Anton Chuvakin
Cloud Security Podcast by Google
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps...
Author
Anton Chuvakin
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
EP60 Impersonating Service Accounts in GCP and Beyond: Cloud Security Is About IAM? 11.04.2022 30:31
Guest: Dylan Ayrey , cofounder of Truffle Security Topics: Could you explain briefly why identity is so important in the cloud? A skeptic on cloud security once told us that "in the cloud, we are one identity mistake from a breach." Is this true? For listeners who aren't familiar with GCP, could you give us the 30 second story on "what is a service account." How is it different from a regular IAM...
EP59 Zero Trust: So Easy Even a Government Can Do It? 04.04.2022 27:38
Guest: Sharon Goldberg , CEO and cofounder of BastionZero and a professor at Boston University Topics: What is your favorite definition of zero trust? You had posted a blog analyzing the whitehouse ZT a memo on the federal government's transition to "zero trust", what caught your eye about the Zero Trust memo and why did you decide to write about it? What's behind the federal government's recomm...
EP0 New Audio Trailer: Cloud Security Podcast by Google 28.03.2022 1:15
New Audio Trailer: Cloud Security Podcast by Google
EP58 SOC is Not Dead: How to Grow and Develop Your SOC for Cloud and Beyond 28.03.2022 28:04
Guests: Alexi Wiemer, Senior Manager at Deloitte Cyber Detection and Response Practice Dan Lauritzen, Senior Manager at Deloitte Cloud Security Practice. Topic s: What is your key learning about the state of SOC today? What one SOC trend are you hearing the most or most interested in? What is your best advice to SOCs that are permanently and woefully understaffed? Many SOC analysts are drowni...
EP57 Stop Zero Days, Save the World: Project Zero's Maddie Stone Speaks 21.03.2022 25:24
Guest: Maddie Stone , Security Researcher @ Google Topics: How do we judge the real risk of being attacked using an exploit for a zero day vulnerability? Does the zero day risk vary by company, industry, etc? What does pricing for zero days tell us, if anything? Are prices more driven by supply or demand these days? What security controls or defenses are useful against zero days including against...
EP56 Rebuilding vs Forklifting and How to Secure a Data Warehouse in the Cloud 14.03.2022 25:42
Guest: Erlander Lo , Security and Compliance Specialist @ Google Cloud Topics: Imagine you are planning a data warehouse in the cloud, how do you think about security? What are the expected threats to a large data store in the cloud? How to create your security approach for a data warehouse project? Are there regulations that force your decisions about security controls or approaches, no matter...
EP55 The Magic of Cloud Migration: Learn Security Lessons from the Field 07.03.2022 26:50
Guests: Brandie Anderson, Global Security Practice Lead @ Google Cloud Renzo Cuadros, Regional Security Practice Lead @ Google Cloud Topics: What are your Cloud migration security lessons? Greatest hits? Near misses? What are the most common cloud security mistakes you see? Any practices or tricks to avoid or mitigate them? How do you talk people out of security "lift and shift"? Do clients under...
EP54 Container Security: The Past or The Future? 28.02.2022 24:14
Guest: Anna Belak , Director of Thought Leadership @ Sysdig Topics: One model for container security is "Infrastructure security | build security | runtime security" - which is most important to get right? Which is hardest to get right? How are you helping users get their infrastructure security right, and what do they get wrong most often here? Your report states that "3⁄4 of running contain...
EP53 Seven Years of SOAR: What's Next? 22.02.2022 23:25
Guest: Amos Stern , CEO of SIEMplify, now part of Google Cloud Topics: SOAR is in the news again , so what can we say about the state of SOAR in 2022? What have we learned trying to get SOAR adopted 2015-2022 (that's 7 years of SOAR-ing for you)? What are the top playbooks to start your SOC automation using SOAR? What about the links between SOAR as security automation and general IT automation...
EP52 Securing AI with DeepMind CISO 14.02.2022 22:49
Guest: Vijay Bolina , CISO at DeepMind Topics: We spend a lot of time on Artificial Intelligence (AI) safety, but what about security? What are some of the useful frameworks for thinking about AI security? What is different about securing AI vs securing another data-intensive, complex, enterprise application? What do we know about threat modeling for AI applications? What attacks against AI syste...
EP51 Policy Intelligence: More Fun and Useful than it Sounds! 07.02.2022 24:33
Guest: Vandy Ramadurai , Product Manager at Google Cloud Topics: What is Cloud Organization Policy , and how is it different from IaC and Policy as code (PaC)? What does successful organization policy design look like from a business and human standpoint? From a technical standpoint? Granular policy work is always hard. How is Google helping users get org policy right? What are the uniquely Go...
EP50 The Epic Battle: Machine Learning vs Millions of Malicious Documents 31.01.2022 30:47
Guest: Elie Bursztein , security, anti-abuse and privacy researcher @ Google Topics: This episode draws on a talk available in the podcast materials . Could you summarize the gist of your talk for the audience? What makes the malicious document problem a good candidate for machine learning (ML)? Could you have used rules? "Millions of documents in milliseconds," not sure how to even parse it - wha...
EP49 Lifesaving Tradeoffs: CISO Considerations in moving Healthcare to Cloud 24.01.2022 27:15
Guest: Taylor Lehmann, Director at the Office of the CISO @ Google Cloud , member of Cybersecurity Action Team Topics: What's top of mind for healthcare organizations' CISOs now? What common advice do you find yourself giving most often to security leaders in healthcare? Is there a list of top 3 items or is this all "it depends"? What regulations are shaping the healthcare industry and its adopti...
