The SaC

Magalix

The future of security lies in shifting security left: codifying security and embedding it into DevOps workflows to keep up with the complexity of cloud-based systems and applications without sacrificing speed or agility. In this podcast, we will be meeting with guests and discussing topics related to cloud security, best security practices, tools, and technologies that can facilitate the shift to the left.

Episodes

  1. Securing the Cloud with Zero Trust Architecture

    11/11/2021

    Securing the Cloud with Zero Trust Architecture

    Zero trust security has become a buzzword of sorts. Nonetheless, its principles are powerful and necessary in a digital world where the “Trust but verify” model is no longer enough. The threat landscape has significantly increased in the complex world of cloud computing, cloud-native applications, Kubernetes, microservices..etc. Designing and building your architecture with the “Never trust, always verify” mindset or rather the zero-trust principles can enable companies to build secure infrastructure and reap the promised benefits of all that is in the cloud. According to the 2020 Security Priorities Study, 28% of the security professionals surveyed were either piloting zero trust or had it in production and 40% claim it’s on their plan. In this episode of the SaC, we will discuss with Daniel Feldman, Zero Trust Architecture, the SPIFFE and SPIRE project, and what the future holds for zero-trust networks.  Some of the questions we tackle in this episode are: What is Zero Trust and what does it mean for organizations? The importance of zero-trust security for hyperscalers (such as Google and Amazon). How the regulated industries (such as Fintech and Healthcare) need zero trust SPIFFE and SPIRE Project: how it started and where it is now. How does the future of zero trust architecture About Our Guest Daniel Feldman is a cloud security architect at Hewlett Packard Enterprise. He’s a member of the CNCF SPIFFE project for zero trust tooling and co-authored the book Solving the Bottom Turtle, a book presenting SPIFFE and SPIRE standards.

    20 min
  2. Deep Dive in Policies and Where they can be Applied?

    04/30/2021

    Deep Dive in Policies and Where they can be Applied?

    Most of the major cloud providers offer dozens of services and products. AWS alone has more than 200 products and services at the time of this episode. As a matter of fact, a company uses on average 20 to 30 cloud services and products. With all the possible ways things can go wrong with these services, the operational and security complexity is exponentially increasing.  We are discussing in this episode how codified policies can help these three functions work harmoniously. Some of the discussed points: What does policy as code mean in simple terms? Is there a correlation between the increased complexity of cloud infrastructure and the rising popularity of codified policies? What problems does policy as code solve for engineering teams? Who is policy as code built for? How can codified policies help engineering teams work closer together? About this episode's guest Tony has been on quite a journey. With over 20 years of experience, Tony has played virtually every role in technology, beginning with telephone tech support. In 2016, as Cofounder & CTO, he raised over 4 million USD in venture capital to help content creators earn sustainable wages. Based on his experiences, he's written a book about his leveraging values when building and growing technical teams in startups. Currently, he's a Solutions Architect at Magalix securing digital transformations for Cloud-Native businesses. For more info check The SaC Podcast at Magalix

    31 min

About

The future of security lies in shifting security left: codifying security and embedding it into DevOps workflows to keep up with the complexity of cloud-based systems and applications without sacrificing speed or agility. In this podcast, we will be meeting with guests and discussing topics related to cloud security, best security practices, tools, and technologies that can facilitate the shift to the left.