Anton Chuvakin
Cloud Security Podcast by Google
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps...
Author
Anton Chuvakin
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
EP185 SAIF-powered Collaboration to Secure AI: CoSAI and Why It Matters to You 12.08.2024 24:27
Guest: David LaBianca , Senior Engineering Director, Google Topics: The universe of AI risks is broad and deep. We've made a lot of headway with our SAIF framework: can you give us a) a 90 second tour of SAIF and b) share how it's gotten so much traction and c) talk about where we go next with it? The Coalition for Secure AI (CoSAI) is a collaborative effort to address AI security challenges. W...
EP184 One Week SIEM Migration: Fact or Fiction? 05.08.2024 24:45
Guest: Manan Doshi , Senior Security Engineer @ Etsy Questions: In your experience, what are the biggest challenges organizations face when migrating to a new SIEM platform? How did you solve them? Many SIEM projects have problems, but a decent chunk of these problems are not about the tool being broken. How did you decide to migrate? When is it time to go? Specifically, how to avoid constan...
EP183 Cloud Security Journeys: Improve, Evolve, Transform with Cloud Customers 29.07.2024 30:15
Guests: Jaffa Edwards , Senior Security Manager @ Google Cloud Lyka Segura , Cloud Security Engineer @ Google Cloud Topics: Security transformation is hard , do you have any secret tricks or methods that actually make it happen? Can you share a story about a time when you helped a customer transform their cloud security posture? Not just improve, but actually transform! What is your process for...
EP182 ITDR: The Missing Piece in Your Security Puzzle or Yet Another Tool to Buy? 22.07.2024 28:20
Guest: Adam Bateman , Co-founder and CEO, Push Security Topics: What is Identity Threat Detection and Response ( ITDR )? How do you define it? What gets better at a client organization once ITDR is deployed? Do we also need "ISPM" (parallel to CDR/CSPM), and what about CIEM? Workload identity ITDR vs human identity ITDR? Do we need both? Are these the same? What are the alternatives to using ITDR...
EP181 Detection Engineering Deep Dive: From Career Paths to Scaling SOC Teams 15.07.2024 30:32
Guest: Zack Allen , Senior Director of Detection & Research @ Datadog, creator of Detection Engineering Weekly Topics: What are the biggest challenges facing detection engineers today? What do you tell people who want to consume detections and not engineer them? What advice would you give to someone who is interested in becoming a detection engineer at her organization? So, what IS a detection eng...
EP180 SOC Crossroads: Optimization vs Transformation - Two Paths for Security Operations Center 08.07.2024 28:09
Guests: Mitchell Rudoll , Specialist Master, Deloitte Alex Glowacki , Senior Consultant, Deloitte Topics: The paper outlines two paths for SOCs: optimization or transformation . Can you elaborate on the key differences between these two approaches and the factors that should influence an organization's decision on which path to pursue? The paper also mentions that alert overload is still a major...
EP179 Teamwork Under Stress: Expedition Behavior in Cybersecurity Incident Response 01.07.2024 23:28
Guests: Robin Shostack , Security Program Manager, Google Jibran Ilyas , Managing Director Incident Response, Mandiant, Google Cloud Topics: You talk about "teamwork under adverse conditions" to describe expedition behavior (EB). Could you tell us what it means? You have been involved in response to many high profile incidents, one of the ones we can talk about publicly is one of the biggest healt...
EP178 Meet Brandon Wood: The Human Side of Threat Intelligence: From Bad IP to Trafficking Busts 24.06.2024 32:09
Guest: Brandon Wood, Product Manager for Google Threat Intelligence Topics: Threat intelligence is one of those terms that means different things to everyone–can you tell us what this term has meant in the different contexts of your career? What do you tell people who assume that "TI = lists of bad IPs"? We heard while prepping for this show that you were involved in breaking up a human trafficki...
EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant 17.06.2024 30:07
Guests: Omar ElAhdan , Principal Consultant, Mandiant, Google Cloud Will Silverstone , Senior Consultant, Mandiant, Google Cloud Topics: Most organizations you see use both cloud and on-premise environments. What are the most common challenges organizations face in securing their hybrid cloud environments? You do IR so in your experience, what are top 5 mistakes organizations make that lead to cl...
EP176 Google on Google Cloud: How Google Secures Its Own Cloud Use 10.06.2024 27:00
Guest: Seth Vargo , Principal Software Engineer responsible for Google's use of the public cloud, Google Topics: Google uses the public cloud, no way, right? Which one? Oh, yeah, I guess this is obvious: GCP, right? Where are we like other clients of GCP? Where are we not like other cloud users? Do we have any unique cloud security technology that we use that others may benefit from? How does our...
EP175 Meet Crystal Lister: From Public Sector to Google Cloud Security and Threat Horizons 03.06.2024 26:43
Guest: Crystal Lister , Technical Program Manager, Google Cloud Security Topics: Your background can be sheepishly called "public sector", what's your experience been transitioning from public to private? How did you end up here doing what you are doing? We imagine you learned a lot from what you just described – how's that impacted your work at Google? How have you seen risk management practices...
EP174 How to Measure and Improve Your Cloud Incident Response Readiness: A New Framework 27.05.2024 21:33
Guest: Angelika Rohrer, Sr. Technical Program Manager , Cyber Security Response at Alphabet Topics: Incident response (IR) is by definition "reactive", but ultimately incident prep determines your IR success. What are the broad areas where one needs to prepare? You have created a new framework for measuring how ready you are for an incident, what is the approach you took to create it? Can you ela...
EP173 SAIF in Focus: 5 AI Security Risks and SAIF Mitigations 20.05.2024 33:16
Guest: Shan Rao , Group Product Manager, Google Topics: What are the unique challenges when securing AI for cloud environments, compared to traditional IT systems? Your talk covers 5 risks, why did you pick these five? What are the five, and are these the worst? Some of the mitigation seems the same for all risks. What are the popular SAIF mitigations that cover more of the risks? Can we move q...
EP172 RSA 2024: Separating AI Signal from Noise, SecOps Evolves, XDR Declines? 13.05.2024 27:20
Guests: None Topics: What have we seen at RSA 2024? Which buzzwords are rising (AI! AI! AI!) and which ones are falling (hi XDR)? Is this really all about AI? Is this all marketing? Security platforms or focused tools, who is winning at RSA? Anything fun going on with SecOps? Is cloud security still largely about CSPM? Any interesting presentations spotted? Resources: EP171 GenAI in the Wrong Hand...
EP171 GenAI in the Wrong Hands: Unmasking the Threat of Malicious AI and Defending Against the Dark Side 06.05.2024 27:03
Guest: Elie Bursztein , Google DeepMind Cybersecurity Research Lead, Google Topics: Given your experience, how afraid or nervous are you about the use of GenAI by the criminals (PoisonGPT, WormGPT and such)? What can a top-tier state-sponsored threat actor do better with LLM? Are there "extra scary" examples, real or hypothetical? Do we really have to care about this "dangerous capabilities" stu...
EP170 Redefining Security Operations: Practical Applications of GenAI in the SOC 29.04.2024 27:48
Guest: Payal Chakravarty , Director of Product Management, Google SecOps, Google Cloud Topics: What are the different use cases for GenAI in security operations and how can organizations prioritize them for maximum impact to their organization? We've heard a lot of worries from people that GenAI will replace junior team members–how do you see GenAI enabling more people to be part of the security...
EP169 Google Cloud Next 2024 Recap: Is Cloud an Island, So Much AI, Bots in SecOps 22.04.2024 27:36
Guests: no guests ( just us !) Topics: What are some of the fun security-related launches from Next 2024 (sorry for our brief "marketing hat" moment!)? Any fun security vendors we spotted "in the clouds"? OK, what are our favorite sessions? Our own, right? Anything else we had time to go to? What are the new security ideas inspired by the event (you really want to listen to this part! Because "fr...
