding the Kubernetes Architecture
READ the Multi-part Medium Article here - Ultimate Guide to Kubernetes Security
For Similar Topics covered in other episode of Cloud Security Podcast visit: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Podcast Twitter - @kaizenteq
To ASK questions from our Guest SUBSCRIBE TO OUR YOUTUBE LINK HERE to JOIN our next LIVE STREAM - : https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
In this episode of the Virtual Coffee with Ashish edition, we spoke with Mark Manning (@antitree) is the Principal Security Architect at Snowflake(@SnowflakeDB). Before this he used to run Kubernetes Risk Analysis at NCC Group (@NCCSECURITYUS)
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/antitree
Podcast Twitter - @kaizenteq
If you want to watch videos of this and previous episodes:
In this Study Hall - Ashish goes through WHAT IS Kubernetes? What Kubernetes is NOT? & Should you start refactoring or building infrastructure in Kubernetes today?
For Similar Topics covered in other episode of Cloud Security Podcast visit: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/itascode
Podcast Twitter - @kaizenteq
To ASK questions from our Guest SUBSCRIBE TO OUR YOUTUBE LINK HERE to JOIN our next LIVE STREAM - : https://www.youtube.com/c/cloudsecuritypodcast?sub_confirmation=1
In this episode of the Virtual Coffee with Ashish edition, we spoke with Madhu Akula (@madhuakula) is an international Kubernetes Security Public Speaker, Black Hat Trainer, Creator of open source repo Kubernetes Goat, Security Researcher and Security Engineering at Miro (Miro).
Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/madhuakula
Podcast Twitter - @kaizenteq
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Geoff Belknap (@geoffbelknap) is the Chief Security Officer of Linkedin (@LinkedIn).
In this episode, Geoff & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
In this Study Hall - Kelsey Hightower explains is it really complex to learn Kubernetes and whether it's really complex. Nothing but the Honest Trust from Kelsey on this episode.
Full Episode on Cloud Security Podcast: www.cloudsecuritypodcast.tv
Cloud Security Academy: www.cloudsecuritypodcast.tv/cloud-security-academy
Host Twitter: twitter.com/hashishrajan
Guest Twitter: twitter.com/kelseyhightower
Podcast Twitter - @kaizenteq
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ashwin Patil (@ashwinpatil) who is a returning guest from Season 1 of the Cloud Security Podcast. Ashwin is a Senior Program Manager at Microsoft (@Microsoft).
Last time Ashwin came to speak about Threat Intelligence in Azure - Click here to checkout the Season 1 Episode here.
In this episode, Ashwin & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ohad Maishlish is the CEO & Co-Founder of env0.
In this episode, Ohad & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Kelsey Hightower (@kelseyhightower) is the Staff Advocate at Google Cloud (@GoogleCloud) and co-author of “Kubernetes: Up and Running: Dive Into the Future of Infrastructure.”
In this episode, Kelsey & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Yoni Leitersdorf (@yonadavl) who is the CEO & Co-Founder of Indeni
In this episode, Yoni & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with John Savill (Linkedin_John Savill) is the Principal Cloud Architect, Author and YouTuber.
In this episode, John & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Barak Schoster Goihman (@barakschoster) is the Co-Founder and CTO of Bridgecrew (@Bridgecrewio).
In this episode, Barak & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
In this episode of the Virtual Coffee with Ashish edition, we spoke with Toni de la Fuente (@toniblyx) is the Senior Security Consultant at AWS (@AWSCloud) and author of Prowler - AWS Security Tool.
In this episode, Toni & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Nicholas McLaren (Linkedin - nmclarencys) is the Cloud Security Engineer, ByteChek(@Bytechek).
In this episode, Nick & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Michael Fraser (@itascode) is the Chief Architect, Co-Founder at refactr (@RefactrIT).
In this episode, Michael & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Ben Tomhave (Linkedin - @btomhave) is the Principal, Falcon’s View Consulting (@FalconsView).
In this episode, Ben & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Zane Lackey, CISO & Co-Founder Signal Sciences, which is now owned by Fastly.
In this episode, Zane & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Kurt John,Chief CyberSecurity Officer CISO at Siemens USA
In this episode, Kurt & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with David Lavezzo,Director of Security Chaos Engineering at Capital One
In this episode, David & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Brianna Malcolmson, Security Engineering Manager, Atlassian
In this episode, Brianna & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Matt Johnson, Developer Advocate Lead, Bridgecrew.
In this episode, Matt & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Pawel Rzepa, Snr Security Consultant, SecuRing.
