Cloud Security Today

Zombie identities: the hidden threat in your cloud


Listen Later

Send us a text

Episode Summary

On this episode, Sandy Bird, CTO and Co-Founder of Sonrai Security, joins the show to discuss identity security in the Cloud. Prior to Sonrai Security, Sandy co-founded Q1 Labs, which was acquired by IBM. He then became the CTO and helped IBM Security grow to $2B in revenue.

Today, Sandy talks about his journey in cybersecurity and how to manage and eliminate dormant identities. Why should listeners be concerned about zombie identities? Hear about the permissions attack surface and where to start implementing zero trust policies.

Timestamp Segments

·       [01:41] Getting into cybersecurity.

·       [03:48] Key lessons from IBM.

·       [08:40] Zombie identities.

·       [12:53] Is it possible to manage and eliminate dormant identities?

·       [16:17] Tying the process into a CI/CD pipeline.

·       [21:01] The Dirty Dozen of Cloud Identity.

·       [24:13] The permissions attack surface.

·       [27:00] Zero Trust best practices.

·       [30:08] Creating nett new machine identities.

·       [33:17] Prioritizing identity misconfigurations.

·       [35:15] Sandy’s mentors and inspirations.

·       [37:37] How does Sandy stay sharp?

 

Sound Bites

"Nothing is a straight path in starting companies in your career."
"Zombie identities are identities that were part of previous projects and never get cleaned up."
"Fix the low-hanging fruit first, such as getting rid of zombie identities and locking down sensitive identities."

 

Relevant Links

Website:          sonraisecurity.com

LinkedIn:         Sandy Bird

Quantifying Cloud Access: Overprivileged Identities and Zombie Identities

...more
View all episodesView all episodes
Download on the App Store

Cloud Security TodayBy Matthew Chiodi

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

15 ratings


More shows like Cloud Security Today

View all
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

638 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,016 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

175 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Cloud Security Podcast by Cloud Security Podcast Team

Cloud Security Podcast

57 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

Cloud Security Podcast by Google by Anton Chuvakin

Cloud Security Podcast by Google

40 Listeners