Cloud Security Podcast by Google cover art

All Episodes

Cloud Security Podcast by Google — 279 episodes

#
Title
1

EP279 Native Cloud Security: Is 'Good Enough' Actually Winning?

2

EP278 The Agentic SOC: Are We Measuring Time Saved or Risk Reduced?

3

EP277: CISO as CFO, From Citi to Celery, It's All about the Cabbage

4

EP276 AI Governance vs. The Hyper-Velocity Agentic Future: A Lawyer's Take

5

EP275 Google Cloud Next 2026: The AI Earthquake, "SOC-home" Syndrome, and the Ragged Edge of Reality

6

EP273 From CISA to Cloud: AI Assurance, Concentration Risk, and the New Regulatory Frontier

7

EP272 More Than Just Packets: Is NDR a "First-Class" Cloud Security Control?

8

EP271 Can AI-Native MDR Actually Fix Your Broken SOC Workflows or Just Automate the Mess?

9

EP270 The Convenience Tax: Why We Keep Failing at Supply Chain Security

10

EP269 Reflections on RSA 2026 - Beyond AI AI AI AI AI AI AI

11

EP268 Weaponizing the Administrative Fabric: Cloud Identity and SaaS Compromise in M Trends 2026

12

EP267 AI SOC or AI in a SOC? Cutting Through Hype, Pricing Models, and SIEM Detection Efficacy with Raffy Marty

13

EP266 Resetting the SOC for Code War: Allie Mellen on Detecting State Actors vs. Doing the Basics

14

EP265 Beyond Shadow IT: Unsanctioned AI Agents Don't Just Talk, They Act!

15

EP264 Measuring Your (Agentic) SOC: Two Security Leaders Walk into a Podcast

16

EP263 SOC Refurbishing: Why New Tools Won't Fix Broken Processes (Even With AI)

17

EP262 Freedom, Responsibility, and the Federated Guardrails: A New Model for Modern Security

18

EP261 No More Aspiration: Scaling a Modern SOC with Real AI Agents

19

EP260 The Agentic IAM Trainwreck: Why Your Bots Need Better Permissions Than Your Admins

20

EP259 Why DeepMind Built a Security LLM Sec-Gemini and How It Beats the Generalists

21

EP258 Why Your Security Strategy Needs an Immune System, Not a Fortress with Royal Hansen

22

EP257 Beyond the 'Kaboom': What Actually Breaks When OT Meets the Cloud?

23

EP256 Rewiring Democracy & Hacking Trust: Bruce Schneier on the AI Offense-Defense Balance

24

EP255 Separating Hype from Hazard: The Truth About Autonomous AI Hacking

25

EP254 Escaping 1990s Vulnerability Management: From Unauthenticated Scans to AI-Driven Mitigation

26

EP253 The Craft of Cloud Bug Hunting: Writing Winning Reports and Secrets from a VRP Champion

27

EP252 The Agentic SOC Reality: Governing AI Agents, Data Fidelity, and Measuring Success

28

EP251 Beyond Fancy Scripts: Can AI Red Teaming Find Truly Novel Attacks?

29

EP250 The End of "Collect Everything"? Moving from Centralization to Data Access?

30

EP249 Data First: What Really Makes Your SOC 'AI Ready'?

31

EP248 Cloud IR Tabletop Wins: How to Stop Playing Security Theater and Start Practicing

32

EP247 The Evolving CISO: From Security Cop to Cloud & AI Champion

33

EP246 From Scanners to AI: 25 Years of Vulnerability Management with Qualys CEO Sumedh Thakar

34

EP245 From Consumer Chatbots to Enterprise Guardrails: Securing Real AI Adoption

35

EP244 The Future of SOAPA: Jon Oltsik on Platform Consolidation vs. Best-of-Breed in the Age of Agentic AI

36

EP243 Email Security in the AI Age: An Epic 2025 Arms Race Begins

37

EP242 The AI SOC: Is This The Automation We've Been Waiting For?

