Go offline with the Player FM app!
Mindset: Modern SOC Strategies for Cloud & Kubernetes (Ft Sergej Epp. Ex-Deutsche Bank)
Manage episode 478825674 series 2853525
Join Ashish Rajan in this episodeas he dives deep into the evolving world of cloud security with Sergej Epp, formerly of Deutsche Bank and Palo Alto Networks, now with Sysdig.
Discover why traditional security approaches fall short in today's dynamic cloud-native environments, where workloads resemble swarms of drones rather than predictable trains. Sergej explains the critical shift from basic posture management (CSPM/CNAPP) towards runtime security, emphasizing the need for an "assume breach" mindset.
Learn about the staggering reality that over 60% of containers now live for less than a minute and the immense challenges this poses for detection, incident response, and forensics.
This episode covers:
- The evolution from traditional security to cloud-native and runtime security.
- Why CNAPP/CSPM is like a map, but runtime security is the essential radar.
- The complexities of modern incident response with ephemeral workloads.
- Key strategies for Security Operations Centers (SOC) adapting to the cloud.
- The importance of visibility, data collection, and tools for hybrid and even air-gapped environments.
- How AI is starting to aid security operations and forensics.
Guest Socials: Sergej Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction: Cloud Security & The One-Minute Container Problem
(01:31) Meet Sergej Epp: 20+ Years in Cybersecurity (Deutsche Bank, Palo Alto, Sysdig)
(02:44) What is Cloud Native Today? From Train Stations to Airports with Drones
(05:34) Runtime Security Explained: Why It's Crucial Now
(11:05) The Evolution of Cloud Security: Beyond Basic Posture Management
(13:49) Incident Response Evolution: Tackling One-Minute Containers
(18:34) Who Needs Runtime Security? Platform Engineers, SOC Teams & More
(21:01) Runtime Security as a Platform: Beyond Detection to Prevention & Insights
(24:45) Cloud Security Program Maturity: From On-Prem to Cloud Native SOC
(29:20) AI in SOC Operations: Speeding Up Forensics & Context
304 episodes
Manage episode 478825674 series 2853525
Join Ashish Rajan in this episodeas he dives deep into the evolving world of cloud security with Sergej Epp, formerly of Deutsche Bank and Palo Alto Networks, now with Sysdig.
Discover why traditional security approaches fall short in today's dynamic cloud-native environments, where workloads resemble swarms of drones rather than predictable trains. Sergej explains the critical shift from basic posture management (CSPM/CNAPP) towards runtime security, emphasizing the need for an "assume breach" mindset.
Learn about the staggering reality that over 60% of containers now live for less than a minute and the immense challenges this poses for detection, incident response, and forensics.
This episode covers:
- The evolution from traditional security to cloud-native and runtime security.
- Why CNAPP/CSPM is like a map, but runtime security is the essential radar.
- The complexities of modern incident response with ephemeral workloads.
- Key strategies for Security Operations Centers (SOC) adapting to the cloud.
- The importance of visibility, data collection, and tools for hybrid and even air-gapped environments.
- How AI is starting to aid security operations and forensics.
Guest Socials: Sergej Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
If you are interested in AI Cybersecurity, you can check out our sister podcast - AI Cybersecurity Podcast
Questions asked:
(00:00) Introduction: Cloud Security & The One-Minute Container Problem
(01:31) Meet Sergej Epp: 20+ Years in Cybersecurity (Deutsche Bank, Palo Alto, Sysdig)
(02:44) What is Cloud Native Today? From Train Stations to Airports with Drones
(05:34) Runtime Security Explained: Why It's Crucial Now
(11:05) The Evolution of Cloud Security: Beyond Basic Posture Management
(13:49) Incident Response Evolution: Tackling One-Minute Containers
(18:34) Who Needs Runtime Security? Platform Engineers, SOC Teams & More
(21:01) Runtime Security as a Platform: Beyond Detection to Prevention & Insights
(24:45) Cloud Security Program Maturity: From On-Prem to Cloud Native SOC
(29:20) AI in SOC Operations: Speeding Up Forensics & Context
304 episodes
All episodes
×Welcome to Player FM!
Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.