EP168 Beyond Regular LLMs: How SecLM Enhances Security and What Teams Can Do With It 15.04.2024 33:18
Guests: Umesh Shankar , Distinguished Engineer, Chief Technologist for Google Cloud Security Scott Coull , Head of Data Science Research, Google Cloud Security Topics: What does it mean to "teach AI security"? How did we make SecLM? And also: why did we make SecLM? What can "security trained LLM" do better vs regular LLM? Does making it better at security make it worse at other things that we car...
EP167 Stolen Cards and Fake Accounts: Defending Google Cloud Against Abuse 08.04.2024 25:24
Speakers: Maria Riaz , Cloud Counter-Abuse, Engineering Lead, Google Cloud Topics: What is "counter abuse"? Is this the same as security? What does counter-abuse look like for GCP? What are the popular abuse types we face? Do people use stolen cards to get accounts to then violate the terms with? How do we deal with this, generally? Beyond core technical skills, what are some of the relevant co...
EP166 Workload Identity, Zero Trust and SPIFFE (Also Turtles!) 01.04.2024 30:06
Guests: Evan Gilman , co-founder CEO of Spirl Eli Nesterov , co-founder CTO of Spril Topics: Today we have IAM, zero trust and security made easy. With that intro, could you give us the 30 second version of what a workload identity is and why people need them? What's so spiffy about SPIFFE anyway? What's different between this and micro segmentation of your network–why is one better or worse? ...
EP165 Your Cloud Is Not a Pet - Decoding 'Shifting Left' for Cloud Security 25.03.2024 24:34
Guest: Ahmad Robinson , Cloud Security Architect, Google Cloud Topics: You've done a BlackHat webinar where you discuss a Pets vs Cattle mentality when it comes to cloud operations. Can you explain this mentality and how it applies to security? What in your past led you to these insights? Tell us more about your background and your journey to Google. How did that background contribute to your t...
EP164 Quantum Computing: Understanding the (very serious) Threat and Post-Quantum Cryptography 18.03.2024 31:23
Guest: Jennifer Fernick , Senor Staff Security Engineer and UTL, Google Topics: Since one of us (!) doesn't have a PhD in quantum mechanics, could you explain what a quantum computer is and how do we know they are on a credible path towards being real threats to cryptography? How soon do we need to worry about this one? We've heard that quantum computers are more of a threat to asymmetric/public k...
EP163 Cloud Security Megatrends: Myths, Realities, Contentious Debates and Of Course AI 11.03.2024 25:54
Guest: Phil Venables, Vice President, Chief Information Security Officer (CISO) @ Google Cloud Topics: You had this epic 8 megatrends idea in 2021, where are we now with them? We now have 9 of them , what made you add this particular one (AI)? A lot of CISOs fear runaway AI. Hence good governance is key! What is your secret of success for AI governance? What questions are CISOs asking you abo...
EP162 IAM in the Cloud: What it Means to Do It 'Right' with Kat Traxler 04.03.2024 28:09
Guest: Kat Traxler , Security Researcher, TrustOnCloud Topics: What is your reaction to "in the cloud you are one IAM mistake away from a breach"? Do you like it or do you hate it? A lot of people say "in the cloud, you must do IAM 'right'". What do you think that means? What is the first or the main idea that comes to your mind when you hear it? How have you seen the CSPs take different approache...
EP161 Cloud Compliance: A Lawyer - Turned Technologist! - Perspective on Navigating the Cloud 26.02.2024 27:38
Guest: Victoria Geronimo , Cloud Security Architect, Google Cloud Topics: You work with technical folks at the intersection of compliance, security, and cloud. So what do you do, and where do you find the biggest challenges in communicating across those boundaries? How does cloud make compliance easier? Does it ever make compliance harder? What is your best advice to organizations that approach...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.