
Sign up to save your podcasts
Or


Sponsored By:
Attendees
Guest: Arick Goomanovsky
Guest title: Co-Founder & Chief Business Officer
Company: Ermetic
In cloud platforms, identity and permissions are the most important control that customers get to implement. Network segmentation and other traditional controls are often ineffective and access to resources is determined by a mixture of roles & policies. This mixture can become very complex and difficult to lock down. In this episode, we are hosting Arick Goomanovsky, Chief Business Officer at Ermetic, to discuss Cloud identity and access challenges, and to review real life examples of what can happen when neglecting identity and access entitlements in cloud infrastructure.
Mail to: [email protected]
Timing:
0:00 Introducing our guest and Ermetic
2:21 Understanding Identity Governance
4:40 Cloud identity challenges
10:55 Dealing with identity challenges by adding visualization and analysis of permissions
16:30 Who are the organizational stakeholders relevant?
22:01 Examples for IAM challenges and outbreaks
22:25 Example 1: Protecting sensitive resources
26:25 Example 2: Third party access
29:49 Example 3: The visibility challenge when using SSO
31:30 Summary and final words
Attendees
Guest: Ofer Maor
Guest title: Co-Founder & CTO
Company: Mitiga
Abstract
The recent increase of cloud based attacks gives us an opportunity to examine new attack vectors and how attackers exploit new services. In this episode we talked with Ofer Maor, Co-Founder at Mitiga, about new attack vectors in cloud computing and how attackers exploit new services such as marketplaces, community repos and other examples.
Timing:
0:00 Introducing our guest and Mitiga
3:32 Preparing for cloud incident response
7:15 Cloud attack vector - malicious AMI
11:00 More attack vectors on marketplaces
13:18 Github attack vectors
18:15 attack vector - Business email compromise on 365
25:44 how to mitigate cloud incidents
27:58 Summary and last words
Attendees
Guest: Dalit Ben Israel
Guest title: Partner, head of IT & Data protection practice
Company: Naschitz Brandes Amir
In the cloud era, the information security officer's new best friends are the lawyers in the legal department. Legal matters such as cross border data transfers, contractual controls and privacy laws becoming critical in cloud migrations. In this episode we talk with Dalit Ben Israel, Partner at NBlaw, about the legal challenges of cloud computing: cross border transfers, the rise of privacy laws and proper contract management and monitoring.
Timing:
0:00 - Opening
2:03 - Introduction of our guest
4:95 - Considerations of data center location and the effect of the Schrems2 judgement invalidating the Privacy shield
12:50 - The roles and responsibilities of cloud providers and customers
15:27 - Choosing cloud providers - why do we need lawyers in the process and the obligation to enter into DPAs
20:00 - Specific challenges with SaaS and agreements with subprocessors
22:12 – Negotiating cloud contracts - what are the challenges? minimizing risks.
30:32 - Dispute resolution and venue of jurisdiction
33:24 - Ongoing contract monitoring
36:10 - Summary
Connect with Dalit here:
Email: [email protected]
Website: www.nblaw.com
This is a special episode where both of us (Moshe & Ariel – no guests this time) discuss the future of cloud computing and challenges that should be solved. We take a detailed look at shortage in manpower and knowledge, privacy laws and their influence on innovation and technology challenges such as multi tenancy, APi’s, encryption, continuous monitoring and more.
Opening words - 5 min
People
Process
Technology
Closure (5 min)
Attendees
Guest: Shira Shamban
Guest title: CEO & Co-Founder
Company: Solvo
Abstract
In modern cloud environments, Identity and Access Management controls are crucial controls. Many of the access decisions are now made not based on networking structure but rather on roles and permissions. In this episode we talk (again) with Shira Shamban, founder at Solvo about cloud IAM challenges - why is it so hard to get IAM right and how Solvo is planning to revolutionize the IAM management process.
Timing:
0:00 Introducing our guest
3:00 Introducing cloud identity challenges
6:20 Why role management is not enough
11:40 Why we fail to create least-privilege-roles
15:10 How to manage IAM securly - the people angle
18:13 How to manage IAM securly - the process angle
21:08 How to manage IAM securly - the technology angle
31:08 Summary and last words
Attendees
Guest: Dima Revelis
Guest title: Senior Devops engineer
Company: MoonActive
Abstract
DevsecOps is accelerating fast as the new buzzword for modern information security practices. In this episode we use the expertise of Dima Revelis in order to dive deep into understanding DevOps practices, what is CI/ CD pipeline and which security tools are relevant for all of those new practices.
Timing:
0:00 - Introducing our guest
2:50 - What is devops
7:50 - What is deployment pipeline
14:20 - What is CI and which security testing can be implemented
17:20 - What is CD and which security consideration
18:40 - Dive deeper into security testing - QA, code review, static & dynamic analysis
20:45 - So much automation, do we still need manual testing?
22:30 - Additional security aspects: using Jenkins, authentication and authorization, secret management
26:40 - Availability considerations and disaster recovery
33:30 - Summary and final words
Attendees
Guest: Yoad Dvir
Guest title: Security Lead, Central and Eastern Europe
Company: Microsoft
Abstract
Microsoft security portfolio has been growing and diversifying in the last couple of years, adding more capabilities at various areas of information security. In order to better understand Microsoft strategy and offering, we talked with Yoad Dvir, Cyber Security Lead at Microsoft, about the Microsoft new security pillars: Monitoring, Threat Protection and Information Protection.
Timing:
0:00 - Introducing our guest
5:45 - Introducing Microsoft security strategy
12:50 - Security monitoring pillars - Azure monitor, Sentinel, Azure analytics and more
21:10 - Microsoft Threat Protection family - Cloudapp, O365 ATP, Defender ATP, Azure ATP
30:50 - diving deeper into Cloudapp
35:30 - Microsoft Information Protection
44:00 - summary and last words
Attendees
Guest: Liran Tal
Guest title: Developer Advocate
Company: Synk
Abstract
Open source software takes a big part in our daily lives, and also in our development environments. Many applications developers rely on open source libraries & tools and integrating it into their code. This is a great improvement for developers allowing them to innovate quickly and efficiently. But all this good comes with a big responsibility - open source software should be carefully examined in order to make sure its reliability. In this episode we talk with Liran Tal from Synk about the growing importance of adding security evaluation of open source software in the development cycle.
Timing:
0:00 introducing our guest
5:50 what is the challenge of open-source security
10:05 - open source security - the people angel
16:00 - open source security - the process angel
24:55 - open source security - the technology angel
29:42 summary and last words
Attendees
Guest: Eran Feigenbaum
Guest title: CSO, Oracle Cloud
Abstract
The first generation of cloud services began about 15 years ago and stretched until now, but it came with many built-in challenges due to lack of maturity and the fact that security was added on top and not present from the start. In this episode we talk with Eran Feigenbaum, CISO of Oracle cloud about the next generation of cloud services - how can we build cloud that is more secure,, immuned to miss-configuration and other pitfalls that are relevant to today's cloud services.
Timing:
0:00 introducing our guest
5:40 Generation one of cloud infrastructure
8:40 so what is second generation of cloud infrastructure
10:30 how Oracle is planning to change the cloud market
11:40 how second generation cloud services can help with common mistakes such as misconfiguration
13:35 what cloud provider should do in order to increase security
16:05 how cloud providers can be proactive with their customers
19:00 handling miss-configuration such as open buckets and lost API’s keys
23:40 summary and last words
Attendees
Guest: Menny Barzilay
Guest title: Partner @ Herzog Strategic, CTO, ICRC, Tel Aviv University
Abstract
For our 20’ish episode we spoke with a very special guest, the one and only - Menny Barzilay. Menny is one of the most interesting speakers in the cyber landscape, he is an expert in simplifying complex concepts, integrating interesting stories and great examples into stimulating review of technology challenges we are facing as a community.
In this episode we talk with Menny about Privacy - why it is so hard to define what exactly is privacy in the modern age, what people miss about the concepts of privacy and how this affects our everyday lives. This talk will make you laugh, will make you sad and definitely will make you think. We hope you will enjoy listening to it as much as we enjoyed recording it.
Comment: since this is more of a lecture and not a regular podcast, we didn't add our regular podcast timing. Enjoy!
Timing:
0:00 introducing our guest
5:25 Privacy
From the publisher's feed