
Sign up to save your podcasts
Or
In this episode we speak to Nick Jones, an expert in offensive cloud security and Head of Research at WithSecure to expose the biggest security gaps in cloud environments and why CNAPPs and CSPMs alone are not enough often.
With real-world examples from red team engagements and cloud security research, Nick shares insider knowledge on how attackers target AWS, Azure, and Kubernetes environments—and what security teams can do to stop them.
Guest Socials: Nick's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:40) A bit about Nick Jones
(03:56) How has Cloud Security Evolved?
(05:52) Why do we need pentesting in Cloud Security?
(08:09) Misconfiguration vs Vulnerabilities
(11:04) Cloud Pentesting in Different Environments
(17:05) Impact of Kubernetes Adoption on Offensive Cloud Security
(20:19) Planning for a Cloud Pentest
(29:04) Common Attacks Paths in Cloud
(33:05) Mitigating Common Risk in Cloud
(35:14) What is Detection as Code?
(41:17) Skills for Cloud Pentesting
(45:28) Fun Sections
5
5454 ratings
In this episode we speak to Nick Jones, an expert in offensive cloud security and Head of Research at WithSecure to expose the biggest security gaps in cloud environments and why CNAPPs and CSPMs alone are not enough often.
With real-world examples from red team engagements and cloud security research, Nick shares insider knowledge on how attackers target AWS, Azure, and Kubernetes environments—and what security teams can do to stop them.
Guest Socials: Nick's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
-Cloud Security Podcast- Youtube
- Cloud Security Newsletter
- Cloud Security BootCamp
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction
(02:40) A bit about Nick Jones
(03:56) How has Cloud Security Evolved?
(05:52) Why do we need pentesting in Cloud Security?
(08:09) Misconfiguration vs Vulnerabilities
(11:04) Cloud Pentesting in Different Environments
(17:05) Impact of Kubernetes Adoption on Offensive Cloud Security
(20:19) Planning for a Cloud Pentest
(29:04) Common Attacks Paths in Cloud
(33:05) Mitigating Common Risk in Cloud
(35:14) What is Detection as Code?
(41:17) Skills for Cloud Pentesting
(45:28) Fun Sections
361 Listeners
629 Listeners
153 Listeners
368 Listeners
1,011 Listeners
201 Listeners
313 Listeners
925 Listeners
7,821 Listeners
164 Listeners
188 Listeners
310 Listeners
78 Listeners
119 Listeners
33 Listeners