Anton Chuvakin

Cloud Security Podcast by Google

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps...

Author

Anton Chuvakin

Category

Technology

Podcast website

cloud.withgoogle.com

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

EP235 The Autonomous Frontier: Governing AI Agents from Code to Courtroom 21.07.2025

Guest:  Anna Gressel , Partner at Paul, Weiss , one of the AI practice leads Episode co-host: Marina Kaganovich , Office of the CISO, Google Cloud Questions: Agentic AI and AI agents, with its promise of autonomous decision-making and learning capabilities, presents a unique set of risks across various domains. What are some of the key areas of concern for you? What frameworks are most relevant to...

EP234 The SIEM Paradox: Logs, Lies, and Failing to Detect 14.07.2025

Guest: Svetla Yankova , Founder and CEO, Citreno Topics: Why do so many organizations still collect logs yet don't detect threats? In other words, why is our industry spending more money than ever on SIEM tooling and still not "winning" against Tier 1 ... or even Tier 5 adversaries?  What are the hardest parts about getting the right context into a SOC analyst's face when they're triaging and inve...

EP233 Product Security Engineering at Google: Resilience and Security 07.07.2025

Guest: Cristina Vintila , Product Security Engineering Manager, Google Cloud Topic: Could you share insights into how Product Security Engineering approaches at Google have evolved, particularly in response to emerging threats (like Log4j in 2021)? You mentioned applying SRE best practices in detection and response, and overall in securing the Google Cloud products. How does Google balance high re...

EP232 The Human Element of Privacy: Protecting High-Risk Targets and Designing Systems 30.06.2025

Guest: Sarah Aoun , Privacy Engineer, Google Topic: You have had a fascinating career since we [Tim] graduated from college together – you mentioned before we met that you've consulted with a literal world leader on his personal digital security footprint. Maybe tell us how you got into this field of helping organizations treat sensitive information securely and how that led to helping keep target...

EP231 Beyond the Buzzword: Practical Detection as Code in the Enterprise 23.06.2025

Guest: David French , Staff Adoption Engineer, Google Cloud Topic: Detection as code is one of those meme phrases I hear a lot, but I'm not sure everyone means the same thing when they say it. Could you tell us what you mean by it, and what upside it has for organizations in your model of it? What gets better for security teams and security outcomes when you start managing in a DAC world? What is...

EP230 AI Red Teaming: Surprises, Strategies, and Lessons from Google 16.06.2025

Guest: Daniel Fabian , Principal Digital Arsonist, Google Topic: Your RSA talk highlights lessons learned from two years of AI red teaming at Google. Could you share one or two of the most surprising or counterintuitive findings you encountered during this process? What are some of the key differences or unique challenges you've observed when testing AI-powered applications compared to traditional...

EP229 Beyond the Hype: Debunking Cloud Breach Myths (and What DBIR Says Now) 09.06.2025

Guest: Alex Pinto ,  Associate Director of Threat Intelligence, Verizon Business, Lead the Verizon Data Breach Report Topics: How would you define "a cloud breach"? Is that a real (and different) thing?  Are cloud breaches just a result of leaked keys and creds? If customers are responsible for 99% of cloud security problems, is cloud breach really about a customer being breached ? Are misconfigur...

EP228 SIEM in 2025: Still Hard? Reimagining Detection at Cloud Scale and with More Pipelines 02.06.2025

Guest Alan Braithwaite , Co-founder and CTO @ RunReveal Topics: SIEM is hard, and many vendors have discovered this over the years. You need to get storage, security and integration complexity just right. You also need to be better than incumbents. How would you approach this now? Decoupled SIEM vs SIEM/EDR/XDR combo. These point in the opposite directions, which side do you think will win? In a w...

EP227 AI-Native MDR: Betting on the Future of Security Operations? 26.05.2025

Guests: Eric Foster , CEO of Tenex. AI Venkata Koppaka , CTO of Tenex. AI   Topics: Why is your AI-powered MDR special? Why start an MDR from scratch using AI? So why should users bet on an "AI-native" MDR instead of an MDR that has already got its act together and is now applying AI to an existing set of practices?  What's the current breakdown in labor between your human SOC analysts vs your AI...