38

EP241 From Black Box to Building Blocks: More Modern Detection Engineering Lessons from Google

39

EP240 Cyber Resiliency for the Rest of Us: Making it Happen on a Real-World Budget

40

EP239 Linux Security: The Detection and Response Disconnect and Where Is My Agentless EDR

41

EP238 Google Lessons for Using AI Agents for Securing Our Enterprise

42

EP237 Making Security Personal at the Speed and Scale of TikTok

43

EP236 Accelerated SIEM Journey: A SOC Leader's Playbook for Modernization and AI

44

EP235 The Autonomous Frontier: Governing AI Agents from Code to Courtroom

45

EP234 The SIEM Paradox: Logs, Lies, and Failing to Detect

46

EP233 Product Security Engineering at Google: Resilience and Security

47

EP232 The Human Element of Privacy: Protecting High-Risk Targets and Designing Systems

48

EP231 Beyond the Buzzword: Practical Detection as Code in the Enterprise

49

EP230 AI Red Teaming: Surprises, Strategies, and Lessons from Google

50

EP229 Beyond the Hype: Debunking Cloud Breach Myths (and What DBIR Says Now)

51

EP228 SIEM in 2025: Still Hard? Reimagining Detection at Cloud Scale and with More Pipelines

52

EP227 AI-Native MDR: Betting on the Future of Security Operations?

53

EP226 AI Supply Chain Security: Old Lessons, New Poisons, and Agentic Dreams

54

EP225 Cross-promotion: The Cyber-Savvy Boardroom Podcast: EP2 Christian Karam on the Use of AI

55

EP224 Protecting the Learning Machines: From AI Agents to Provenance in MLSecOps

56

EP223 AI Addressable, Not AI Solvable: Reflections from RSA 2025

57

EP222 From Post-IR Lessons to Proactive Security: Deconstructing Mandiant M-Trends

58

EP221 Special - Semi-Live from Google Cloud Next 2025: AI, Agents, Security ... Cloud?

59

EP220 Big Rewards for Cloud Security: Exploring the Google VRP

60

EP219 Beyond the Buzzwords: Decoding Cyber Risk and Threat Actors in Asia Pacific

61

EP218 IAM in the Cloud & AI Era: Navigating Evolution, Challenges, and the Rise of ITDR/ISPM

62

EP217 Red Teaming AI: Uncovering Surprises, Facing New Threats, and the Same Old Mistakes?

63

EP216 Ephemeral Clouds, Lasting Security: CIRA, CDR, and the Future of Cloud Investigations

64

EP215 Threat Modeling at Google: From Basics to AI-powered Magic

65

EP214 Reconciling the Impossible: Engineering Cloud Systems for Diverging Regulations

66

EP213 From Promise to Practice: LLMs for Anomaly Detection and Real-World Cloud Security

67

EP212 Securing the Cloud at Scale: Modern Bank CISO on Metrics, Challenges, and SecOps

68

EP211 Decoding the Underground: Google's Dual-Lens Threat Intelligence Magic

69

EP210 Cloud Security Surprises: Real Stories, Real Lessons, Real "Oh No!" Moments

70

EP209 vCISO in the Cloud: Navigating the New Security Landscape (and Don't Forget Resilience!)

71

EP208 The Modern CISO: Balancing Risk, Innovation, and Business Strategy (And Where is Cloud?)

72

EP207 Slaying the Ransomware Dragon: Can a Startup Succeed?

73

EP206 Paying the Price: Ransomware's Rising Stakes in the Cloud

74

EP205 Cybersecurity Forecast 2025: Beyond the Hype and into the Reality

75

EP204 Beyond PCAST: Phil Venables on the Future of Resilience and Leading Indicators

76

EP203 Cloud Shared Responsibility: Beyond the Blame Game with Rich Mogull

77

EP202 Beyond Tiered SOCs: Detection as Code and the Rise of Response Engineering

78

EP201 Every CTO Should Be a CSTO (Or Else!) - Transformation Lessons from The Hoff

79

EP200 Zero Touch Prod, Security Rings, and Foundational Services: How Google Does Workload Security

80

EP199 Your Cloud IAM Top Pet Peeves (and How to Fix Them)

81

EP198 GenAI Security: Unseen Attack Surfaces & AI Pentesting Lessons

82

EP197 SIEM (Decoupled or Not), and Security Data Lakes: A Google SecOps Perspective

83

EP196 AI+TI: What Happens When Two Intelligences Meet?

