<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Videos - Securosis</title><link>https://securosis.com/research/video/</link><description>Recent posts tagged Videos from Securosis</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 24 Jul 2026 20:03:35 +0000</lastBuildDate><atom:link href="https://securosis.com/research/video/" rel="self" type="application/rss+xml"/><item><title>Multicloud: Deployment Structures and Blast Radius</title><link>https://securosis.com/research/video/multicloud-deployment-structures-and-blast-radius-5/</link><pubDate>Wed, 07 Aug 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/multicloud-deployment-structures-and-blast-radius-5/</guid><description>
&lt;p&gt;In this, our second Firestarter on multicloud deployments, we start digging into the technological differences between the cloud providers. We start with the concept of how to organize your account(s). Each provider uses different terminology but all support similar hierarchies. From the overlay of AWS organizations to the org-chart-from-the-start of an Azure tenant we dig into the details and make specific recommendations. We also discuss the inherent security barriers and cover a wee bit of IAM.&lt;/p&gt;</description></item><item><title>Firestarter: So you want to multicloud?</title><link>https://securosis.com/research/video/firestarter-so-you-want-to-multicloud-2/</link><pubDate>Thu, 01 Aug 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-so-you-want-to-multicloud-2/</guid><description>
&lt;p&gt;This is our first in a series of Firestarters covering multicloud. Using more than one IaaS cloud service provider is, well, a bit of a nightmare. Although this is widely recognized by anyone with hands-on cloud experience that doesn’t mean reality always matches our desires. From executives worried about lock in to M&amp;amp;A; activity we are finding that most organizations are being pulled into multicloud deployments. In this first episode we lay out the top level problems and recommend some strategies for approaching them.&lt;/p&gt;</description></item><item><title>Firestarter: 2019: Insert Winter is Coming Meme Here</title><link>https://securosis.com/research/video/firestarter-2019-insert-winter-is-coming-meme-here/</link><pubDate>Mon, 07 Jan 2019 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-2019-insert-winter-is-coming-meme-here/</guid><description>
&lt;p&gt;In this year-end/start firestarter the gang jumps into our expectations for the coming year. Spoiler alert- the odds are some consolidation and contraction in security markets are impending… and not just because the Chinese are buying fewer iPhones.&lt;/p&gt;</description></item><item><title>re:Invent Security Review</title><link>https://securosis.com/research/video/invent-security-review/</link><pubDate>Mon, 17 Dec 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/invent-security-review/</guid><description>
&lt;p&gt;It’s that time of year again. The time when Amazon takes over our lives. No, not the holiday shopping season but the annual re:Invent conference where Amazon Web Services takes over Las Vegas (really, all of it) and dumps a firehouse of updates on the world. Listen in to hear our take on new services like Transit Hub, Security Hub, and Control Tower.&lt;/p&gt;</description></item><item><title>Firestarter: Hardware Hacks and Lift and Pray</title><link>https://securosis.com/research/video/firestarter-hardware-hacks-and-lift-and-pray-2/</link><pubDate>Thu, 04 Oct 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-hardware-hacks-and-lift-and-pray-2/</guid><description>
&lt;p&gt;Did China manage to hardware hack the Apple and Amazon data centers? Or did Bloomberg get it wrong? And what the heck can you do about it anyway? This week we start with a discussion of today’s blockbuster security news, before shifting gears back to cloud. It turns out most organizations are having to lift and shift to cloud, even when that is not ideal. We talk about some of your options, even facing ridiculous management timelines.&lt;/p&gt;</description></item><item><title>Firestarter: Black Hat and AI… What Could Go Wrong?</title><link>https://securosis.com/research/video/firestarter-black-hat-and-ai-what-could-go-wrong/</link><pubDate>Tue, 28 Aug 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-black-hat-and-ai-what-could-go-wrong/</guid><description>
&lt;p&gt;In this episode we review the lessons of this year’s Black Hat and DEF CON. In particular, we talk about how things have changed with the students we have in class, now that we’ve racked up over 5 years of running trainings on cloud security. then we delve into one of the biggest, and most confusing, trends… the mysteries of Artificial Intelligence and Machine Learning. Considering our opinions of natural intelligence, you might guess where this heads…&lt;/p&gt;</description></item><item><title>It’s a GDPR Thing</title><link>https://securosis.com/research/video/its-a-gdpr-thing/</link><pubDate>Fri, 06 Jul 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/its-a-gdpr-thing/</guid><description>