In this episode, Pawel & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Sriya Potham, Principal Cloud Security Architect
In this episode, Sriya & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this Christmas special episode of the Virtual Coffee with Ashish edition, we had a panel of successful CyberSecurity Podcast Hosts that answered questions about starting and running a successful CyberSecurity Podcast.
Panel Participants:
In this episode, Ashish & Panelist spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Youtube Channel: https://lnkd.in/gUHqSai
Twitch Channel: https://lnkd.in/gxhFrqw
In this episode of the Virtual Coffee with Ashish edition, we spoke with Monica Verma, CISO
In this episode, Monica & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Sam Small, Chief Security Officer, Zerofox
In this episode, Sam & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Matthew Fuller, co-Founder CloudSploit, Aqua
In this episode, Matthew & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Melissa Benua, Director of Engineering
In this episode, Melissa & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Naomi Buckwalter
In this episode, Naomi & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Casey Ellis
In this episode, Casey & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Daniel Miessler
In this episode, Daniel & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Houston Hopkins, Director CyberSecurity, Capital One
In this episode, Houston & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Caleb Sima, VP - Security, Databricks
In this episode, Caleb & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Jerome Walter, Security Modernisation, Director, VMWare
In this episode, Jerome & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition for Cloud Security Podcast, we spoke with Alexander J Yawn - ISC2 Miami Board Member | NABCRMP Founding Board Member
In this episode, AJ & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Alexandre Sieira - Founder @ Tenchi Security
In this episode, Alex & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with David O’Brien, MVP Azure , Argos Founder
In this episode, David & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Gaurav Kumar, co-founder of RedLock (now part of Palo Alto Prisma Cloud).
In this episode, Gaurav & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Darpan Shah, Cloud Security Engineer. Darpan has 8 AWS Certificates, 6 GCP certificates and at his work, he works on both Google Cloud and AWS.
In this episode, Darpan & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Nicholas Hughes, CEO of EITR Technologies.
In this episode, Nicholas & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Clint Gibler
In this episode, Clint & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Tanya Janca, Founder, SheHacksPurple & WeHackPurple.
Tanya & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Aaron Rinehart, CTO Co-Founder Verica.
This is episode not to miss.
Aaron & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Parul Kharub, CISSP, HMM. Parul has spent number of years in the Operational Technology (OT) space building cybersecurity strategy and if you in the OT space or want to do cybersecurity in this space.
This is episode not to miss.
Parul & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch videos of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Abbas Kudrati, CyberSecurity Advisor for Microsoft Asia Pacific Region. Abbas has previously worked in various large companies as a CISO and continues to share and support Microsoft Azure customers understand security in a world of cloud. This is episode not to miss.
Abbas & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch video of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Darpan Shah, Cloud Security Engineer. Darpan has 8 AWS Certificates, 6 GCP certificates and at his work, he works on both Google Cloud and AWS. This is episode not to miss.
Darpan & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch video of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Christopher Hughes, CISSP, Cloud Security Engineer.
Chris & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch video of this and previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Edwin Kwan, Head of Application and Software Security at Tyro payments.
Edwin & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch the previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Alannah Guo, Founder of 0xCC & Pentester.
Alannah & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch the previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode sponsored by Virtual Coffee with Ashish edition, we spoke with Francesco Cipollone, Chapter Chair (UK), Cloud Security Alliance
Francesco & Ashish spoke about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch the previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode sponsored by Virtual Coffee with Ashish edition, we spoke with Graeme Cantu-Park, CISO of Matilion
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
If you want to watch the previous episodes:
Twitch Channel: https://lnkd.in/gxhFrqw
Youtube Channel: https://lnkd.in/gUHqSai
In this episode of the Virtual Coffee with Ashish edition, we spoke with Alissa Knight, Car Hacker, Author, Cybersecurity Influencer and Entrepreneur
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @alissaknight
In this episode of the Virtual Coffee with Ashish edition, we spoke with Tim Heckman, Sr. SRE Netflix.
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @theckman
In this episode of the Virtual Coffee with Ashish edition, we spoke with @Taylor Hersom about
ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
In this episode, we sit with Chris Cochran & Ronald Eddings from Hacker Valley Studio.
Chris Cochran & Ronald Eddings from Hacker Valley Studio & Ashish spoke about
More info and show notes transcript on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @theHackerValley @chriscochrcyber @ronaldeddings
In this episode, we sit with Abhay Bhargav,CTO, we45.
Abhay & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @abhaybhargav
In this episode, we are covering a trending topic CORONAVIRUS OR COVID19 and how it is affecting businesses around me and my friends & colleagues. I also talk about my personal challenge with starting a new job in this COVID world with a remote team.
I hope you are reaching out to your friends and family to check on them and staying indoors to keep the community safe too.
