Cloud Security Podcast by Google

De: Anton Chuvakin
  • Resumen

  • Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit. We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.
    Copyright Google Cloud
    Más Menos
Episodios
  • EP221 Special - Semi-Live from Google Cloud Next 2025: AI, Agents, Security ... Cloud?
    Apr 23 2025

    Guests:

    • No guests [Tim in Vegas and Anton remote]

    Topics:

    • So, another Next is done. Beyond the usual Vegas chaos, what was the overarching security theme or vibe you [Tim] felt dominated the conference this year?
    • Thinking back to Next '24, what felt genuinely different this year versus just the next iteration of last year's trends?
    • Last year, we pondered the 'Cloud Island' vs. 'Cloud Peninsula'. Based on Next 2025, is cloud security becoming more integrated with general cyber security, or is it still its own distinct domain?
    • What wider trends did you observe, perhaps from the expo floor buzz or partner announcements, that security folks should be aware of?
    • What was the biggest surprise for you at Next 2025? Something you absolutely didn't see coming?
    • Putting on your prediction hats (however reluctantly): based on Next 2025, what do you foresee as the major cloud security focus or challenge for the industry in the next 12 months?
    • If a busy podcast listener listening could only take one key message or action item away from everything announced and discussed at Next 2025, what should it be?

    Resources:

    • EP169 Google Cloud Next 2024 Recap: Is Cloud an Island, So Much AI, Bots in SecOps

    Más Menos
    30 m
  • EP220 Big Rewards for Cloud Security: Exploring the Google VRP
    Apr 21 2025

    Guests:

    • Michael Cote, Cloud VRP Lead, Google Cloud
    • Aadarsh Karumathil, Security Engineer, Google Cloud

    Topics:

    • Vulnerability response at cloud-scale sounds very hard! How do you triage vulnerability reports and make sure we’re addressing the right ones in the underlying cloud infrastructure?
    • How do you determine how much to pay for each vulnerability? What is the largest reward we paid? What was it for?
    • What products get the most submissions? Is this driven by the actual product security or by trends and fashions like AI?
    • What are the most likely rejection reasons?
    • What makes for a very good - and exceptional? - vulnerability report? We hear we pay more for “exceptional” reports, what does it mean?
    • In college Tim had a roommate who would take us out drinking on his Google web app vulnerability rewards. Do we have something similar for people reporting vulnerabilities in our cloud infrastructure? Are people making real money off this?
    • How do we actually uniquely identify vulnerabilities in the cloud? CVE does not work well, right?
    • What are the expected risk reduction benefits from Cloud VRP?

    Resources:

    • Cloud VRP site
    • Cloud VPR launch blog
    • CVR: The Mines of Kakadûm
    Más Menos
    29 m
  • EP219 Beyond the Buzzwords: Decoding Cyber Risk and Threat Actors in Asia Pacific
    Apr 14 2025

    Guest:

    • Steve Ledzian, APAC CTO, Mandiant at Google Cloud

    Topics:

    • We've seen a shift in how boards engage with cybersecurity. From your perspective, what's the most significant misconception boards still hold about cyber risk, particularly in the Asia Pacific region, and how has that impacted their decision-making?
    • Cybersecurity is rife with jargon. If you could eliminate or redefine one overused term, which would it be and why? How does this overloaded language specifically hinder effective communication and action in the region?
    • The Mandiant Attack Lifecycle is a well-known model. How has your experience in the East Asia region challenged or refined this model? Are there unique attack patterns or actor behaviors that necessitate adjustments?
    • Two years post-acquisition, what's been the most surprising or unexpected benefit of the Google-Mandiant combination?
    • M-Trends data provides valuable insights, particularly regarding dwell time. Considering the Asia Pacific region, what are the most significant factors reducing dwell time, and how do these trends differ from global averages?
    • Given your expertise in Asia Pacific, can you share an observation about a threat actor's behavior that is often overlooked in broader cybersecurity discussions?
    • Looking ahead, what's the single biggest cybersecurity challenge you foresee for organizations in the Asia Pacific region over the next five years, and what proactive steps should they be taking now to prepare?

    Resources:

    • EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant
    • EP156 Living Off the Land and Attacking Critical Infrastructure: Mandiant Incident Deep Dive
    • EP191 Why Aren't More Defenders Winning? Defender’s Advantage and How to Gain it!

    Más Menos
    32 m
adbl_web_global_use_to_activate_webcro768_stickypopup

Lo que los oyentes dicen sobre Cloud Security Podcast by Google

Calificaciones medias de los clientes

Reseñas - Selecciona las pestañas a continuación para cambiar el origen de las reseñas.