Cloud Security Podcast by Google

Cloud Security Podcast by Google

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We’re going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject’s benefit or just for organizational benefit. We hope you’ll join us if you’re interested in where technology overlaps with process and bumps up against organizational design. We’re hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can’t keep as the world moves from on-premises computing to cloud computing.

Episodes

July 7, 2025 25 mins

Guest:

Topic:

  • Could you share insights into how Product Security Engineering approaches at Google have evolved, particularly in response to emerging threats (like Log4j in 2021)?
  • You mentioned applying SRE best practices i...
Mark as Played

Guest:

Topic:

  • You have had a fascinating career since we [Tim] graduated from college together – you mentioned before we met that you’ve consulted with a literal world leader on his personal digital security footprint. Maybe tell us how you got into this field of helping organizations tr...
Mark as Played

Guest:

Topic:

  • Detection as code is one of those meme phrases I hear a lot, but I’m not sure everyone means the same thing when they say it. Could you tell us what you mean by it, and what upside it has for organizations in your model of it?
  • Read more
Mark as Played

Guest:

Topic:

  • Your RSA talk highlights lessons learned from two years of AI red teaming at Google. Could you share one or two of the most surprising or counterintuitive findings you encountered during this process?
  • What are some of the key d...
Mark as Played

Guest:

  • Alex Pinto,  Associate Director of Threat Intelligence, Verizon Business, Lead the Verizon Data Breach Report

Topics:

  • How would you define “a cloud breach”? Is that a real (and different) thing? 
  • Are cloud breaches just a result of leaked keys and creds?
  • If customers are responsible ...
Mark as Played

Guest

Topics:

  • SIEM is hard, and many vendors have discovered this over the years. You need to get storage, security and integration complexity just right. You also need to be better than incumbents. How ...
Mark as Played

Guests:

 Topics:

  • Why is your AI-powered MDR special? Why start an MDR from scratch using AI?
  • So why should users bet on an “AI-native” MDR instead of an MDR that has already got its act together and is now ap...
Mark as Played

Guest:

 Topics:

  • Can you describe the key components of an AI software supply chain, and how do they compare to those in a traditional software supply chain? 
  • I hope folks listening have heard past episodes where we ...
Mark as Played

Hosts:

...

Mark as Played

Guest:

 Topics:

  • Can you explain the concept of "MLSecOps" as an analogy with DevSecOps, with 'Dev' replaced by 'ML'? This has nothing to do with SecOps, right?
  • What are the most critical steps a CISO should prioritize when implementing MLSecOps within their organization? ...
Mark as Played

Guests: 

  • no guests, just us in the studio

Topics:

  • At RSA 2025, did we see solid, measurably better outcomes from AI use in security, or mostly just "sizzle" and good ideas with potential?
  • Are the promises of an "AI SOC" repeating the mistakes seen with SOAR in previous years regarding fully...
Mark as Played

Guests:

Topics:

  • What is the hardest thing about turning distinct incident reports into a fun to read and useful report like M-Trends?
  • How much are the lessons and...
Mark as Played

Guests:

  • No guests [Tim in Vegas and Anton remote]

Topics:

  • So, another Next is done. Beyond the usual Vegas chaos, what was the overarching security theme or vibe you [Tim] felt dominated the conference this year?
  • Thinking back to Next '24, what felt genuinely different this year versus just...
Mark as Played

Guests:

Topics:

  • Vulnerability response at cloud-scale sounds very hard! How do you triage vulnerability reports and make sure we’re addressing the right ones in the underlying cloud infrastructure...
Mark as Played

Guest:

Topics:

  • We've seen a shift in how boards engage with cybersecurity. From your perspective, what's the most significant misconception boards still hold about cyber risk, particularly in the Asia Pacific region, and how has that impacted their decision-making?
  • Read more
Mark as Played

Guest:

Topics:

  • How have you seen IAM evolve over the years, especially with the shift to the cloud, and now AI? What are some of the biggest challenges and opportunities these two shifts present? 
  • ITDR (Identity Threat De...
Mark as Played

Guest:

Topics:

  • Adversa AI is known for its focus on AI red teaming and adversarial attacks. Can you share a particularly memorable red teaming exercise that exposed a surprising vulnerability in an AI system? What was the key takeaway for your team and the client?
  • Read more
Mark as Played

Guest:

Topics:

  • Cloud Detection and Response (CDR) vs Cloud Investigation and Response Automation(CIRA) ... what’s the story here? There is an “R” in CDR, right?
  • Can’t my (modern) SIEM/SOAR d...
Mark as Played

Guest:

 Topics:

  • Can you walk us through Google's typical threat modeling process? What are the key steps involved?
  • Threat modeling can be applied to various areas. Where does Google utilize it the most? How do we apply this to huge and complex systems?
Mark as Played

Guest:

Topics:

  • You are responsible for building systems that need to comply with laws that are often mutually contradictory. It seems technically impossible to do, how do you do this?
  • Google is not alone in being a glo...
Mark as Played

Popular Podcasts

    If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.

    The Joe Rogan Experience

    The official podcast of comedian Joe Rogan.

    24/7 News: The Latest

    The latest news in 4 minutes updated every hour, every day.

    The Breakfast Club

    The World's Most Dangerous Morning Show, The Breakfast Club, With DJ Envy And Charlamagne Tha God!

    Dateline NBC

    Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

Advertise With Us
Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.