<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Scale To Zero</title><description>Scale To Zero helps security team members get answers to every security question. Practitioners and leaders on cloud, AppSec, identity, AI security and building security teams.</description><link>https://www.scaletozero.com/</link><language>en</language><item><title>Enterprise Security Restructuring &amp; The AI Vulnerability Boom with Alma Paul</title><link>https://www.scaletozero.com/episodes/enterprise-security-restructuring-the-ai-vulnerability-boom-with-alma-paul/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/enterprise-security-restructuring-the-ai-vulnerability-boom-with-alma-paul/</guid><description>Alma Paul of Faire on why restructuring enterprise security starts with visibility, and why AI-era vulnerabilities must be prioritised by business context.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Alma Paul, Senior Corporate Security Engineer at Faire, argues that restructuring an enterprise security program starts with the basics: visibility into what you own, a consistent risk model, a North Star for each security domain, and actually using the tools you already have. On the AI-driven surge in discovered vulnerabilities, she says finding them was never the hard part, fixing them is, so teams should prioritise by business context and use AI to enrich and triage findings. She treats vulnerability management and detection and response as complementary layers, and sees AI as a way to augment security teams rather than replace engineers.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Now more than ever, the basics matter most: know what you have (your landscape, resources and assets) and where you want to get to (your North Star).&lt;/li&gt;&lt;li&gt;Embedding security into the culture early avoids cleanup at a much later point and makes security programs relatively easy to implement.&lt;/li&gt;&lt;li&gt;For vulnerability management, prioritise by business context (public-facing assets, exploitability indicators, application priority) instead of trying to fix every vulnerability.&lt;/li&gt;&lt;li&gt;Avoid vanity metrics: a good program metric tells a story over time of how much risk you have reduced and how much coverage you have gained.&lt;/li&gt;&lt;li&gt;Use AI to augment the security program, offloading repeatable work such as risk reviews and triage context, not to replace security engineers.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Mythos Era: TPRM Evolution, AI Ethics, and Project Glasswing with Matthew Moog</title><link>https://www.scaletozero.com/episodes/the-mythos-era-tprm-evolution-ai-ethics-and-project-glasswing-with-matthew-moog/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-mythos-era-tprm-evolution-ai-ethics-and-project-glasswing-with-matthew-moog/</guid><description>Matthew Moog of EY on why third-party risk is shifting from periodic assessments to continuous, SOC-style monitoring, and what Mythos means for security.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Matthew Moog, a principal at EY, argues that third-party risk management is moving away from repeated annual assessments toward continuous monitoring of signals such as financial health, resiliency, cybersecurity and zero-day events, run almost like a mini SOC. He estimates AI can take about 60% of the effort out of an assessment, but warns against over-reliance on its output and against turning the savings into headcount cuts. What sets Mythos apart, he says, is that it chains individually minor vulnerabilities into serious ones; he expects more vulnerabilities to patch and more scrutiny of open source code, and sees demand for more technically deep security professionals, not fewer.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Treat assessments as a baseline, not the whole program. Moog rarely sees material year-to-year differences in mature assessments, so he would keep annual deep dives for critical third parties and spend more time on continuous signals: financial health, resiliency, cybersecurity and zero-day events.&lt;/li&gt;&lt;li&gt;AI can remove around 60% of the effort from a third-party assessment, but every answer needs checking. His team&apos;s agents cite the policy, the page and a screenshot of the evidence so a reviewer can confirm each one quickly.&lt;/li&gt;&lt;li&gt;Reinvest AI efficiency gains instead of banking them as layoffs: move budget into threat and vulnerability management, incident response, agentic pen testing and security posture management.&lt;/li&gt;&lt;li&gt;Mythos changes the threat picture by stacking vulnerabilities that are minor on their own into a serious one, and by Moog&apos;s account about 90% of what it found was in open source, so expect pressure to find and test the open source code across your third-party ecosystem.&lt;/li&gt;&lt;li&gt;Put controls in place before scaling agents. In a lab simulation, a prompt injection hidden as white text in a mortgage file instructed agents to delete a whole bunch of things and was picked up by the roughly 800 rules the team ran in the workflow; uncapped token usage is its own risk, with one organization spending $100 million on tokens in a quarter.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>AI: Your Next Tool or New Colleague? Next-Gen Security Skills with Priyanka Chatterjee</title><link>https://www.scaletozero.com/episodes/ai-your-next-tool-or-new-colleague-next-gen-security-skills-with-priyanka-chatterjee/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/ai-your-next-tool-or-new-colleague-next-gen-security-skills-with-priyanka-chatterjee/</guid><description>Priyanka Chatterjee (London School of Cybersecurity) says treat AI as a colleague: trust it for SOC analysis, keep humans on response, and build skills.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Priyanka Chatterjee, CEO of London School of Cybersecurity, argues that AI is the first technology that augments our thinking rather than just automating tasks, which is why she treats it as a colleague rather than a tool. In security operations she would rely on it for reporting, data gathering, triage and investigation, but keeps a human in the loop for response decisions such as taking a machine off the network or disabling an account. For people entering cybersecurity, she says we have moved from a knowledge economy to a skills economy: a portfolio that shows you can apply what you know is what gets you hired, and human agency is what sets you apart.