You can reach me on ashish@kaizenteq.com
Ashish's Website: www.ashishrajan.com
Previous episodes videos are available on www.cloudsecuritypodcast.tv
In this episode, we sit with Merritt Baer,Principal Security Architect, AWS.
Merritt & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @merrittbaer
In this episode, we sit with Michael Fuller,Cloud Centre of Excellence, Atlassian.
Michael & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan Michael Fuller
In this episode, we sit with Fareedah Shaheed, Online Safety and Security Strategist @Sekuva.
Fareedah & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @cyberfareedah
In this episode, we sit with Will Bengtson, Director for Threat Detection and Response, Hashicorp.
Will & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @WillBengtson(__muscles)
In this episode, we sit with David Linthicum, Chief Cloud Strategy Officer for Delloite.
David & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @DavidLinthicum
In this episode, we sit with Taylor Hersom, vCISO, Austin,Texas.
Taylor & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @taylorhersom
Michael Hausenblas is a Product Developer Advocate, Amazon Web Services (AWS) Container Service team.
Michael & Ashish spoke about
More details in the podcast. More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan Michael Hausenblaus - Twitter @mhausenblas
Ashwin Patel is a Senior Program Manager, Threat Intelligence Microsoft.
Ashwin & Ashish in this episode spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @ashwinpatil
David & Ashish spoke about
More info and show notes on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @david_obrien
In this episode we speak to Francesco Cipollone, Head of Cloud Security Alliance for UK
Francesco and Ashish speak about is public cloud secure and if multi-cloud is a good thing, especially if you are starting out.
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @Frances07789950
In this episode we speak to Stu Hirst, Principal Cloud Security @Just Eat.
Stu and Ashish speak about keeping up security in a world of multi cloud, the challenges of recruiting for cloud security, what should people who are starting today in cloud security focus on .
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @stuhirstinfosec
This episode is a non-sponsored episode which is recording from Ashish's recent visit to Tokyo, Japan. During the trip Ashish caught up with mixed group of cybersecurity professionals who have been working in the public cloud space for some time in Tokyo with some of big companies in Tokyo.
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan
In this episode, we sit with Tanya Janca, previously Senior Cloud Advocate at Microsoft.
Tanya & I spoke about the right way to do move workloads to Azure with DevOps. We compared notes on AWS and Azure and Google Cloud. Tanya also busted some myths when it comes to migrating any workload in any cloud.
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @shehackspurple
In this episode, we sit with Jay Kelath, Director for Product Security at Dow Jones.
Jay & I spoke about the Dow Jones breach and how things changed from top down in Dow Jones for the better. We spoke about security lost trust of engineering by trusting security vendors and then How security won the trust of engineering back. The teams together were able to build lot of devops friendly security tools which was open sourced for others to reap benefits from it too.
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @kelath
In this episode, we sit with Jane Frankland, an award-winning entrepreneur, best-selling author and international speaker. Jane is a CISO advisor and has a diverse background, from being nominated as a Young British Designer after graduating to building my own global hacking firm and becoming a board advisor, awards judge, awards winner, LinkedInTop Voices and a top 20 cybersecurity global influencer. Jane has been a champion in enabling organisation to attract female talent in cybersecurity roles. Jane also is a huge advocate of mentoring women to get into a cyber security role.
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @janefrankland
In this Blue team episode, we sit with Vandana Verma, a Board member of OWASP and was recently awarded “Top influencers in Security and Fire” and “Cybersecurity Women of the year award by Women Cyberjutsu Society in the Category “Secure Coder”. We talk about Cloud Security in public cloud, the myths in cloud security incidents and mistakes she sees people do.
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @InfosecVandana
In this DevSecOps in AWS episode, we sit with Arjen Schwarz the host of Ambassador Lounge Podcast and review the security releases from AWS Re:invent 2019 and what it means for DevOps teams and security teams who are currently working together or planning to work together.
ShowNotes for the episode can be found on www.cloudsecuritypodcast.tv
Twitter - @kaizenteq @hashishrajan @ArjenSchwarz
Hey what’s up everyone! This is Ashish! I am a sysadmin turned cloud security guy with strange opinion on cyber security in the new world of cloud, containers, serverless and whatever comes next. I am also your host of Cloud Security podcast, a podcast where every episode I sit down and talk with cloud security practitioners on the challenges they face in public cloud and get into as much detail as possible on how they tackled.
The podcast is for security enthusiast and practitioners who are interested in how security can work in public cloud and how some of the most successful organisation are solving doing security at scale.
Talk to you in our next episode. :)
Podcast Website: www.cloudsecuritypodcast.tv