Anton Chuvakin
Cloud Security Podcast by Google
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps...
Author
Anton Chuvakin
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
EP110 Detection and Response in a High Velocity and High Complexity Environment 27.02.2023 27:52
Guest: David Seidman , Head of Detection and Response @ Robinhood Toipics: Tell us about joining Robinhood and prioritizing focus areas for detection in your environment? Tim and Anton argue a lot about what kind of detection is best - fully bespoke and homemade, or scalable off-the-shelf. First, does our framework here make sense, and second, looking at your suite of detection capabilities, how...
EP109 How Google Does Vulnerability Management: The Not So Secret Secrets! 20.02.2023 27:37
Guest: Ana Oprea , Staff Security Engineer, European Lead of Vulnerability Coordination Center @ Google Topics: What is the scope for the vulnerability management program at Google? Does it cover OS, off-the-shelf applications, custom code we wrote … or all of the above? Our vulnerability prioritization includes a process called "impact assessment." What does our impact assessment for a vulnerab...
EP108 How to Hunt the Cloud: Lessons and Experiences from Years of Threat Hunting 13.02.2023 26:10
Guest: John Stoner , Principal Security Strategist @ Google Cloud Topics: Please define threat hunting for us quickly, the term has been corrupted a bit What are your favorite beginner hunts to jump start the effort at a new team? How to incorporate hunting lessons in detection? What are the differences for hunting in the cloud? Are there specific data sources you prefer to have access to when t...
EP 107 How Google Secures It's Google Cloud Usage at Massive Scale 06.02.2023 28:51
Guest: Karan Dwivedi , Security Engineering Manager, Enterprise Infrastructure Protection @ Google Cloud Topics: Google's use of Google Cloud is a massive cloud environment with wildly diverse use cases. Could you share, for our listeners, a few examples of the different kinds of things we're running in GCP? Given that we're doing these wildly different things in GCP, how do we think about scaling...
EP106 Beyond BeyondProd - How Do You Zero Trust Your Workloads? 30.01.2023 26:14
Guest: Anoosh Saboori, former Product Manager at Google Cloud Topics: We had zero trust episodes before and definitions vary! When we say zero trust, what do we mean? What about zero trust for workloads in production? When you say "workload," what do you mean? What is BeyondProd, for those that are unfamiliar with it? And how is this different from BeyondCorp? How has BeyondProd actually been i...
EP105 Security Architect View: Cloud Migration Successes, Failures and Lessons 23.01.2023 28:45
Guest: Michele Chubirka , Senior Cloud Security Advocate, Google Cloud Topics: We are here to talk about cloud migrations and we are here to talk about failures. What are your favorites? What are your favorite cloud security process failures? What are your favorite cloud security technical failures? What are your favorite cloud security container and k8s failures? Is "lift and shift" always wron...
EP104 CISO Walks Into the Cloud: And The Magic Starts to Happen! 16.01.2023 25:01
Guest: Gary Hayslip , CISO at Softbank Topics: "So we're talking about your journey as a CISO migrating to Cloud. Could you give us the 30 second overview of What triggered your organization's migration to the cloud? When did you and the security organization get brought in? How did you plan your security organization's journey to the cloud? Did you take going to cloud as an opportunity to cha...
EP103 Security Incident Response and Public Cloud - Exploring with Mandiant 09.01.2023 24:14
Guest: Nader Zaveri , Senior Manager of IR and Remediation at Mandiant, now part of Google Cloud Topics: Could we start with a story of a cloud incident response (IR) failure and where things went wrong? What should that team have done to get it right? Are there skills that matter more in cloud incidents than they do for on-prem incidents? Are there on-prem instincts that will lead incident re...
EP102 Sunil Potti on Building Cloud Security at Google 19.12.2022 25:24
Guest: Sunil Potti , VP / GM, Google Cloud Topics: One of the biggest shifts we've noticed is the shift from building security because we think security is good, to building security as a business. How did you make that cultural shift happen in our organization? With organizations migrating to cloud we have a set of tradeoffs between meeting security teams where they are with on-prem expectation...
EP101 Cloud Threat Detection Lessons from a CISO 12.12.2022 24:42
Guest: Jim Higgins , CISO at Snap, former CISO at Square Topics: You were at Google for a long time, and at Google you sat between Google security and Cloud. Now that you're leading security for a major company, how are you prioritizing your focus between your on-premise resources and your cloud resources? How are you thinking about threat detection in the Cloud? In detection, how has your tech...
EP100 2022 Accelerate State of DevOps Report and Software Supply Chain Security 05.12.2022 33:06
Guests: John Speed Meyers , Security Data Scientist, Chainguard Todd Kulesza, User Experience Researcher, Google Topics: How did you get involved with this year's Accelerate State of DevOps Report ( DORA report ) ? So what is DORA and why did you decide to focus on supply chain security for the 2022 report? What are the big learnings from this year's report ? What's the difference between SLSA and...
EP99 Google Workspace Security: from Threats to Zero Trust 28.11.2022 22:54
Guests: Nikhil Sinha, Group Product Manager, Workspace Security Kelly Anderson, Product Marketing Manager, Workspace Security Topics: We are talking about Google Workspace security today. What kinds of threats do we have to care about here? Are there compliance-related motivations for security here too? Is compliance in the cloud changing? How's adoption of hardware keys for MFA going for your use...
EP98 How to Cloud IR or Why Attackers Become Cloud Native Faster? 21.11.2022 26:58
Guests: Matt Linton , Chaos Specialist @ Google John Stone , Chaos Coordinator @ Office of the CISO, Google Cloud Topics: Let's talk about security incident response in the cloud. Back in 2014 when I [Anton] first touched on this, the #1 challenge was getting the data to investigate as cloud providers had few logs available. What are the top 2022 cloud incident response challenges? Does cloud cha...
