Cloud Security Podcast by Google

EP215 Threat Modeling at Google: From Basics to AI-powered Magic


Listen Later

Guest:

  • Meador Inge, Security Engineer, Google Cloud

 Topics:

  • Can you walk us through Google's typical threat modeling process? What are the key steps involved?
  • Threat modeling can be applied to various areas. Where does Google utilize it the most? How do we apply this to huge and complex systems?
  • How does Google keep its threat models updated? What triggers a reassessment?
  • How does Google operationalize threat modeling information to prioritize security work and resource allocation? How does it influence your security posture?
  • What are the biggest challenges Google faces in scaling and improving its threat modeling practices? Any stories where we got this wrong?
  • How can LLMs like Gemini improve Google's threat modeling activities? Can you share examples of basic and more sophisticated techniques?
  • What advice would you give to organizations just starting with threat modeling? 

Resources:

  • EP12 Threat Models and Cloud Security
  • EP150 Taming the AI Beast: Threat Modeling for Modern AI Systems with Gary McGraw
  • EP200 Zero Touch Prod, Security Rings, and Foundational Services: How Google Does Workload Security
  • EP140 System Hardening at Google Scale: New Challenges, New Solutions
  • Threat Modeling manifesto
  • EP176 Google on Google Cloud: How Google Secures Its Own Cloud Use
  • Awesome Threat Modeling
  • Adam Shostack “Threat Modeling: Designing for Security” book
  • Ross Anderson “Security Engineering”  book
  • ”How to Solve It” book
...more
View all episodesView all episodes
Download on the App Store

Cloud Security Podcast by GoogleBy Anton Chuvakin

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

38 ratings


More shows like Cloud Security Podcast by Google

View all
Risky Business by Patrick Gray

Risky Business

363 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

632 Listeners

The Cloudcast by Massive Studios

The Cloudcast

154 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

370 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,010 Listeners

AWS Podcast by Amazon Web Services

AWS Podcast

200 Listeners

Smashing Security by Graham Cluley & Carole Theriault

Smashing Security

313 Listeners

Click Here by Recorded Future News

Click Here

387 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

142 Listeners

Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

Kubernetes Podcast from Google

182 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

182 Listeners

Hacking Humans by N2K Networks

Hacking Humans

309 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

72 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

120 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners