Anton Chuvakin
Cloud Security Podcast by Google
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps...
Author
Anton Chuvakin
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
NEXT Special - Google Cybersecurity Action Team: What's the Story? 13.10.2021 20:48
Guest: Phil Venables ( @philvenables ), Vice President, Chief Information Security Officer (CISO) @ Google Cloud Topics: We are here to talk Google Cybersecurity Action Team , and this is your brainchild, so tell our audience the origin of this idea? How is Cybersecurity Action Team going to help secure GCP enterprise clients? Is there also a "improve the security of the internet" story? Many orga...
NEXT Special - Cloud Security and DEI: Being an Ally! 12.10.2021 19:01
Guest: Aditi Joshi, Manager in Cloud Security Team @ Google Cloud Topics: What is Allyship? How is it defined? What is its main goal? Why is allyship important in Cloud Security, specifically? Are there aspects of security that make allyship particularly important? What specifically has Google Cloud Security deployed and operationalized around Allyship? How does effective allyship look like? More...
NEXT Special - Google Cloud NEXT Security: What to Watch? 11.10.2021 20:55
Guest: Rob Sadowski, Trust and Security Lead @ Google Cloud Topics: What are the big security themes at NEXT? Is security still visible? What about invisible security vs autonomic security? Is that just "invisible security" with a neat name? This has got to be your fourth or fifth Next, right? What's new this year compared to last years, aside from being virtual? Anything particularly uniquely Go...
EP34 Instrumenting Modern Application Stack for Detection and Response 04.10.2021 25:01
Guest: Matt Svensson, Senior Security Engineer @ BetterCloud Topics: What are the approaches for monitoring serverless and other modern application architectures? What are the challenges with these new environments? What approaches don't work? What can go wrong with modern stack security monitoring? What should we watch for in a modern application stack? Most new architecture setups are predicated...
EP33 Cloud Migrations: Security Perspectives from The Field 27.09.2021 25:35
Guest: Elliott Abraham, Security and Compliance Specialist @ Google Cloud Topics: We talk about lift and shift vs cloud native, what are these and are they fair characterizations? Is lift and shift always negative? Does it always harm security? Are security planning needs different between them? What are the fundamentals with security during cloud migration that you have to get right regardless? W...
EP32 Can You Ever Know Thyself: Cloud Attack Surface Management 20.09.2021 23:39
Guest: Derek Abdine , CTO @ Censys.io Topics: Attack Surface Management (ASM). Why do we need a new toolset and a new category? Isn't this just 1980s asset management or CMDB? How do we find those assets that may have been misplaced by the organizations? How can any technology do this reliably? ASM seems to often rely on network layer 3 and 4. Can't bad guys just hit the app endpoints and all you...
EP31 Cloud Certifications, and Cloud Security with TheCertsGuy 13.09.2021 22:09
Guest: Iman Ghanizada , Solutions Manager for Security Operations & Analytics @ Google Cloud Topics: What is your book "Google Cloud Certified Professional Cloud Architect All-in-One Exam Guide " about? What was your journey into writing this book, how long did it take? The book seems to be targeted towards Cloud Architects, but you come from a predominantly security background, how has that in...
EP30 Malware Hunting with VirusTotal 07.09.2021 26:19
Guest: Vicente Diaz, Threat Intelligence Strategist @ VirusTotal Topics: How would you describe modern threat hunting process? Share some of the more interesting examples of attacker activities or artifacts you've seen? Do we even hunt for malware? What gets you more concerned, malware or human attackers? How do you handle the risk of attackers knowing how you perform hunting? What is the role of...
Future of EDR: Is It Reason-able to Suggest XDR? 30.08.2021 27:54
Guest: Sam Curry , Chief Security Officer @ Cybereason and Visiting Fellow @ National Security Institute Topics: EDR was "invented" in 2013 and we are now in 2021. What do you consider to be modern EDR components and c apabilities? Where has EDR fallen short on its initial hype? How focused are the attackers on bypassing EDR? How do you think EDR works in the cloud? In your view, how would futur...
Tales from the Trenches: Using AI for Gmail Security 23.08.2021 19:14
Guest: Andy Wen , Product Lead for Abuse & Security @ Google Cloud Topics: What are you doing with AI for security? What kinds of security problems are addressable with AI, and which ones are harder to address with ML techniques? Tell us where you've been surprised by AI's success? Do you expect a) AI use by adversaries and b) attacks focused on disrupting the AI use by defenders? What advice woul...
The Mysteries of Detection Engineering: Revealed! 16.08.2021 30:09
Guest: Keith McCammon , Co-founder and Chief Security Officer, Red Canary Topics: What is Detection Engineering? How it differs from just building rules/analytics? How to convert threat intelligence into detections? How to tell good detections from bad? And perhaps also good from great? How to test detections in the real world? Anything special about building detections for cloud environments? Wh...
SOC in a Large, Complex and Evolving Organization 09.08.2021 20:24
Guest: Johnathan Keith , Director of Information Security (CISO) @ ViacomCBS Streaming / Digital (at the time of the recording) Topics: What is the mission for your SOC? Has it evolved in recent years? How do you rate your state of maturity in security operations? I hear that your organization is complex and decentralized, how do you run a SOC in such a case? How do you approach the balance of pe...
