SilverLining IL

SilverLining IL

Download on the App Store

SilverLining IL episodes

  • SilverLining Episode 39: Securing API Services

    Attendees

    Guest: Oz Avenstein

    Guest Title: Founder & CEO @ Avensec - Cloud & Application Security

    Topic: Securing API Services

     

    Abstract

    The applicative infrastructure is becoming more and more complex due to different requirements, design patterns, and technologies. In many of these cases, one of those requirements is to connect other parties to systems, and in other cases, to connect systems to other parties. Nowadays, the most common connection method is to use Application Programming Interfaces (APIs). In this episode we spoke with Oz Avenstein, co-author of the CSA Security Guidelines for Providing and Consuming APIs about the guidelines creation process and how organizations should secure access to API resources.

    30 min
  • SilverLining Episode 38: Cloud Native Security Foundations

    Attendees

    Guest: Gadi Naor 

    Guest Title: VP Software Engineering, Cloud Security @ Rapid7

    Topic: Cloud Native Security Foundations

    Abstract

    Lately, The CNCF (Cloud Native Computing Foundation) released the cloud native security whitepaper: the first release of security guidelines for organizations who adopt cloud native approaches. In order to better understand the guidelines, we hosted Gadi Naor, VP Software Engineering, Cloud Security @ Rapid7, and co-author of the guidelines, for a conversation about what is cloud native security and why & how organizations should adopt this approach.

    33 min
  • SilverLining Episode 37: Software Package Dependencies Attacks
    Attendees

    Guest: Tzachi Zornstain

    Guest Title: Co-Founder & CEO, Dustico

    Topic: Software Package Dependencies Attacks

    Abstract

    Supply chain and software dependencies attacks are becoming more popular, and organizations are having a hard time coping with those types of vectors. In this episode, we spoke with Tzach Zornstain, Co-Founder at Dustico, about the difference between malicious software and vulnerable software, and how organizations should use 3rd party software for the development of their own applications securely.

    28 min
  • Episode 36: Wiz

    Attendees

    Guest: Yinon Costica

    Guest title: VP Product 

    Abstract

    Wiz is the new star in the cloud security market, founded by veterans with a proven record and raised over $100M in less than a year of operations. In this episode, we talked with Yinon Costica, Co-Founder and VP Product at Wiz, about cloud security challenges, how is Wiz different from others, and how are they going to disrupt the market. 

    31 min
  • Episode 35: Compliance Automation and Zero Trust Containers
    Sponsored By:
     
    ‍‍
    Attendees
    Guest: Malgorzata (Gosia) Steinder
    Guest title: CTO of Hybrid Cloud Research. IBM research
    Topic: Compliance automation and zero trust containers

     

    Abstract

    Continuous monitoring, containers, zero trust, confidential computing - those are all examples of technologies that will be the main focus in the upcoming years. In this episode, we hosted Malgorzata (Gosia) Steinder, CTO of Hybrid Cloud Research at IBM, who provided her vision on how all those technologies mentioned above, should be integrated into highly secure applications deployments.

     

    Links: 
    • NIST OSCAL standard: https://pages.nist.gov/OSCAL/
    • Automated compliance Open Source tool  by IBM  https://github.com/IBM/compliance-trestle
    • Security monitoring open source tool by IBM:  https://www.ibm.com/blogs/research/2020/01/sysflow/
    • workload identity: https://developer.ibm.com/solutions/security/articles/protecting-data-using-secret-management-trusted-service-identity/
    •  

       

      34 min
    • Episode 34: PayPal cloud journey

      Attendees

      Guest: Assaf Keren

      Guest Title: VP, Enterprise Cyber Security

      Company: PayPal

      Abstract

      PayPal is one of the most interesting organizations in the world in terms of security. The combination of online presence with the unique line of business is making PayPal one of the most secure hi-tech companies and one of the most innovative financial institutions. 

      In this episode, we hosted Assaf Keren, VP of enterprise cyber security, for a discussion about PayPal’s cloud journey from traditional on-premise to the multi-cloud / multi-locations giant they are now, and how COVID-19 is changing Paypal’s digital journey with their customers & employees.

       

       

      50 min
    • Episode 33: Researching Cloud Vulnerabilities

      Attendees

      Guest: Asaf Hecht 

      Guest Title: Security research team leader

      Company: CyberArk 

      Abstract

      With the growth of cloud services, more knowledge is gathered on vulnerabilities and misconfigurations in cloud infrastructure. A great deal of this knowledge is coming from cloud security researchers. In this episode, we host Asaf Hecht, Security research team leader At Cyberark, for a conversation about cloud security research and the vulnerabilities they disclose are various cloud vendors. 

      32 min
    • Episode 32: Understanding Infrastructure as Code and How to Use it Effectively

      Attendees

      Guest: Ohad Maislish 

      Guest Title: Co-Founder & CEO 

      Company: env0

      Abstract

      Infrastructure as code is one of the most interesting technologies in the market. It enables organizations to deploy heavy workloads within seconds and avoid risky configuration mistakes. In this episode, we talked with Ohad Maislish, Co-Founder and CEO at env0, about infrastructure as code technology, how and where it is being used, and how env0 helps organizations to better utilize this technology.

      Timing

      0:00 introducing our guest

      2:26 What is infrastructure as a code

      10:16 Examples for practical deployment of IaaC

      13:55 How IaaC is helping governance 

      19:20 IaaC behind the scenes

      25:18 IaaC in a multi-cloud environment

      28:40 Summary and last words

      32 min
    • Episode 31: Understanding Cloud Native Security Basics

      Attendees

      Guest: Benjy Portnoy

      Guest Title: Sr. Director, Solution Architects

      Company: Aqua Security

      Abstract

      A cloud-native security strategy entails protecting the infrastructure, build, and running workloads. In this episode, we spoke with Benjy Portnoy, Sr Director of Solution Architects at Aqua Security regarding cloud-native security fundamentals. We also delve into various attacks identified in the recently published Cloud Native Threat Report by Aqua's security research team, Nautilus.

      Timing

      0:00 introducing our guest

      2:50 what is cloud native security

      5:11 Sorting out between CWPP, CSPM & DevSecOps

      8:01 Protecting the build, the platform and workload

      10:30 Understanding what is CASB 

      12:45 diving into the kinsing attack

      29.11 Summary and last words

      33 min
    • Episode 30:  The challenges of CISO in a security company

      Attendees

      Guest: Eitan Satmary

      Guest Title: CISO 

      Company: Tufin

      Abstract

      Being a CISO is challenging, being a CISO at a security vendor is even more challenging. In this episode we host Eitan Satmary, CISO for Tufin, to talk about the good and bad of being a CISO in a cyber security vendor. We will talk about CISO's ability to influence innovation and product roadmap in the company and how the transition from on-prem offering to SaaS offering changed the company's security posture.

      Timing:

      0:00 introducing our guest

      4:20 CISO in a security company:  influence the innovation team

      10:30 the relationship between CISO and the sales department

      12:30 the company journey of adding cloud capabilities

      15:00 CISO’s first steps

      20:11 Risk management considerations for SaaS companies

      25:00  Summary and final thoughts

      30 min

    About SilverLining IL

    From the publisher's feed

    The podcast for Security Architecture