EP226 AI Supply Chain Security: Old Lessons, New Poisons, and Agentic Dreams 19.05.2025

Guest: Christine Sizemore , Cloud Security Architect, Google Cloud   Topics: Can you describe the key components of an AI software supply chain, and how do they compare to those in a traditional software supply chain?  I hope folks listening have heard past episodes where we talked about poisoning training data. What are the other interesting and unexpected security challenges and threats associat...

EP225 Cross-promotion: The Cyber-Savvy Boardroom Podcast: EP2 Christian Karam on the Use of AI 14.05.2025

Hosts: David Homovich , Customer Advocacy Lead, Office of the CISO, Google Cloud  Alicja Cade , Director, Office of the CISO, Google Cloud  Guest:  Christian Karam , Strategic Advisor and Investor Resources: EP2 Christian Karam on the Use of AI (as aired originally) The Cyber-Savvy Boardroom podcast site The Cyber-Savvy Boardroom podcast on Spotify The Cyber-Savvy Boardroom podcast on Apple Podcas...

EP224 Protecting the Learning Machines: From AI Agents to Provenance in MLSecOps 12.05.2025

Guest: Diana Kelley , CSO at Protect AI   Topics: Can you explain the concept of "MLSecOps" as an analogy with DevSecOps, with 'Dev' replaced by 'ML'? This has nothing to do with SecOps, right? What are the most critical steps a CISO should prioritize when implementing MLSecOps within their organization? What gets better  when you do it? How do we adapt traditional security testing, like vulnerabi...

EP223 AI Addressable, Not AI Solvable: Reflections from RSA 2025 05.05.2025

Guests:  no guests, just us in the studio Topics: At RSA 2025, did we see solid, measurably better outcomes from AI use in security, or mostly just "sizzle" and good ideas with potential? Are the promises of an "AI SOC" repeating the mistakes seen with SOAR in previous years regarding fully automated security operations? Does "AI SOC" work according to RSA floor? How realistic is the vision expres...

EP222 From Post-IR Lessons to Proactive Security: Deconstructing Mandiant M-Trends 28.04.2025

Guests: Kirstie Failey @ Google Threat Intelligence Group Scott Runnels @ Mandiant Incident Response   Topics: What is the hardest thing about turning distinct incident reports into a fun to read and useful report like M-Trends ? How much are the lessons and recommendations skewed by the fact that they are all "post-IR" stories? Are "IR-derived" security lessons the best way to improve security? I...

EP221 Special - Semi-Live from Google Cloud Next 2025: AI, Agents, Security ... Cloud? 23.04.2025

Guests: No guests [Tim in Vegas and Anton remote] Topics: So, another Next is done. Beyond the usual Vegas chaos, what was the overarching security theme or vibe you [Tim] felt dominated the conference this year? Thinking back to Next '24, what felt genuinely different this year versus just the next iteration of last year's trends? Last year, we pondered the 'Cloud Island' vs. 'Cloud Peninsula'. B...

EP220 Big Rewards for Cloud Security: Exploring the Google VRP 21.04.2025

Guests: Michael Cote , Cloud VRP Lead, Google Cloud Aadarsh Karumathil , Security Engineer, Google Cloud Topics: Vulnerability response at cloud-scale sounds very hard! How do you triage vulnerability reports and make sure we're addressing the right ones in the underlying cloud infrastructure? How do you determine how much to pay for each vulnerability? What is the largest reward we paid? What was...

EP219 Beyond the Buzzwords: Decoding Cyber Risk and Threat Actors in Asia Pacific 14.04.2025

Guest: Steve Ledzian , APAC CTO, Mandiant at Google Cloud Topics: We've seen a shift in how boards engage with cybersecurity. From your perspective, what's the most significant misconception boards still hold about cyber risk, particularly in the Asia Pacific region, and how has that impacted their decision-making? Cybersecurity is rife with jargon. If you could eliminate or redefine one overused...