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;AI brings an immense productivity gain. Kick-start adoption by automating well-defined playbooks such as data collection, investigation and false-positive detection.&lt;/li&gt;&lt;li&gt;Keep a human in the loop for high-impact response decisions, such as disconnecting a machine from the network or disabling an account, even when AI does the analysis.&lt;/li&gt;&lt;li&gt;We are now in a skills economy rather than a knowledge economy. If you are entering cybersecurity, focus on building skills and a portfolio; it will put you ahead of others in your job search.&lt;/li&gt;&lt;li&gt;Build human agency and use it in your job search and in how you build skills. This is what will differentiate you from others.&lt;/li&gt;&lt;li&gt;Learn to communicate clearly, in speech and in writing. Clear thinking gets better results from your AI colleagues and is what the growing work of AI governance demands.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Beyond the Tools: Bridging Product Security Gaps &amp; Calibrating SDLC with Neelu Tripathy</title><link>https://www.scaletozero.com/episodes/beyond-the-tools-bridging-product-security-gaps-calibrating-sdlc-with-neelu-tripathy/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/beyond-the-tools-bridging-product-security-gaps-calibrating-sdlc-with-neelu-tripathy/</guid><description>Adobe&apos;s Neelu Tripathy on bridging product security gaps: foundational controls first, then security built into the platforms and pipelines engineers use.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Neelu Tripathy, Senior Security Architect at Adobe, argues that product security still starts with foundational controls (authentication for every entity including machines and agents, data security, auditing and hardened configurations) with AI-specific controls layered on top. The gaps she most often finds sit in build systems, the supply chain and the supporting services around an application, and rather than adding tools she recommends pushing controls into the platforms, pipelines, registries and golden images engineers already use, so security scales without slowing velocity. For agentic development, she adds a vetted registry for MCP servers and AI tools, registered agent identities, gateway and runtime controls, and security for context.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For product security, start with foundational controls (authentication for every entity, data security, auditing, hardened configurations) and add AI controls as AI usage is introduced.&lt;/li&gt;&lt;li&gt;Build organisational policies and paved roads into engineering practice at every touch point, from IDE checks to build pipeline checks and infrastructure checks.&lt;/li&gt;&lt;li&gt;To collaborate with engineering, provide security systems and platforms and embed controls into existing workflows, working alongside engineering practices instead of replacing them.&lt;/li&gt;&lt;li&gt;Focus on controls rather than detection tools: thousands of untriaged scanner findings overwhelm developers, and issues get fixed when the fix is built into the system and automated.&lt;/li&gt;&lt;li&gt;Treat MCP servers and other AI tools like dependencies: vet them in a registry every time they are imported, and register agents so their actions can be traced.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Ransomware in the AI Era: Evolution, Hidden Weaknesses, and Incident Response with Behnaz Karimi</title><link>https://www.scaletozero.com/episodes/ransomware-in-the-ai-era-evolution-hidden-weaknesses-and-incident-response-with-behnaz-karimi/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/ransomware-in-the-ai-era-evolution-hidden-weaknesses-and-incident-response-with-behnaz-karimi/</guid><description>Behnaz Karimi (Tramarena) explains how ransomware now targets AI models, pipelines and supply chains, and how incident response must change for AI.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ransomware has shifted from encrypting files to stealing data and multi-layered extortion, and AI systems are now both a target and a weapon. Behnaz Karimi, founder of Tramarena and co-leader of the OWASP AI Exchange, explains how attackers slip malicious models in through the AI supply chain, stay dormant in ML pipelines long enough to evade anomaly detection, and why small and mid-sized companies adopting AI quickly are just as exposed. She argues that isolate-and-restore incident response is not enough for AI: a model that may be poisoned has to be verified, or retrained from scratch in a clean environment.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;AI ransomware attacks have many entry points, including models, ML libraries, pipelines, datasets and prompts. Each one deserves equal attention when securing AI systems.&lt;/li&gt;&lt;li&gt;Start with reachability: can a normal IT attack reach your AI systems, and can a compromised AI component affect the rest of your environment? Then review each component, such as the supply chain, pipelines and ML libraries, honestly and prioritize the least secure areas.&lt;/li&gt;&lt;li&gt;Take a moment to analyze your AI systems: inventory the tools and use cases, identify the risks that apply, assess how likely they are and their impact, and set basic controls and governance around them. Repeat whenever your AI systems change.&lt;/li&gt;&lt;li&gt;Isolate, eradicate and restore from backup is not enough for AI. A poisoned model can misbehave long before the attack is noticed, so verify models before restoring them and retrain from scratch in a clean environment if you cannot be confident they are clean.&lt;/li&gt;&lt;li&gt;Small and mid-sized organizations are targets too. Ransomware as a service makes complex attacks easy to launch, and teams adopting AI fast often do not track where their models come from or monitor what enters their systems.