84

EP195 Containers vs. VMs: The Security Showdown!

85

EP194 Deep Dive into ADR - Application Detection and Response

86

EP193 Inherited a Cloud? Now What? How Do I Secure It?

87

EP192 Confidential + AI: Can AI Keep a Secret?

88

EP191 Why Aren't More Defenders Winning? Defender's Advantage and How to Gain it!

89

EP190 Unraveling the Security Data Fabric: Need, Benefits, and Futures

90

EP189 How Google Does Security Programs at Scale: CISO Insights

91

EP188 Beyond the Buzzwords: Identity's True Role in Cloud and SaaS Security

92

EP187 Conquering SOC Challenges: Leadership, Burnout, and the SIEM Evolution

93

EP186 Cloud Security Tools: Trust the Cloud Provider or Go Third-Party? An Epic Debate, Anton vs Tim

94

EP185 SAIF-powered Collaboration to Secure AI: CoSAI and Why It Matters to You

95

EP184 One Week SIEM Migration: Fact or Fiction?

96

EP183 Cloud Security Journeys: Improve, Evolve, Transform with Cloud Customers

97

EP182 ITDR: The Missing Piece in Your Security Puzzle or Yet Another Tool to Buy?

98

EP181 Detection Engineering Deep Dive: From Career Paths to Scaling SOC Teams

99

EP180 SOC Crossroads: Optimization vs Transformation - Two Paths for Security Operations Center

100

EP179 Teamwork Under Stress: Expedition Behavior in Cybersecurity Incident Response

101

EP178 Meet Brandon Wood: The Human Side of Threat Intelligence: From Bad IP to Trafficking Busts

102

EP177 Cloud Incident Confessions: Top 5 Mistakes Leading to Breaches from Mandiant

103

EP176 Google on Google Cloud: How Google Secures Its Own Cloud Use

104

EP175 Meet Crystal Lister: From Public Sector to Google Cloud Security and Threat Horizons

105

EP174 How to Measure and Improve Your Cloud Incident Response Readiness: A New Framework

106

EP173 SAIF in Focus: 5 AI Security Risks and SAIF Mitigations

107

EP172 RSA 2024: Separating AI Signal from Noise, SecOps Evolves, XDR Declines?

108

EP171 GenAI in the Wrong Hands: Unmasking the Threat of Malicious AI and Defending Against the Dark Side

109

EP170 Redefining Security Operations: Practical Applications of GenAI in the SOC

110

EP169 Google Cloud Next 2024 Recap: Is Cloud an Island, So Much AI, Bots in SecOps

111

EP168 Beyond Regular LLMs: How SecLM Enhances Security and What Teams Can Do With It

112

EP167 Stolen Cards and Fake Accounts: Defending Google Cloud Against Abuse

113

EP166 Workload Identity, Zero Trust and SPIFFE (Also Turtles!)

114

EP165 Your Cloud Is Not a Pet - Decoding 'Shifting Left' for Cloud Security

115

EP164 Quantum Computing: Understanding the (very serious) Threat and Post-Quantum Cryptography

116

EP163 Cloud Security Megatrends: Myths, Realities, Contentious Debates and Of Course AI

117

EP162 IAM in the Cloud: What it Means to Do It 'Right' with Kat Traxler

118

EP161 Cloud Compliance: A Lawyer - Turned Technologist! - Perspective on Navigating the Cloud

119

EP160 Don't Cloud Your Judgement: Security and Cloud Migration, Again!

120

EP159 Workspace Security: Built for the Modern Threat. But How?

121

EP158 Ghostbusters for the Cloud: Who You Gonna Call for Cloud Forensics

122

EP157 Decoding CDR & CIRA: What Happens When SecOps Meets Cloud

123

EP156 Living Off the Land and Attacking Critical Infrastructure: Mandiant Incident Deep Dive

124

EP155 Cyber, Geopolitics, AI, Cloud - All in One Book?

