Anton Chuvakin
Cloud Security Podcast by Google
Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps...
Author
Anton Chuvakin
Category
Podcast website
Latest episode
Jul 6, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
EP85 Deploy Security Capabilities at Scale: SRE Explains How 26.09.2022 30:50
Guest: Steve McGhee , Reliability Advocate, Google Cloud Topics: What can security teams learn from the Site Reliability Engineering (SRE) art of rapid and safe deployment? Is this all about the process or do SREs possess some magical technology to do this? What is SRE approach to automation? What are the pillars / components of SRE approach to deployment? SRE is also about scaling. Some securit...
EP84 How to Secure Artificial Intelligence (AI): Threats, Approaches, Lessons So Far 19.09.2022 26:29
Guest: Alex Polyakov , CEO of Adversa.ai Topics: You did research by analyzing 2000 papers on AI attacks released in the previous decade. What are the main insights? How do you approach discovering the relevant threat models for various AI systems and scenarios? Which threats are real today vs in a few years? What are the common attack vectors? What do you see in the field of supply chain attacks...
EP83 What Does reCAPTCHA Actually Do and How Does It Do it? Product Manager Explains 12.09.2022 27:17
Guest: Badr Salmi , Product Manager for reCAPTCHA Topics: What is reCAPTCHA ? Aren't you guys the super annoying 'click on the busses' thing? What is account defender? Why was this a natural next step for you? What are the actual threats that this handles - and handles well? Specific web attacks? Web fraud? Let's talk about account fraud, what do these attacks look like and how do bad guys moneti...
EP82 Mega-confused by XDR? You Are Not Alone! This XDR Skeptic Clarifies! 05.09.2022 28:00
Guest: Dimitri McKay , Principal Security Strategist @ Splunk Topics: How do you define that "XDR thing" that you are so skeptical about? So within that definition of XDR, you think it's not so great, why? If you have to argue pro-XDR, what would you say? Two main XDR camps are "XDR as EDR+" and "XDR as SIEM-", which camp do you think is more right? Are both wrong? What approach do you think is m...
EP81 Demystify Data Sovereignty and Sovereign Cloud Secrets at Google Cloud 29.08.2022 26:04
Guest: Christopher "CJ" Johnson , retired Fire Chief, and Global Regulated Cloud Product Lead @ Google Cloud Topics: In political science, they define sovereignty as a local monopoly on the legitimate use of force. Why are we talking about "sovereignty" in IT? What is a sovereign cloud? How much of the term is marketing vs engineering? Who cares or should care about sovereign cloud? Is this abou...
EP80 CISO Walks Into the Cloud: Frustrations, Successes, Lessons ... And Does the Risk Change? 22.08.2022 29:19
Guest: David Stone , Staff Consultant at Office of the CISO, Google Cloud Topics: Speaking as a former CISO, what triggered your organization migration to the cloud? When did you and the security organization get brought in? How did you plan your security organization journey to the cloud? Did you take going to Cloud as an opportunity to change things beyond the tools you were using? As you got...
EP79 Modernize Data Security with Autonomic Data Security Approach 15.08.2022 27:37
Guest: John Stone , Chaos Coordinator @ Office of the CISO, Google Cloud Topics: So what is Autonomic Data Security, described in our just released paper? What are some notorious data security issues today? Perhaps common data security mistakes security leaders commit? What never worked in data security, like say manual data classification? How should organizations think about securing the data...
EP78 Classic SOC Meets Cloud: What Changes? What Stays the Same? 08.08.2022 28:25
Guest: Gorka Sadowski , Chief Strategy Officer @ Exabeam Topics: How do we get a legacy SOC team to think about the cloud? How to think about cloud threat detection, in general? What is different … threats, the environment, what else? What is the same? How do we know which TTPs are relevant for the new environments? What to bring with us to the cloud? Do content/rules and detection engines need...
EP77 Operational Realities of SOAR: Automate and/or Enrich, Playbooks, Magic 01.08.2022 25:06
Guest: Cyrus Robinson , SOC Director and IR Team lead at Ingalls Information Security Topics: You've been using SOAR tools for years, so what do you think of the technology so far? What is driving SOAR adoption today? And what is inhibiting SOAR adoption? Realistically, how hard is SOAR to operationalize for a typical company? What are your favorite SOAR playbooks to start with? How to build, trai...
EP76 Powering Secure SaaS … But Not with CASB? Cloud Detection and Response? 25.07.2022 30:16
Guest: Ben Johnson , CTO/co-founder @ Obsidian Security Topics: Why is there so much attention lately on SaaS security? Doesn't this area date back to 2015 or so ? What do you see as the primary challenges in securing SaaS? What does a SaaS threat model look like? What are the top threats you see? CASB has been the fastest growing security market and it has grown into a broad platform and many ass...
EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil 18.07.2022 26:51
Guest: Tim Nguyen , Director of Detection and Response @ Google Topics: I know we don't like to say "SOC" here, so why don't we talk about the role of automation in detection and response (D&R) at Google? One SRE concept we found useful in security operations is "toil" - How do we squeeze toil out of D&R practice at Google? A combined analyst and engineer role (just like an SRE) was critical for b...
EP74 Who Will Solve Cloud Security: A View from Google Investment Side 11.07.2022 26:31
Guest: James Luo , Partner @ CapitalG Topics: You've looked at hundreds of security startups at the growth stage - what is getting funded? What is not getting funded? What is the difference? What's your view on the current market environment for security companies? Is security "recession-proof", whatever that means? How do you think about what problems are worth solving with a new venture vs ex...