EP218 IAM in the Cloud & AI Era: Navigating Evolution, Challenges, and the Rise of ITDR/ISPM 07.04.2025

Guest: Henrique Teixeira , Senior VP of Strategy, Saviynt, ex-Gartner analyst Topics: How have you seen IAM evolve over the years, especially with the shift to the cloud, and now AI? What are some of the biggest challenges and opportunities these two shifts present?  ITDR (Identity Threat Detection and Response) and ISPM (Identity Security Posture Management) are emerging areas in IAM. How do you...

EP217 Red Teaming AI: Uncovering Surprises, Facing New Threats, and the Same Old Mistakes? 31.03.2025

Guest: Alex Polyakov , CEO at Adversa AI Topics: Adversa AI is known for its focus on AI red teaming and adversarial attacks. Can you share a particularly memorable red teaming exercise that exposed a surprising vulnerability in an AI system? What was the key takeaway for your team and the client? Beyond traditional adversarial attacks, what emerging threats in the AI security landscape are you mo...

EP216 Ephemeral Clouds, Lasting Security: CIRA, CDR, and the Future of Cloud Investigations 24.03.2025

Guest: James Campbell , CEO, Cado Security Chris Doman , CTO, Cado Security Topics: Cloud Detection and Response (CDR) vs Cloud Investigation and Response Automation( CIRA ) ... what's the story here? There is an "R" in CDR, right? Can't my (modern) SIEM/SOAR do that?  What about this becoming a part of modern SIEM/SOAR in the future? What gets better when you deploy a CIRA (a) and your CIRA in pa...

EP215 Threat Modeling at Google: From Basics to AI-powered Magic 17.03.2025

Guest: Meador Inge , Security Engineer, Google Cloud   Topics: Can you walk us through Google's typical threat modeling process? What are the key steps involved? Threat modeling can be applied to various areas. Where does Google utilize it the most? How do we apply this to huge and complex systems? How does Google keep its threat models updated? What triggers a reassessment? How does Google operat...

EP214 Reconciling the Impossible: Engineering Cloud Systems for Diverging Regulations 10.03.2025

Guest: Archana Ramamoorthy , Senior Director of Product Management, Google Cloud Topics: You are responsible for building systems that need to comply with laws that are often mutually contradictory. It seems technically impossible to do, how do you do this? Google is not alone in being a global company with local customers and local requirements. How are we building systems that provide local comp...

EP213 From Promise to Practice: LLMs for Anomaly Detection and Real-World Cloud Security 03.03.2025

Guest: Yigael Berger , Head of AI, Sweet Security Topic: Where do you see a gap between the "promise" of LLMs for security and how they are actually used in the field to solve customer pains? I know you use LLMs for anomaly detection. Explain how that "trick" works? What is it good for? How effective do you think it will be?  Can you compare this to other anomaly detection methods? Also, won't thi...

EP212 Securing the Cloud at Scale: Modern Bank CISO on Metrics, Challenges, and SecOps 24.02.2025

Guest: Dave Hannigan , CISO at Nu Bank Topics: Tell us about the challenges you're facing as CISO at NuBank and how are they different from your past life at Spotify? You're a big cloud based operation  - what are the key challenges you're tracking in your cloud environments?  What lessons do you wish you knew back in your previous CISO run [at Spotify]? What metrics do your team report for you to...

EP211 Decoding the Underground: Google's Dual-Lens Threat Intelligence Magic 17.02.2025

Guest: Kimberly Goody , Head of Intel Analysis and Production, Google Cloud Topics: Google's Threat Intelligence Group (GTIG) has a unique position, accessing both underground forum data and incident response information. How does this dual perspective enhance your ability to identify and attribute cybercriminal campaigns? Attributing cyberattacks with high confidence is important. Can you walk us...

Listen to the Cloud Security Podcast by Google podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.