Beyond Compliance: Cloud Security in Europe 02.08.2021 27:03
Guest: John Stone , Chaos Coordinator at the Office of the CISO @ Google Cloud Topics: What are the top European-specific cloud migration security challenges? Are there interesting cloud adoption barriers related to security in Europe? Are some of these challenges more compliance than security related? Do you think compliance still drives security in the cloud for European companies? Do you think...
Linking Up The Pieces: Software Supply Chain Security at Google and Beyond 26.07.2021 23:03
Guests: Eric Brewer , VP of Infrastructure, and Google Fellow @ Google Aparna Sinha , Director of Product Management @ Google Cloud Topics: What is software supply chain security and how is it different from other kinds of supply chain security? What types of organizations need to care about it? Is supply chain security a concern for large, elite enterprises only? What's the relationship between...
Threat Detection at Google Cloud Security Summit 19.07.2021 21:12
No guests. We interviewed each other! Topics: What would you say are the most things that Chronicle is trying to address today? What are the good ways to use threat intel to detect threats that do not ruin your SOC? What does "autonomic" security mean, anyway? Is this a fancy way of saying "automatic" or something more? For sure, "the Cloud is not JUST someone else's computer" - but how does this...
Securing Multi-Cloud from a CISO Perspective, Part 3 12.07.2021 24:13
Guests: Phil Venables (@ philvenables ), Vice President, Chief Information Security Officer (CISO) @ Google Cloud Dave Hannigan, Director, Financial Services Security & Compliance @ Google Cloud Topics: As a CISO, would you ever decide to use multiple clouds, if it were in your hands? How is security typically considered when companies go multi-cloud in their approach? Practically, or operation...
Security Marketing? Every Product Needs a Story! 06.07.2021 23:45
Guest: Kelly Anderson , Head of Product Marketing, User Protection Services @ Google Cloud Topics: What is marketing, really? Why is it sometimes reviled by the technologists? What makes a great marketer in cloud security? What's different about cloud security marketing, as opposed to regular old on-premise security marketing? Is there still FUD in the cloud? Which things are the easiest or hardes...
Security Operations, Reliability, and Securing Google with Heather Adkins 28.06.2021 28:27
Guest: Heather Adkins , Sr Director, Information Security @ Google Topics: Your RSA presentation has 3 pillars: zero trust, microservices, automation/zero prod, is this all you need to be secure & reliable in the modern world? Let's drill down again into the "secure and reliable" concept, are you sure that they are interrelated? Is there a risk that microservices could actually increase attack sur...
Double-clicking, but not on fire hydrants, with bot fighters 21.06.2021 34:04
Guest 1: Sparky Toews, Product Manager for Adobe identity @ Adobe Topics 1: Why are bots a problem to you? Give us a bit of your bot threat assessment? Can you tell us how you think about and practice securing the user experience? What kind of security products or best practices are involved? How do you see what security professionals do to secure the user experience evolving over time? Guests 2:...
More Cloud Migration Security Lessons 14.06.2021 32:04
Guests: Jane Chung, VP of Cloud @ Palo Alto Joe Crawford, Director of Strategic Technology Partnerships for Google Cloud @ Palo Alto Topics: What are the top security mistakes you've seen during cloud migrations? What is your best advice to security leaders who want to go to the cloud using the on-premise playbook? What security technologies may no longer be needed in the cloud? Which are transfor...
Modern Threat Detection at Google 07.06.2021 24:13
Guest: Julien Vehent , Security Engineering Manager in the Detection and Response team @ Google Topics: What is special about detecting modern threats in modern environments? How does the Google team turn the knowledge of threats into detection logic? Run through an example of creating a detection for a new threat? How do we test our detection rules? We use the same people to write detections and...
Modern Data Security Approaches: Is Cloud More Secure? 01.06.2021 28:15
Guests: Tim Dierks, Engineering Director, Data Protection @ Google Cloud Topics: What are the key components of data security in the public cloud today? Why do companies need specific data security plans and products? Do you think Google Cloud today has enough controls for processing the most sensitive data? Many organizations seem to be unaware of where sensitive data exists in their cloud enviro...
Scaling Google Kubernetes Engine Security 24.05.2021 20:48
Guest: Greg Castle, Senior Staff Security Engineer at Google Topics: How is kubernetes security different from traditional host security? What's different about securing GKE vs security Kubernetes on-prem? Where does one start with security hardening for GKE? In your view, what are top realistic threats to container deployments? What do users get wrong most often? Did we manage to make containers...
Making Compliance Cloud-native 19.05.2021 20:11
Guest: Zeal Somani, Security Solutions Manager @ Google Cloud, former PCI QSA Topics: What are the usable recipes for thinking about compliance in the cloud? What regulations are more challenging for public cloud users? How do you see the client/provider responsibility split for compliance? What is this "shift left" for compliance? How do we educate auditors and regulators who insist on 1980s solu...
Application Security in the Cloud 10.05.2021 24:55
Guest: Alyssa Miller , BISO @ S&P Global Ratings Topics: How do application security practices change as organizations launch their cloud transformations? What bad things happen to you if you lift/shift your big applications to somebody's IaaS? What unique challenges do containers and serverless deployments create for application security? Is there good news here? How can cloud native technologie...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.