EP73 Your SOC Is Dead? Evolve to Output-driven Detect and Respond! 05.07.2022 27:56
Guest: Erik Bloch , Senior Director of Detection and Response at Sprinklr Topics: You recently coined a concept of "output-driven Detection and Response" and even perhaps broader "output-driven security." What is it and how does it work? Detection and response is alive (obviously), but sometimes you say SOC is dead, what do you mean by that? You refer to a federated approach for Detection and Res...
EP72 What Does Good Detection and Response Look Like in the Cloud? Insights from Expel MDR 27.06.2022 32:04
Guests: Dave "Merk" Merkel , CEO @ Expel Peter Silberman , CTO @ Expel Topics: Many MDRs claim to be "security from the cloud", but they actually don't know much about cloud security. What does good looks like for MDR in the cloud (cloud being a full range from IaaS to SaaS)? What are the key challenges for clients picking an MDR for their cloud environments? What are the questions to ask your...
EP71 Attacking Google to Defend Google: How Google Does Red Team 21.06.2022 22:46
Guest: Stefan Friedli , Senior Security Engineer @ Google Topics: What is our "red team" testing philosophy and approach at Google? How did we evolve to this approach? What is the path from testing to making Google and our users more secure? How does our testing power the improvements we make? What is unique about red teaming at Google? Care to share some fun testing stories or examples from y...
EP70 Special - RSA 2022 Reflections - Securing the Past vs Securing the Future 16.06.2022 22:49
Guests: none Topics: What have we seen at the RSA 2022 Conference ? What was the most interesting and unexpected? What was missing? Resources: "RSA 2022 Musings: The Past and The Future of Security" Google Cloud Security at RSA 2022
EP69 Cloud Threats and How to Observe Them 13.06.2022 29:40
Guest: James Condon , Director of Security Research @ Lacework Topics: What are realistic and actually observed cloud threats today? How did you observe them at Lacework? Cloud threats: are they on-premise style threats to cloud assets? We hate the line "cloud is just somebody else's computer" but apparently threats actors seem to think so? What is the 2nd most dangerous cloud issue after conf...
EP68 How We Attack AI? Learn More at Our RSA Panel! 06.06.2022 28:12
Guest: Nicholas Carlini , Research Scientist @ Google Topics: What is your threat model for a large-scale AI system? How do you approach this problem? How do you rank the attacks? How do you judge if an attack is something to mitigate? How do you separate realistic from theoretical? Are there AI threats that were theoretical in 2020, but may become a daily occurrence in 2025? What are the threat...
EP67 Cyber Defense Matrix and Does Cloud Security Have to DIE to Win? 31.05.2022 25:57
Guest: Sounil Yu , CISO and Head of Research at JupiterOne Topics: How does your Cyber Defense Matrix apply to cloud security? Are things easier or harder? Cloud (at least the cloudy-cloud, also called cloud native) definitely supports "Distributed Immutable Ephemeral" (DIE) - your new creation, how does that change security and CDM? Cyber resilience generates a lot of confusion, how do you defin...
EP66 Is This Binary Legit? How Google Uses Binary Authorization and Code Provenance 23.05.2022 24:57
Guest: Sandra Guo , Product Manager in Security, Google Cloud Topics: We have a really interesting problem here: if we make great investments in our use of trusted repositories, and great investments in doing code review on every change, and securing our build systems, and having reproducible builds, how do we know that all of what we did upstream is actually what gets deployed to production? What...
EP65 Is Your Healthcare Security Healthy? Mandiant Incident Response Insights 16.05.2022 28:02
Guests: Charles Carmakal , CTO at Mandiant Taylor Lehmann , Director at Office of the CISO, Google Cloud Topics: What are the current "popular" incidents at healthcare providers that you handled? Any of them involve cloud? Do healthcare CISOs have time for anything other than ransomware? Does insider threat matter? What can incident response teach us here? How do you think the threat actors bene...
EP64 Security Operations Center: The People Side and How to Do it Right 09.05.2022 29:25
Guest: Dave Herrald @ Principal Security Strategist, Google Cloud Topics: What are some tenets of good SOC training? How does this depend on the SOC model (traditional L1/L2/L3, virtual, etc)? How do you make SOC training realistic? Should training be about the toolset or should it be about the analyst's skills? Should you primarily train for engineering skills or analysis skills? Do you need to c...
EP63 State of Autonomic Security Operations: Are There Sharks in Your SOC? 02.05.2022 34:59
Guests: Robert Herjavec , Founder and CEO of Herjavec Group Eric Foster , President of CYDERES Iman Ghanizada , Global Head of Autonomic Security Operations at Google Cloud. Topics: It's been a few months since we launched Autonomic Security Operations (ASO) and it seems like the whitepaper has been going viral in the industry. Tell us what ASO is about? How was the ASO story received by your cus...
EP62 Protect Modern Applications in the Cloud: Union of APIs and Application Security 25.04.2022 27:10
Guest: Etienne De Burgh , Senior Security and Compliance Specialist, Office of the CISO @ Google Cloud Topics: Why is API security hot now? What happened that made it a priority for many? Is API security different from application security? Doesn't the first "A" in API stand for application? What are the real threats to exposed APIs? APIs are designed for automated use, so how do you tell autom...
EP61 Anniversary Episode - What Did We Learn So Far on Cloud Security Podcast? 18.04.2022 26:35
No guests - just Anton and Tim Topics: Why cloud security? What do we really think about our podcast name and topic, cloud security? Can you once again explain security for the cloud, in the cloud, from the cloud? What is one thing that we learned from doing a podcast? Favorite cloud security trend that we encountered on the podcast? What did we learn about security from organization's migrating...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.