125

EP154 Mike Schiffman: from Blueboxing to LLMs via Network Security at Google

126

EP153 Kevin Mandia on Cloud Breaches: New Threat Actors, Old Mistakes, and Lessons for All

127

EP152 Trust, Security and Google's Annual Transparency Report

128

EP151 Cyber Insurance in the Cloud Era: Balancing Protection, Data and Risks

129

EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw

130

EP149 Canned Detections: From Educational Samples to Production-Ready Code

131

EP148 Decoding SaaS Security: Demystifying Breaches, Vulnerabilities, and Vendor Responsibilities

132

EP147 Special: 2024 Google Cloud Security Forecast Report

133

EP146 AI Security: Solving the Problems of the AI Era: A VC's Insights

134

EP145 Cloud Security: Shared Responsibility, Shared Fate, Shared Faith?

135

EP144 LLMs: A Double-Edged Sword for Cloud Security? Weighing the Benefits and Risks of Large Language Models

136

EP143 Cloud Security Remediation: The Biggest Headache?

137

EP142 Cloud Security Podcast Ask Me Anything #AMA 2023

138

EP141 Cloud Security Coast to Coast: From 2015 to 2023, What's Changed and What's the Same?

139

EP140 System Hardening at Google Scale: New Challenges, New Solutions

140

EP139 What is Chronicle? Beyond XDR and into the Next Generation of Security Operations

141

EP138 Terraform for Security Teams: How to Use IaC to Secure the Cloud

142

EP137 Next 2023 Special: Conference Recap - AI, Cloud, Security, Magical Hallway Conversations

143

EP136 Next 2023 Special: Building AI-powered Security Tools - How We Do It?

144

EP135 AI and Security: The Good, the Bad, and the Magical

145

EP134 How to Prioritize UX and Security in the Cloud: UX as a Security Capability

146

EP133 The Shared Problem of Alerting: More SRE Lessons for Security

147

EP132 Chaos Engineering for Security: How to Improve Software Resilience with Kelly Shortridge

148

EP131 A Deep Dive into Google's Assured OSS: How Google Secures the Software You Use

149

EP130 Cloud is Secure: Are you Using It Securely - True or False?

150

EP129 How CISO Cloud Dreams and Realities Collide

151

EP128 Building Enterprise Threat Intelligence: The Who, What, Where, and Why

152

EP127 Is IAM Really Fun and How to Stay Ahead of the Curve in Cloud IAM?

153

EP126 What is Policy as Code and How Can It Help You Secure Your Cloud Environment?

154

EP125 Will SIEM Ever Die: SIEM Lessons from the Past for the Future

155

EP124 Safe Browsing: Lessons from How Google Secures Five Billion Devices at Low False Positive Rates

156

EP123 The Good, the Bad, and the Epic of Threat Detection at Scale with Panther

157

EP122 Firewalls in the Cloud: How to Implement Trust Boundaries for Access Control

158

EP121 What Happens Here Stays Here: Confidential City (and Space)

159

EP120 Building Secure Cloud and Building Security Products: Finding the Balance

160

EP119 RSA 2023 - What We Saw, What We Learned, and What We're Excited About

161

EP118 RSA 2023 - How to Protect Your Organization from Cyberattacks in a Time of Political Turmoil

162

EP117 Can a Small Team Adopt an Engineering-Centric Approach to Cybersecurity?

163

EP116 SBOMs: A Step Towards a More Secure Software Supply Chain

164

EP115 How to Approach Cloud in a Cloudy Way, not As Somebody Else's Computer?

165

EP114 Minimal Viable Secure Product (MVSP) - Is That a Thing?

166

EP113 Love it or Hate it, Network Security is Coming to the Cloud

167

EP112 Threat Horizons - How Google Does Threat Intelligence

168

EP111 How to Solve the Mystery of Application Security in the Cloud?

169

EP110 Detection and Response in a High Velocity and High Complexity Environment

170

EP109 How Google Does Vulnerability Management: The Not So Secret Secrets!

