『Cloud Security Podcast by Google』のカバーアート

Cloud Security Podcast by Google

Cloud Security Podcast by Google

著者: Anton Chuvakin
無料で聴く

このコンテンツについて

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps with process and bumps up against organizational design. We're hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can't keep as the world moves from on-premises computing to cloud computing.Copyright Google Cloud
エピソード
  • EP254 Escaping 1990s Vulnerability Management: From Unauthenticated Scans to AI-Driven Mitigation
    2025/12/01

    Guest:

    • Caleb Hoch, Consulting Manager on Security Transformation Team, Mandiant, Google Cloud

    Topics:

    • How has vulnerability management (VM) evolved beyond basic scanning and reporting, and what are the biggest gaps between modern practices and what organizations are actually doing?
    • Why are so many organizations stuck with 1990s VM practices?
    • Why mitigation planning is still hard for so many?
    • Why do many organizations, including large ones, still rely on unauthenticated scans despite the known importance of authenticated scanning for accurate results?
    • What constitutes a "gold standard" vulnerability prioritization process in 2025 that moves beyond CVSS scores to incorporate threat intelligence, asset criticality, and other contextual factors?
    • What are the primary human and organizational challenges in vulnerability management, and how can issues like unclear governance, lack of accountability, and fear of system crashes be overcome?
    • How is AI impacting vulnerability management, and does the shift to cloud environments fundamentally change VM practices?

    Resources:

    • EP109 How Google Does Vulnerability Management: The Not So Secret Secrets!
    • EP246 From Scanners to AI: 25 Years of Vulnerability Management with Qualys CEO Sumedh Thakar
    • EP248 Cloud IR Tabletop Wins: How to Stop Playing Security Theater and Start Practicing
    • How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends
    • Mandiant M Trends 2025
    • EP204 Beyond PCAST: Phil Venables on the Future of Resilience and Leading Indicators
    • Mandiant Vulnerability Management
    続きを読む 一部表示
    31 分
  • EP253 The Craft of Cloud Bug Hunting: Writing Winning Reports and Secrets from a VRP Champion
    2025/11/24

    Guests:

    • Sivanesh Ashok, bug bounty hunter
    • Sreeram KL, bug bounty hunter

    Topics:

    • We hear from the Cloud VRP team that you write excellent bugbounty reports - is there any advice you'd give to other researchers when they write reports?
    • You are one of Cloud VRP's top researchers and won the MVH (most valuable hacker) award at their event in June - what do you think makes you so successful at finding issues?
    • What is a Bugswat?
    • What do you find most enjoyable and least enjoyable about the VRP?
    • What is the single best piece of advice you'd give an aspiring cloud bug hunter today?

    Resources:

    • EP220 Big Rewards for Cloud Security: Exploring the Google VRP
    • Cloud Vulnerability Reward Program Rules
    • Insights from BugSWAT
    • Google Cloud's Vulnerability Reward Program
    • Critical Thinking Podcast

    続きを読む 一部表示
    28 分
  • EP252 The Agentic SOC Reality: Governing AI Agents, Data Fidelity, and Measuring Success
    2025/11/17

    Guests:

    • Alexander Pabst, Deputy Group CISO, Allianz
    • Lars Koenig, Global Head of D&R, Allianz

    Topics:

    • Moving from traditional SIEM to an agentic SOC model, especially in a heavily regulated insurer, is a massive undertaking. What did the collaboration model with your vendor look like?
    • Agentic AI introduces a new layer of risk - that of unconstrained or unintended autonomous action. In the context of Allianz, how did you establish the governance framework for the SOC alert triage agents?
    • Where did you draw the line between fully automated action and the mandatory "human-in-the-loop" for investigation or response?
    • Agentic triage is only as good as the data it analyzes. From your perspective, what were the biggest challenges - and wins - in ensuring the data fidelity, freshness, and completeness in your SIEM to fuel reliable agent decisions?
    • We've been talking about SOC automation for years, but this agentic wave feels different. As a deputy CISO, what was your primary, non-negotiable goal for the agent? Was it purely Mean Time to Respond (MTTR) reduction, or was the bigger strategic prize to fundamentally re-skill and uplevel your Tier 2/3 analysts by removing the low-value alert noise?
    • As you built this out, were there any surprises along the way that left you shaking your head or laughing at the unexpected AI behaviors?
    • We felt a major lack of proof - Anton kept asking for pudding - that any of the agentic SOC vendors we saw at RSA had actually achieved anything beyond hype! When it comes to your org, how are you measuring agent success? What are the key metrics you are using right now?

    Resources:

    • EP238 Google Lessons for Using AI Agents for Securing Our Enterprise
    • EP242 The AI SOC: Is This The Automation We've Been Waiting For?
    • EP249 Data First: What Really Makes Your SOC 'AI Ready'?
    • EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI
    • "Simple to Ask: Is Your SOC AI Ready? Not Simple to Answer!" blog
    • "How Google Does It: Building AI agents for cybersecurity and defense" blog
    • Company annual report to look for risk
    • "How to Win Friends and Influence People" by Dale Carnegie
    • "Will It Make the Boat Go Faster?" book
    続きを読む 一部表示
    36 分
まだレビューはありません