&lt;p&gt;Mike and Rich discuss the ugly reality that GDPR really is a thing. Not that privacy or even GDPR are bad (we’re all in favor), but they do require extra work on our part to ensure that policies are in place, audits are performed, and pesky data isn’t left lying around in log files unexpectedly.&lt;/p&gt;</description></item><item><title>Firestarter: The RSA 2018 Episode</title><link>https://securosis.com/research/video/firestarter-the-rsa-2018-episode/</link><pubDate>Thu, 12 Apr 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-the-rsa-2018-episode/</guid><description>
&lt;p&gt;This week Rich, Mike, and Adrian talk about what they expect to see at the RSA Security Conference, and if it really means anything. As we do in most of our RSA Conference related discussions the focus is less on what to see and more on what industry trends we can tease out, and the potential impact on the regular security practitioner. For example, what happens when blockchain and GDPR collide? Do security vendors finally understand cloud? What kind of impact does DevOps have on the security market? Plus we list where you can find us, and, as always, don’t forget to attend the Tenth Annual Disaster Recovery Breakfast!&lt;/p&gt;</description></item><item><title>Firestarter: Auditors, Assessors, and Cloud.. Oh My!</title><link>https://securosis.com/research/video/firestarter-auditors-assessors-and-cloud-oh-my/</link><pubDate>Mon, 19 Mar 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-auditors-assessors-and-cloud-oh-my/</guid><description>
&lt;p&gt;This week the gang discusses Rich’s recent discussions with some clients struggling to deal with auditors and assessors who don’t really understand cloud computing.&lt;/p&gt;</description></item><item><title>Firestarter: Best Practices for Root Account Security and… SQRRL!!!!</title><link>https://securosis.com/research/video/firestarter-best-practices-for-root-account-security-and-sqrrl/</link><pubDate>Mon, 05 Feb 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-best-practices-for-root-account-security-and-sqrrl/</guid><description>
&lt;p&gt;Just because we are focusing on cloud fundamentals doesn’t mean we are forgetting the rest of the world. This week we start with a discussion over the latest surprise acquisition of Sqrrl by Amazon Web Services and what it might indicate. Then we jump into our ongoing series of posts on cloud security by focusing on the best practices for root account security. From how to name the email accounts, to handling MFA, to your break glass procedures.&lt;/p&gt;</description></item><item><title>Firestarter: Architecting Your Cloud with Accounts</title><link>https://securosis.com/research/video/firestarter-architecting-your-cloud-with-accounts/</link><pubDate>Wed, 31 Jan 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-architecting-your-cloud-with-accounts/</guid><description>
&lt;p&gt;We are taking over our own Firestarter and kicking off a new series of discussions on cloud security… from soup to nuts (whatever that means). Each week for the next few months we will cover, in order, how to build out your cloud security program. We are taking our assessment framework and converting it into a series of discussions talking about what we find and how to avoid issues. This week we start with architecting your account structures, after a brief discussion of the impact of the Meltdown and Spectre vulnerabilities since they impact cloud (at least for now) more than your local computer.&lt;/p&gt;</description></item><item><title>Firestarter: Old School and False Analogies</title><link>https://securosis.com/research/video/firestarter-old-school-and-false-analogies/</link><pubDate>Wed, 31 Jan 2018 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-old-school-and-false-analogies/</guid><description>
&lt;p&gt;This week we skip over our series on cloud fundamentals to go back to the Firestarter basics. We start with a discussion of the week’s big acquisition (like BIG considering the multiple). Then we talk about the hyperbole around the release of the iBoot code from an old version of iOS. We also discuss Apple, cyberinsurance, and the actuarial tables. Then we finish up with Rich blabbing about lessons learned as he works on his paramedic again and what parallels to bring to security. For more on that you can read these posts: https://securosis.com/blog/this-security-shits-hard-and-it-aint-gonna-get-any-easier and https://securosis.com/blog/best-practices-unintended-consequences-negative-outcomes&lt;/p&gt;</description></item><item><title>Firestarter: An Explicit End of Year Roundup</title><link>https://securosis.com/research/video/firestarter-an-explicit-end-of-year-roundup/</link><pubDate>Thu, 21 Dec 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-an-explicit-end-of-year-roundup/</guid><description>