171

EP108 How to Hunt the Cloud: Lessons and Experiences from Years of Threat Hunting

172

EP 107 How Google Secures It's Google Cloud Usage at Massive Scale

173

EP106 Beyond BeyondProd - How Do You Zero Trust Your Workloads?

174

EP105 Security Architect View: Cloud Migration Successes, Failures and Lessons

175

EP104 CISO Walks Into the Cloud: And The Magic Starts to Happen!

176

EP103 Security Incident Response and Public Cloud - Exploring with Mandiant

177

EP102 Sunil Potti on Building Cloud Security at Google

178

EP101 Cloud Threat Detection Lessons from a CISO

179

EP100 2022 Accelerate State of DevOps Report and Software Supply Chain Security

180

EP99 Google Workspace Security: from Threats to Zero Trust

181

EP98 How to Cloud IR or Why Attackers Become Cloud Native Faster?

182

Special: Coordinated Release of Detection Rules for CobaltStike Abuse

183

EP96 Cloud Security Observability for Detection and Response

184

EP95 Cloud Security Talks Panel: Cloud Threats and Incidents

185

EP94 Meet Cloud Security Acronyms with Anna Belak

186

EP93 CISO Walks Into the Cloud: Frustrations, Successes, Lessons ... And Is My Data Secure?

187

Special: Sharing The Mic In Cyber with STMIC Hosts Lauren and Christina: Representation, Psychological Safety, Security

188

EP91 "Hacking Google", Op Aurora and Insider Threat at Google

189

Next 2022 Google Cybersecurity Action Team: One Year Later!

190

Next 2022 Can We Escape Ransomware by Migrating to the Cloud?

191

Next 2022 Improving Browser Security in the New Era of Work

192

Next 2022 Log4j Reflections, Software Dependencies and Open Source Security

193

EP86 How to Apply Lessons from Virtualization Transition to Make Cloud Transformation Better

194

EP85 Deploy Security Capabilities at Scale: SRE Explains How

195

EP84 How to Secure Artificial Intelligence (AI): Threats, Approaches, Lessons So Far

196

EP83 What Does reCAPTCHA Actually Do and How Does It Do it? Product Manager Explains

197

EP82 Mega-confused by XDR? You Are Not Alone! This XDR Skeptic Clarifies!

198

EP81 Demystify Data Sovereignty and Sovereign Cloud Secrets at Google Cloud

199

EP80 CISO Walks Into the Cloud: Frustrations, Successes, Lessons ... And Does the Risk Change?

200

EP79 Modernize Data Security with Autonomic Data Security Approach

201

EP78 Classic SOC Meets Cloud: What Changes? What Stays the Same?

202

EP77 Operational Realities of SOAR: Automate and/or Enrich, Playbooks, Magic

203

EP76 Powering Secure SaaS … But Not with CASB? Cloud Detection and Response?

204

EP75 How We Scale Detection and Response at Google: Automation, Metrics, Toil

205

EP74 Who Will Solve Cloud Security: A View from Google Investment Side

206

EP73 Your SOC Is Dead? Evolve to Output-driven Detect and Respond!

207

EP72 What Does Good Detection and Response Look Like in the Cloud? Insights from Expel MDR

208

EP71 Attacking Google to Defend Google: How Google Does Red Team

209

EP70 Special - RSA 2022 Reflections - Securing the Past vs Securing the Future

210

EP69 Cloud Threats and How to Observe Them

211

EP68 How We Attack AI? Learn More at Our RSA Panel!

212

EP67 Cyber Defense Matrix and Does Cloud Security Have to DIE to Win?

213

EP66 Is This Binary Legit? How Google Uses Binary Authorization and Code Provenance

214

EP65 Is Your Healthcare Security Healthy? Mandiant Incident Response Insights

215

EP64 Security Operations Center: The People Side and How to Do it Right

216

EP63 State of Autonomic Security Operations: Are There Sharks in Your SOC?

217

EP62 Protect Modern Applications in the Cloud: Union of APIs and Application Security

218

EP61 Anniversary Episode - What Did We Learn So Far on Cloud Security Podcast?

