Cloud Security Podcast by Google

EP258 Why Your Security Strategy Needs an Immune System, Not a Fortress with Royal Hansen


Listen Later

Guest:

  • Royal Hansen, VP of Engineering at Google, former CISO of Alphabet

Topics:

  • The "God-Like Designer" Fallacy: You've argued that we need to move away from the "God-like designer" model of security—where we pre-calculate every risk like building a bridge—and towards a biological model. Can you explain why that old engineering mindset is becoming risky in today's cloud and AI environments?
  • Resilience vs. Robustness: In your view, what is the practical difference between a robust system (like a fortress that eventually breaks) and a resilient system (like an immune system)? How does a CISO start shifting their team's focus from creating the former to nurturing the latter?
  • Securing the Unknown: We're entering an era where AI agents will call other agents, creating pathways we never explicitly designed. If we can't predict these interactions, how can we possibly secure them? What does "emergent security" look like in practice?
  • Primitives for Agents: You mentioned the need for new "biological primitives" for these agents—things like time-bound access or inherent throttling. Are these just new names for old concepts like Zero Trust, or is there something different about how we need to apply them to AI?
  • The Compliance Friction: There's a massive tension between this dynamic, probabilistic reality and the static, checklist-based world of many compliance regimes. How do you, as a leader, bridge that gap? How do you convince an auditor or a board that a "probabilistic" approach doesn't just mean "we don't know for sure"?
  • "Safe" Failures: How can organizations get comfortable with the idea of designing for allowable failure in their subsystems, rather than striving for 100% uptime and security everywhere?

Resources:

  • Video version
  • EP189 How Google Does Security Programs at Scale: CISO Insights
  • BigSleep and CodeMender agents
  • "Chasing the Rabbit" book
  • "How Life Works: A User's Guide to the New Biology" book
...more
View all episodesView all episodes
Download on the App Store

Cloud Security Podcast by GoogleBy Anton Chuvakin

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

39 ratings


More shows like Cloud Security Podcast by Google

View all
WSJ Your Money Briefing by The Wall Street Journal

WSJ Your Money Briefing

1,721 Listeners

WSJ What’s News by The Wall Street Journal

WSJ What’s News

4,383 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,005 Listeners

Risky Business by Patrick Gray

Risky Business

372 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,032 Listeners

NVIDIA AI Podcast by NVIDIA

NVIDIA AI Podcast

346 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,092 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

178 Listeners

Practical AI by Practical AI LLC

Practical AI

201 Listeners

Cloud Security Podcast by TechRiot.io

Cloud Security Podcast

58 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

Huberman Lab by Scicomm Media

Huberman Lab

29,396 Listeners

The AI Daily Brief: Artificial Intelligence News and Analysis by Nathaniel Whittemore

The AI Daily Brief: Artificial Intelligence News and Analysis

639 Listeners

HBR On Leadership by Harvard Business Review

HBR On Leadership

170 Listeners

AI Security Podcast by Kaizenteq Team

AI Security Podcast

9 Listeners