Stay current on new cloud trends. Top software companies, respected industry analysts, and experienced consultants join Amazon Web Services leaders to talk abou...
Ep076: Incident Response in the Age of Personal CISO Liability with Suresh Vasudevan of Sysdig
Suresh Vasudevan, CEO of Sysdig, discusses the evolving challenges of cloud security incident response and the need for new approaches to mitigate organizational risk.Topics Include:Cybersecurity regulations mandate incident response reporting.Challenges of cloud breach detection and response.Complex cloud attack patterns: reconnaissance, lateral movement, exploit.Rapid exploitation - minutes vs. days for on-prem.Importance of runtime, identity, and control plane monitoring.Limitations of EDR and SIEM tools for cloud.Coordinated incident response across security, DevOps, executives.Criticality of pre-defined incident response plans.Increased CISO personal liability risk and mitigation.Documenting security team's diligence to demonstrate due care.Establishing strong partnerships with legal and audit teams.Covering defensive steps in internal communications.Sysdig's cloud-native security approach and Falco project.Balancing prevention, detection, and response capabilities.Integrating security tooling with customer workflows and SOCs.Providing 24/7 monitoring and rapid response services.Correlating workload, identity, and control plane activities.Detecting unusual reconnaissance and lateral movement behaviors.Daisy-chaining events to identify potential compromise chains.Tracking historical identity activity patterns for anomaly detection.Aligning security with business impact assessment and reporting.Adapting SOC team skills for cloud-native environments.Resource and disruption cost concerns for cloud agents.Importance of "do no harm" philosophy for response.Enhancing existing security data sources with cloud context.Challenges of post-incident forensics vs. real-time response.Bridging security, DevOps, and executive domains.Establishing pre-approved incident response stakeholder roles.Maintaining documentation to demonstrate proper investigation.Evolving CISO role and personal liability considerations.Proactive management of cyber risk at board level.Developing strong general counsel and audit relationships.Transparency in internal communications to avoid discovery risks.Security teams as business partners, not just technicians.Sysdig's cloud security expertise and open-source contributions.Participants:· Suresh Vasudevan – CEO, SysdigSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/
--------
34:20
Ep075: Beyond Compliance: Crafting Effective Security Culture with leaders from Clumio, Mongo DB, Symphony and AWS
From hard-coded credentials to boardroom buy-in, join four tech security leaders from Clumio, Mongo DB, Symphony and AWS, as they unpack how building the right security culture can be your organization's strongest defense against cyber threats.Topics Include:Security culture is crucial for managing organizational cyber riskGood culture enables quick decision-making without constant expert consultationMany security incidents occur from well-meaning people getting dupedPanel includes leaders from AWS, Symphony, MongoDB, and ClumioMeasuring security culture requires both quantitative and qualitative metricsBoard-level engagement indicates organizational security culture maturitySelf-reporting of security incidents shows positive cultural developmentSecurity committees' participation helps measure cultural engagementHard-coded credentials remain persistent problem across organizationsInternal audits and risk committees strengthen security governancePublic security incidents change board conversations about prioritiesLeadership vulnerability and transparency help build trustBeing pragmatic beats emotional responses in security leadershipSecurity programs should align with business revenue goalsCustomer security requirements drive program improvementsExcessive security questionnaires drain resources from actual securitySecurity culture started as exclusionary, evolved toward collaborationFinancial institutions often create unnecessary compliance burdenEarly security involvement in product development prevents delaysSecurity teams must match development team speedTrust between security and development teams enables efficiencySmall security teams can support large enterprise requirementsVendor partnerships help scale security capabilitiesProcess changes work better than adding security toolsSecurity leaders need deep business knowledgeTechnical depth and breadth remain essential skillsEvangelism capability critical for security leadership successInfluencing without authority key for security effectivenessCrisis moments create opportunities for security improvementSocializing between security and development teams builds trustDEF CON attendance helps developers understand security perspectiveBug bounty programs provide continuous security feedbackRegular informal meetings between teams improve collaborationBuilding personal relationships improves security outcomesModern security leadership requires balance of IQ and EQParticipants:Jacob Berry – Head of Information Security, ClumioGeorge Gerchow – Interim CISO, Head of Trust, Mongo DBBrad Levy – Chief Executive Officer, SymphonyBrendan Staveley – Global Sales Leader, Security Services, Amazon Web ServicesSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/
--------
47:28
Ep074: Unlocking Global Growth - Mastering Compliance Across Boundaries
AWS executive Giancarlo Casella explains how organizations can navigate global privacy regulations and achieve compliant international expansion using AWS's privacy reference architecture.Topics Include:Welcome to executive forum on security and Gen AIIntroduction of Giancarlo Casella from AWS Security Assurance ServicesAWS helps organizations with compliance and audit readinessGlobal expansion requires understanding local privacy lawsGermany and France interpret GDPR differentlyGermany has Federal Data Protection Act (BDSG)France focuses on consumer privacy through CENILRisk of non-compliance includes fines and reputation damagePrivacy laws existed in only 10 countries in 2000EU Privacy Directive of 1990 was prominentBy 2010, forty countries had privacy lawsHIPAA and GLBA introduced in United StatesNow over 150 countries have privacy regulations75% of world population under privacy laws soonRegulations are vague and open to interpretationGDPR example: encryption requirements lack specificityNeed right stakeholders for privacy complianceLegal team must lead privacy interpretationEngineering implements technical privacy aspectsRisk and compliance teams coordinate evidence gatheringData Protection Officer oversees entire programCIO, CTO, CISO alignment creates strong foundationSecurity transforms from bureaucratic to revenue enablerAWS develops cloud-specific privacy reference architectureIndustry standards provide guidance frameworksAWS privacy reference architecture focuses on cloud specificsData minimization and individual autonomy are keyCase study: Middle Eastern AI company expands to CanadaCompany used CCTV at gas stationsCreated privacy baseline and roadmapData flow documentation essential for complianceContinuous compliance strategy helps enable successAligning stakeholders across different organizational linesFuture of US federal privacy regulation discussedDiscussion of responsible AI usage requirementsParticipants:Giancarlo Casella - Head of Business Development and Growth Strategies, AWS Security Assurance ServicesSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/
--------
27:56
Ep073: The Evolving Threat Landscape – Reshaping Cybersecurity Practices
Haggai Polak – Chief Product Officer, Securonix and a veteran cybersecurity expert examines how artificial intelligence, quantum computing, and resource constraints are fundamentally transforming the threat landscape for security leadersTopics Include:AI transformation of cybersecurity landscape from past tactical focusCISO accountability and regulatory pressures increasing significantlyAttack surface expanding beyond traditional network boundariesQuantum computing threatens current cryptographic protectionsDefenders remain understaffed and outmatched against sophisticated threatsSecuronix leads SIEM/SOAR space with 1000+ global customersWorld Economic Forum identifies misinformation/disinformation as major crisisAI benefits attackers more than defenders currentlySmall/medium enterprises falling below cyber poverty lineAI enables faster, more sophisticated malware developmentDeepfakes caused $25M loss in Hong Kong CFO impersonationDigital tsunami: broadband, IoT, cloud everywhere expanding attack surface50+ democracies face election security challenges in 2024Cloud intrusions increased 75% between 2022-2023Quantum-resistant cryptography transition needed within 10 yearsSEC regulations require specific cybersecurity incident disclosure guidelines4 million unfilled cybersecurity positions globallyCybercrime-as-a-Service growing, estimated $1.6B annual revenue81% of organizations faced ransomware attacks in 2023Insider threats increasing with remote work adoption30,000+ vulnerabilities published last year, half critical/highMean time to exploit now 44 daysSecuronix Eon leverages AI to increase analyst efficiencyDark web selling corporate credentials for $10,000Balance needed between protection and detection/response investmentsParticipants:Haggai Polak – Chief Product Officer, SecuronixSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/
--------
32:50
Ep072: From Alerts to Action - How Datadog Manages Security Incidents with AI
Dr. Yanbing Li, Chief Product Officer at Datadog, outlines how the company has integrated AI and automation into its incident response framework, helping customers manage both traditional security challenges and emerging AI-specific risks.Topics Include:Introduced talk about incident response and CISO liabilityDatadog founded 14 years ago for cloud-based developmentPlatform unifies observability and security for cloud applicationsCurrent environment has too many fragmented security productsSEC requires material incident reporting within four daysDatadog's incident response automates Slack room creationResponse team includes Legal, Security, Engineering, and ProductSystem tracks non-material incidents to identify concerning patternsReal-time telemetry data drives incident management automationOn-call capabilities manage escalation workflowsDatadog uses own products internally for incident responseCompany focuses on reducing time to incident detectionAI brings new risks: hallucination, data leaks, design exploitationBits.ai launched as LLM-based incident management co-pilotTool synthesizes events and generates incident summariesBits.ai suggests code remediation and creates synthetic testsSecurity built into AI products from initial designPrompt injection prevented through structured validation approachSensitive data anonymized before LLM processingEngineering and security teams collaborate closely on AILLM observability becoming critical for production deploymentsCustomers need monitoring for hallucinations and token usageDatadog extends infrastructure monitoring into security naturallyCompany maintains strong partnership with AWSQ&A covered Bits.ai proactive capabilities and enterprise differentiationParticipants:Yanbing Li – Chief Product Officer - DatadogSee how Amazon Web Services gives you the freedom to migrate, innovate, and scale your software company at https://aws.amazon/isv/
--------
23:44
Más podcasts de TecnologíaMás podcasts de Tecnología
Stay current on new cloud trends. Top software companies, respected industry analysts, and experienced consultants join Amazon Web Services leaders to talk about the cloud topics that matter to you—including the latest in AI, migration, Software-as-a-Service, and more. We produce new episodes regularly.