219

EP60 Impersonating Service Accounts in GCP and Beyond: Cloud Security Is About IAM?

220

EP59 Zero Trust: So Easy Even a Government Can Do It?

221

EP0 New Audio Trailer: Cloud Security Podcast by Google

222

EP58 SOC is Not Dead: How to Grow and Develop Your SOC for Cloud and Beyond

223

EP57 Stop Zero Days, Save the World: Project Zero's Maddie Stone Speaks

224

EP56 Rebuilding vs Forklifting and How to Secure a Data Warehouse in the Cloud

225

EP55 The Magic of Cloud Migration: Learn Security Lessons from the Field

226

EP54 Container Security: The Past or The Future?

227

EP53 Seven Years of SOAR: What's Next?

228

EP52 Securing AI with DeepMind CISO

229

EP51 Policy Intelligence: More Fun and Useful than it Sounds!

230

EP50 The Epic Battle: Machine Learning vs Millions of Malicious Documents

231

EP49 Lifesaving Tradeoffs: CISO Considerations in moving Healthcare to Cloud

232

EP48 Confidentially Speaking 2: Cloudful of Secrets

233

EP47 Megatrends, Macro-changes, Microservices, Oh My! Changes in 2022 and Beyond in Cloud Security

234

EP46 Products and Solutions: Helping Our Customers Precipitate Change

235

EP45 VirusTotal Insights on Ransomware Business and Technology

236

EP44 Evolving a SIEM for the Future While Learning from the Past

237

EP43 Automation as Paved Roads in Cloud Enablement

238

EP42 Missing Diversity Hurts Your Security

239

EP41 Beyond Phishing: Email Security Isn't Solved

240

EP40 2021: Phishing is Solved?

241

EP39 From False Positives to Karl Popper: Rationalizing Cloud Threat Detection

242

NEXT Special - 6 Cloud Security PMs (and a Developer Advocate!) Walk into a Studio

243

NEXT Special - Google Cybersecurity Action Team: What's the Story?

244

NEXT Special - Cloud Security and DEI: Being an Ally!

245

NEXT Special - Google Cloud NEXT Security: What to Watch?

246

EP34 Instrumenting Modern Application Stack for Detection and Response

247

EP33 Cloud Migrations: Security Perspectives from The Field

248

EP32 Can You Ever Know Thyself: Cloud Attack Surface Management

249

EP31 Cloud Certifications, and Cloud Security with TheCertsGuy

250

EP30 Malware Hunting with VirusTotal

251

Future of EDR: Is It Reason-able to Suggest XDR?

252

Tales from the Trenches: Using AI for Gmail Security

253

The Mysteries of Detection Engineering: Revealed!

254

SOC in a Large, Complex and Evolving Organization

255

Beyond Compliance: Cloud Security in Europe

256

Linking Up The Pieces: Software Supply Chain Security at Google and Beyond

257

Threat Detection at Google Cloud Security Summit

258

Securing Multi-Cloud from a CISO Perspective, Part 3

259

Security Marketing? Every Product Needs a Story!

260

Security Operations, Reliability, and Securing Google with Heather Adkins

261

Double-clicking, but not on fire hydrants, with bot fighters

262

More Cloud Migration Security Lessons

263

Modern Threat Detection at Google

264

Modern Data Security Approaches: Is Cloud More Secure?

265

Scaling Google Kubernetes Engine Security

266

Making Compliance Cloud-native

267

Application Security in the Cloud

268

Threat Models and Cloud Security

269

Preparing for Cloud Migrations from a CISO Perspective, Part 2

270

SIEM Modernization? Is That a Thing?

271

Building a Third Party Platform for Cloud Security

272

Zero Trust: Fast Forward from 2010 to 2021

273

No One Expects the Malware Inquisition

274

Cloud Security Talks Summarized: A Recap Episode

275

Preparing for Cloud Migrations from a CISO Perspective, Part 1

276

Gathering Data for Zero Trust

277

Automate and/or Die?

278

Data Security in the Cloud

279

Confidentially Speaking