Cloud Security Podcast by Google Podcast By Anton Chuvakin cover art

Cloud Security Podcast by Google

Cloud Security Podcast by Google

By: Anton Chuvakin
Listen for free

Cloud Security Podcast by Google focuses on security in the cloud, delivering security from the cloud, and all things at the intersection of security and cloud. Of course, we will also cover what we are doing in Google Cloud to help keep our users' data safe and workloads secure. We're going to do our best to avoid security theater, and cut to the heart of real security questions and issues. Expect us to question threat models and ask if something is done for the data subject's benefit or just for organizational benefit. We hope you'll join us if you're interested in where technology overlaps with process and bumps up against organizational design. We're hoping to attract listeners who are happy to hear conventional wisdom questioned, and who are curious about what lessons we can and can't keep as the world moves from on-premises computing to cloud computing.Copyright Google Cloud
Episodes
  • EP269 Reflections on RSA 2026 - Beyond AI AI AI AI AI AI AI
    Mar 30 2026

    Guests:

    • No guests! Just Tim and Anton

    Topics:

    • Hard to believe we've been doing these since 2022, is that right?
    • What did we see this year at RSA, apart from AI? And more AI? And more AI?
    • What framework can we use to understand the approaches vendors take to AI and security? Just saying "AI washing" is not enough!
    • How to tell "AI washer" from "AI tourist"?
    • I sense that "securing AI" (and agents) is finally growing as fast as "using AI for security", do you agree?
    • Is the AI vulnerability apocalypse coming? Soon?
    • Have we seen any signs of AI backlash?

    Resource:

    • Video version
    • EP223 AI Addressable, Not AI Solvable: Reflections from RSA 2025
    • RSA 2025: AI's Promise vs. Security's Past — A Reality Check blog
    • EP172 RSA 2024: Separating AI Signal from Noise, SecOps Evolves, XDR Declines?
    • EP119 RSA 2023 - What We Saw, What We Learned, and What We're Excited About
    • EP70 Special - RSA 2022 Reflections - Securing the Past vs Securing the Future
    • EP255 Separating Hype from Hazard: The Truth About Autonomous AI Hacking
    • EP256 Rewiring Democracy & Hacking Trust: Bruce Schneier on the AI Offense-Defense Balance
    Show more Show less
    33 mins
  • EP268 Weaponizing the Administrative Fabric: Cloud Identity and SaaS Compromise in M Trends 2026
    Mar 23 2026

    Guests:

    • Kelli Vanderlee, Senior Manager, Threat Analysis, Mandiant, Google Cloud
    • Scott Runnels, Mandiant Incident Response, Google Cloud

    Topics:

    • Do we need to rethink "Mean Time to Respond" entirely, or are we just in deep trouble?
    • Why are threat groups collaborating so well, and are there actual lessons for defenders in their "business" model?
    • What is the scalable advice for teams worried about voice phishing and GenAI cloning?
    • What does "weaponizing the administrative fabric" actually mean in a world where identity is the perimeter?
    • Why is identity/SaaS compromise "news" in 2026 when cloud security folks have been shouting about it for years? What actually changed?
    • What's the latest in supply chain compromise, particularly regarding malicious open-source packages?
    • How do we defend against malware that is "lazy" enough to use the victim's own AI tools for reconnaissance?
    • What is the specific advice for Detection and Response (D&R) teams to handle "living off the land" (or "living off the cloud")?
    • How do you fix the situation when IT and Security departments genuinely hate each other?
    • Besides reading the report, what is the one book or piece of advice for a CISO to survive this year?

    Resources:

    • Video version
    • M-Trends 2026 Report
    • EP222 From Post-IR Lessons to Proactive Security: Deconstructing Mandiant M-Trends
    • EP254 Escaping 1990s Vulnerability Management: From Unauthenticated Scans to AI-Driven Mitigation
    • EP205 Cybersecurity Forecast 2025: Beyond the Hype and into the Reality
    • EP147 Special: 2024 Security Forecast Report
    • "The Evolution of Cooperation" book
    Show more Show less
    34 mins
  • EP267 AI SOC or AI in a SOC? Cutting Through Hype, Pricing Models, and SIEM Detection Efficacy with Raffy Marty
    Mar 16 2026

    Guest:

    • Raffael Marty, Operating Advisor, a SIEM legend since 1999

    Topics:

    • You argue that declaring existing SIEM being obsolete is a "marketing slogan" rather than a true thesis. What is the real pain point and the actual gap in traditional SIEMs as opposed to the more sensational claims?
    • You highlight that "correlation, state, timelines, and real-time detection require locality," making centralization a necessary trade-off. Can a truly federated or decoupled SIEM architecture achieve the same fidelity and real-time performance for complex, stateful detections as a centralized one?
    • You call the rise of independent security data pipelines the "SIEM Trojan Horse." How quickly is this abstraction layer turning SIEM into a "swappable" component, and what should SIEM vendors have done differently years ago to prevent this market from existing?
    • This "AI SOC" thing, is this even real? Is AI in a SOC a better label? Do you think major SIEM vendors will own this very soon, like they did with UEBA and SOAR?
    • If volume-based pricing is flawed because it penalizes good security hygiene, what is a better SIEM pricing model that fairly addresses compute, enrichment, and retention costs without just shifting the volume cost to unpredictable query charges?
    • You question the idea that startups can find a better way to release detection rules than large vendors with significant content teams. What metrics should security leaders use to evaluate the quality of a vendor's detection engineering (DE) output beyond just coverage numbers? Can AI fix DE?

    Resources:

    • Video version
    • The SIEM Maturity Framework: A Practical Scoring Tool for Security Analytics Platforms and raffy.ch/SIEM/
    • The Gaps That Created the New Wave of SIEM and AI SOC Vendors
    • How AI Impacts the Cyber Market and The Future of SIEM
    • Why Venture Capital Is Betting Against Traditional SIEMs
    • EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI
    • EP234 The SIEM Paradox: Logs, Lies, and Failing to Detect
    • EP125 Will SIEM Ever Die: SIEM Lessons from the Past for the Future
    • Decoupled SIEM: Brilliant or Stupid?
    • Decoupled SIEM: Where I Think We Are Now?
    Show more Show less
    36 mins
No reviews yet