EP48 Confidentially Speaking 2: Cloudful of Secrets 18.01.2022 29:55
Guest: Nelly Porter, Group Product Manager @ Google Cloud Topics In the past year, what has changed with Confidential Computing here at Google ? Could we please talk about a user or two who has really nailed it with our Confidential Computing? What have we learned about the threat models of clients who are choosing to deploy Confidential Computing? What are they solving for? Doing Confidential Co...
EP47 Megatrends, Macro-changes, Microservices, Oh My! Changes in 2022 and Beyond in Cloud Security 11.01.2022 26:09
Guest: Phil Venables (@ philvenables ), Vice President, Chief Information Security Officer (CISO) @ Google Cloud Topics: Explain the whole cloud security megatrend concept to us? How can we better explain that "yes, cloud is more secure than most client's data centers"? Can you please explain "shared fate" one more time? Shared fate seems to require shared incentives. Do we see the incentives to i...
EP46 Products and Solutions: Helping Our Customers Precipitate Change 06.12.2021 22:47
Guests: Alison Reyes , Director, Security Solutions, Google Cloud Iman Ghanizada , Solutions Manager for Security Operations & Analytics @ Google Cloud Topics: What is our thinking on solutions vs products for security? Sure, "security is a process, not a product," but where do solutions fit in? Security as an industry has too many vendors with little understanding of how users secure things, can...
EP45 VirusTotal Insights on Ransomware Business and Technology 29.11.2021 22:59
Guests: Vlad Stolyarov , Security Engineer @ Threat Analysis Group (TAG) Vicente Diaz , Threat Intelligence Strategist @ VirusTotal Topics: Why GandCrab / REvil was the most popular ransomware family in 2020? What is ransomware as a service? Is every scary article about ransomware essentially marketing for the criminals? Some ransomware payoffs are huge, how do you think they spend the money? H...
EP44 Evolving a SIEM for the Future While Learning from the Past 22.11.2021 28:16
Guest: Mike Orosz , a Chief Information and Product Security Officer @ Vertiv Topics: What are your views on modern SIEM? What should it do and what should it be? Should it even be called SIEM? Is SaaS/cloud-native SIEM the only way to go? Can anybody build a SIEM in the cloud by installing the regular SIEM on IaaS? What are the top challenges for organizations deploying and operationalizing SIE...
EP43 Automation as Paved Roads in Cloud Enablement 15.11.2021 23:13
Guests: Amber Shafi, Production Manager GSK Svetlin Zamfirov, Senior Platform Engineer at GSK Ivan Angelov, Principal Platform Engineer at GSK Topics: Tell us about your team, what are you responsible for and how is the team setup to make that happen? What components of cloud security do you cover? Tell us about cloud misconfigurations and why these are different from on- premise misconfiguration?...
EP42 Missing Diversity Hurts Your Security 08.11.2021 23:43
Guest: MK Palmore , Director at Office of the CISO, Google Cloud, member of Cybersecurity Action Team Topics: Why is there such a huge gap in security professionals who are women and people of color? How does the lack of women and people of color in tech impact the industry, cybersecurity & tech overall? Are diverse teams better performing, better morale, happier people? Are there kinds of threat...
EP41 Beyond Phishing: Email Security Isn't Solved 01.11.2021 23:49
Guest: Ryan Noon , CEO @ Material Security Topics: When we think about traditional email security, we think anti-spam/phishing. Your company is doing other things, so what are they? In other words, isn't email security solved with legacy appliance vendors (SEG) and cloud email providers? What was the combination of technology and security opportunities that really resonated with you and your inve...
EP40 2021: Phishing is Solved? 25.10.2021 31:49
Guests Elie Bursztein , security, anti-abuse and privacy researcher @ Google Kurt Thomas, security, anti-abuse and privacy researcher @ Google Topics: Can we say that "Multi-Factor Authentication - if done well - fixes phishing for good" or is this too much to say? What are the realistic and seen-in-the-wild bypasses for MFA as a protection? How do you think these controls fare vs top tier attacke...
EP40 2021: Phishing is Solved? 25.10.2021 31:49
Guests Elie Bursztein , security, anti-abuse and privacy researcher @ Google Kurt Thomas, security, anti-abuse and privacy researcher @ Google Topics: Can we say that "Multi-Factor Authentication - if done well - fixes phishing for good" or is this too much to say? What are the realistic and seen-in-the-wild bypasses for MFA as a protection? How do you think these controls fare vs top tier attacke...
EP39 From False Positives to Karl Popper: Rationalizing Cloud Threat Detection 18.10.2021 30:46
Guest: Jared Atkinson , Adversary Detection Technical Director at SpecterOps Topics: What are bad/good/great detections? Is this all about the Bianco's pyramid? Is high good and low bad? How should we judge the quality of detections? Can there be a quality framework? Is that judgment going to be site specific? What should we do to build more good directions? Is this all about reducing false positi...
NEXT Special - 6 Cloud Security PMs (and a Developer Advocate!) Walk into a Studio 14.10.2021 31:23
Guests: Stephanie Wong Vicente Diaz, Jerome McFarland Scott Ellis Patrick Faucher Il-Sung Lee, Anoosh Saboori Topics: What is your session about? Why would audience care? What is special about your security technology? Resources: Google Cloud Next 2021 SEC212 6 layers of GCP data center security SEC101 Ransomware and cyber resilience SEC204 Take charge of your sensitive data SEC207 Securing the s...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.