&lt;p&gt;The gang almost makes it through half the episode before dropping some inappropriate language as they summarize 2017. Rather than focusing on the big news, we spend time reflecting on the big trends and how little has changed, other than the pace of change. How the biggest breaches of the year stemmed from the oldest of old issues, to the newest of new. And last we want to thank all of you for all your amazing support over the years. Securosis has been running as a company for a decade now, which likely scares all of you even more than us. We couldn’t have done it without you… seriously.&lt;/p&gt;</description></item><item><title>Firestarter: Breacheriffic EquiFail</title><link>https://securosis.com/research/video/firestarter-breacheriffic-equifail/</link><pubDate>Fri, 15 Dec 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/firestarter-breacheriffic-equifail/</guid><description>
&lt;p&gt;This week Mike and Rich address the recent spate of operational fails leading to massive security breaches. This isn’t yet another blame the victim rant, but a frank discussion of why these issues are so persistent and so difficult to actually manage. We also discuss the rising role of automation and its potential to reduce these all-too-human errors.&lt;/p&gt;</description></item><item><title>Evils of the Minimum Viable Cloud.</title><link>https://securosis.com/research/video/evils-of-the-minimum-viable-cloud/</link><pubDate>Tue, 31 Oct 2017 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/evils-of-the-minimum-viable-cloud/</guid><description>
&lt;p&gt;The team is back from the dead, and so are some really crappy cloud ideas.&lt;/p&gt;
&lt;iframe src="https://player.vimeo.com/video/240661764?title=0&amp;byline=0&amp;portrait=0" width="550" height="309" frameborder="0" webkitallowfullscreen="" mozallowfullscreen="" allowfullscreen=""&gt;&lt;/iframe&gt;</description></item><item><title>How to Tell When Your Cloud Consultant Sucks</title><link>https://securosis.com/research/video/how-to-tell-when-your-cloud-consultant-sucks/</link><pubDate>Mon, 07 Nov 2016 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/how-to-tell-when-your-cloud-consultant-sucks/</guid><description>
&lt;p&gt;Mike and Rich had a call this week with another prospect who was given some pretty bad cloud advice. We spend a little time trying to figure out why we keep seeing so much bad advice out there (seriously, BIG B BAD, not just OOPSIE bad). Then we focus on key things to look for, to figure out when someone is leading you down the wrong path in your cloud migration.&lt;/p&gt;</description></item><item><title>Where to start?</title><link>https://securosis.com/research/video/where-to-start/</link><pubDate>Tue, 31 May 2016 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/where-to-start/</guid><description>
&lt;p&gt;It’s long past the day we need to convince you that cloud and DevOps is a thing. We all know it’s happening, but one of the biggest questions we get is “Where do I start?” In this episode we scratch the surface of how to start approaching the problem when you don’t get to join a hot unicorn startup and build everything from scratch with an infinite budget behind you.&lt;/p&gt;</description></item><item><title>What the hell is a cloud anyway?</title><link>https://securosis.com/research/video/what-the-hell-is-a-cloud-anyway/</link><pubDate>Tue, 03 May 2016 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/what-the-hell-is-a-cloud-anyway/</guid><description>
&lt;p&gt;In our wanderings we’ve noticed that when we pull our heads out of the bubble, not everyone necessarily understands what cloud is or where it’s going. Heck, many smart IT people are still framing it within the context of what they currently do. It’s only natural, especially when they get crappy advice from clueless consultants, but it certainly can lead you down some ugly paths. This week Mike, Adrian and Rich are also joined by Dave Lewis (who accidentally sat down next to Rich at a conference) to talk about how people see cloud, the gaps, and how to navigate the waters.&lt;/p&gt;</description></item><item><title>The Rugged vs. SecDevOps Smackdown</title><link>https://securosis.com/research/video/the-rugged-vs-secdevops-smackdown/</link><pubDate>Tue, 15 Mar 2016 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/the-rugged-vs-secdevops-smackdown/</guid><description>
&lt;p&gt;After a short review of the RSA Security Conference, Rich, Mike, and Adrian debate the value of using labels like “Rugged DevOps” or “SecDevOps”. Rich sees them as different, Mike wonders if we really need them, and Adrian has been tracking their reception on the developer side of the house. Okay, it’s pathetic as smackdowns go, but you wouldn’t have read this far if we didn’t give it an interesting title.&lt;/p&gt;</description></item><item><title>RSA Conference- the Good, Bad, and the Ugly</title><link>https://securosis.com/research/video/rsa-conference-the-good-bad-and-the-ugly/</link><pubDate>Wed, 17 Feb 2016 00:00:00 +0000</pubDate><guid>https://securosis.com/research/video/rsa-conference-the-good-bad-and-the-ugly/</guid><description>
&lt;p&gt;Every year we focus a lot on the RSA Conference. Love it or hate it, it is the biggest event in our industry. As we do every year we break down some of the improvements and disappointments we expect to see. Plus, we spend a few minutes talking about some of the big changes coming here at Securosis. We cover a possibly-insulting keynote, the improvements in the sessions, and how we personally use the event to improve our knowledge.&lt;/p&gt;</description></item></channel></rss>