Special: Coordinated Release of Detection Rules for CobaltStike Abuse 17.11.2022 20:55
Guest: Greg Sinclair , Security Engineer @ Google Cloud Topics: Could you tell us a bit about your background and how you ended up here at Google? Also, tell us about your team here? We're very excited about the release of the CobaltStrike rules. Could you share more about what they are looking for and second why this is so valuable? How did CobaltStrike come to be so widely used by bad guys? When...
EP96 Cloud Security Observability for Detection and Response 14.11.2022 32:32
Guest: Jeff Bollinger , Director of Incident Response and Detection Engineering @ Linkedin Topics: Observability sounds cool (please define it for us BTW), but relating it to security has been "hand-wavy" at best. What is your opinion on the relevance of observability data for security use cases? What use cases are those, apart from saving the data for IR just in case? How can we best approach o...
EP95 Cloud Security Talks Panel: Cloud Threats and Incidents 07.11.2022 27:42
Guests: Alijca Cade , Director, Financial Services, Office of the CISO, Google Cloud Ken Westin , Director, Security Strategy, Cybereason Robert Wallace , Senior Director, Mandiant, now Google Cloud Topics: How are cloud environments attacked and compromised today? Is it still about the configuration mistakes? Do cryptominers represent a serious threat now that they are often mentioned as the most...
EP94 Meet Cloud Security Acronyms with Anna Belak 31.10.2022 27:32
Guest: Dr Anna Belak , Director of Thought Leadership at Sysdig , former Gartner analyst Questions: Analysts (and vendors) coined a log of "C-something acronyms" for cloud security, and two of the people on this episode were directly involved in some of them. What do you make of all the cloud security acronym proliferation? What is CSPM? What gets better when you deploy it? What is CWPP? Does any...
EP93 CISO Walks Into the Cloud: Frustrations, Successes, Lessons ... And Is My Data Secure? 24.10.2022 28:25
Guest: Alicja Cade , Director for Financial Services, Office of the CISO, Google Cloud Topics: We are talking about your journey as a CISO migrating to the cloud. Could you give us the overview of … What triggered your organization's migration to the cloud? When did you and the security team get brought in? Did you take going to the cloud as an opportunity to change things beyond the tools you we...
Special: Sharing The Mic In Cyber with STMIC Hosts Lauren and Christina: Representation, Psychological Safety, Security 21.10.2022 22:43
Guests: Lauren Zabierek ( @lzxdc ), Acting Executive Director of the Belfer Center at the Harvard Kennedy School Christina Morillo ( @divinetechygirl ), Principal Security Consultant at Trimark Security Topics: We are so excited to have you on the show today talking about your awesome effort, Share The Mic in Cyber . I love that we are Sharing our Mic with you today. Could you please introduce you...
EP91 "Hacking Google", Op Aurora and Insider Threat at Google 17.10.2022 26:07
Guest: Mike Sinno , Security Engineering Director, Detection and Response @ Google Topics: You recently were featured in " Hacking Google" videos , can you share a bit about this effort and what role you played? How long have you been at Google? What were you doing before, if you can remember after all your time here? What brought you to Google? We hear you now focus on insider threats. Insider t...
Next 2022 Google Cybersecurity Action Team: One Year Later! 13.10.2022 29:36
Guest: Phil Venables , Vice President and CISO at Google Cloud Topics: Google Cybersecurity Action Team is your brainchild and it is 1 year old, what comes to mind first when we reflect on this anniversary? The team is primarily about helping clients with security, what did we learn doing this for a year? What challenges have we (Google Cybersecurity Action Team) faced in our first year? We releas...
Next 2022 Can We Escape Ransomware by Migrating to the Cloud? 12.10.2022 18:54
Guest: Nelly Kassem , Security and Compliance Specialist @ Google Cloud Topics: Why did ransomware attacks become so popular? What type of organizations are targeted by ransomware? Do these affect mostly the organizations with sub-par security? Ransomware has been raging since 2015 and shows few signs of subsiding. Why are these attacks still successful? Do we see ransomware in the cloud? Do...
Next 2022 Improving Browser Security in the New Era of Work 11.10.2022 20:58
Guest: Fletcher Oliver , Chrome Browser Customer Engineer, Google Topics: What is browser security? Isn't it just application security by another name? Why is browser security more important now than ever? Do we have statistical measures or data that tell us if we're succeeding at browser security? Do we know if we're doing a good job at making this better? What are the components of modern bro...
Next 2022 Log4j Reflections, Software Dependencies and Open Source Security 10.10.2022 26:36
Guest: Dr Nicky Ringland , Product Manager for Open Source Insights , Google Topics: Let's talk Open Source Software - are all these dependencies dependable? Why was log4j such a big thing - at a whole ecosystem level? Was it actually a Java / Maven problem? Are other languages "better" or more secure? Is another log4j inevitable? What can organizations to minimise their own risks? Resources : G...
EP86 How to Apply Lessons from Virtualization Transition to Make Cloud Transformation Better 04.10.2022 23:28
Guest: Thiébaut Meyer , Director at Office of the CISO, Google Cloud Topics: Virtualization's arrival caused a major IT upheaval 20 years ago. What can we learn from that revolution for our current cloud transformation? We talk about our three legged security stool of people/process/technology. How do we balance the technical issues (new technology stack, etc.) with the new processes (agile, etc)...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.