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>IAM in 2026: From Anti-Patterns to Autonomous AI Agents with Advait Patel</title><link>https://www.scaletozero.com/episodes/iam-in-2026-from-anti-patterns-to-autonomous-ai-agents-with-advait-patel/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/iam-in-2026-from-anti-patterns-to-autonomous-ai-agents-with-advait-patel/</guid><description>Advait Patel (Broadcom): automate just-in-time access, build IAM up from least privilege, and keep AI agents on low-risk tasks until you can trust them.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Advait Patel, a senior SRE at Broadcom, argues that IAM in 2026 should unblock engineers rather than slow them down: automate just-in-time access against predefined controls, start from minimal permissions and add more as needed, and build compliance into the infrastructure from day one instead of treating it as a checklist. He says traditional KPIs like mean time to detect and resolve are no longer enough once AI is involved, and proposes measuring signal quality, engineer efficiency, decision quality and automation safety. AI agents are useful for log analysis, root cause analysis and incident runbooks, but he would start them on low-risk tasks and keep humans checking their output, especially as attackers use AI too.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Do not treat compliance as a checklist. Focus on the security basics — patching, visibility, logging, tracking who changed what — and lay a solid foundation from day one; that foundation makes compliance easier too.&lt;/li&gt;&lt;li&gt;Security programs should keep the experience of development, engineering and product in mind. A bad experience backfires and costs security their trust, which is why access that waits days on manual tickets should give way to automated just-in-time access.&lt;/li&gt;&lt;li&gt;Traditional KPIs like mean time to detect and resolve are not enough once AI is in the loop. Measure signal quality, engineer efficiency, decision quality and automation safety, and favour quality over quantity in what the AI recommends.&lt;/li&gt;&lt;li&gt;Build IAM from the bottom up: start from minimal permissions, assign roles by team, and add access as it is needed, rather than granting admin rights and trimming what goes unused.&lt;/li&gt;&lt;li&gt;Start AI agents on low-risk tasks such as log pattern analysis, root cause analysis and incident runbooks. Hand work to autonomous agents only where you are confident in the results without full visibility.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>AI Security: Hype vs. Reality and the Roadmap to CISO with Niyati Daftary</title><link>https://www.scaletozero.com/episodes/ai-security-hype-vs-reality-and-the-roadmap-to-ciso-with-niyati-daftary/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/ai-security-hype-vs-reality-and-the-roadmap-to-ciso-with-niyati-daftary/</guid><description>Niyati Daftary on separating AI security hype from reality and the career roadmap to becoming a CISO.</description><pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Niyati Daftary observes that the biggest AI question for security leaders is defining the CISO&apos;s remit in AI governance — many are still unsure of security&apos;s role, how to inventory approved AI usage, and which framework (NIST AI RMF or ISO 42001) to follow. She argues the industry overestimates AI&apos;s short-term threat, since attackers have not yet leveraged it at scale, while underestimating its long-term value — for example, automating L1 and L2 SOC work. The challenges she hears most are about programme management: aligning the security roadmap to business priorities and demonstrating value to the board.&lt;/p&gt;</content:encoded></item><item><title>Product Security at Scale: Minimizing Friction &amp; Defending AI Integrations with Sana Talwar</title><link>https://www.scaletozero.com/episodes/product-security-at-scale-minimizing-friction-defending-ai-integrations-with-sana-talwar/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/product-security-at-scale-minimizing-friction-defending-ai-integrations-with-sana-talwar/</guid><description>Sana Talwar on product security at scale, reducing friction for developers, and defending AI integrations in the enterprise.</description><pubDate>Wed, 11 Mar 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Sana Talwar shares how to scale product-security programmes while minimising friction for engineering teams. She discusses the unique challenges of securing AI integrations and how to defend against the new attack surfaces they introduce. Her approach emphasises automation, developer enablement, and pragmatic risk prioritisation.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When engaging with Product / Engineering, 3 principles go a long way. Use business language over technical jargons. Highlight Actual risk vs all risks. Automate processes to reduce burden.&lt;/li&gt;&lt;li&gt;Product / Engineering teams should engage security team early in SDLC process to avoid difficult conversation before go live.&lt;/li&gt;&lt;li&gt;For AI Workloads, follow few principles like red teaming of agents, prompt validation, output validation, set guardrails and most importantly have provisions for Human In The Loop.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>eBPF, MCP Servers, And The Kernel-Level Future of AI Security with Ammar Ekbote</title><link>https://www.scaletozero.com/episodes/ebpf-mcp-servers-and-the-kernel-level-future-of-ai-security-with-ammar-ekbote/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/ebpf-mcp-servers-and-the-kernel-level-future-of-ai-security-with-ammar-ekbote/</guid><description>Ammar Ekbote, Cloud Security Engineer at Pinterest, on eBPF, MCP server adoption, and kernel-level AI security monitoring.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ammar Ekbote explains that eBPF hooks into kernel-level activity, which means vendors&apos; monitoring tools need rigorous security testing before adoption. For secure MCP adoption, he recommends enabling org-level hosting, policy enforcement, and approved MCP lists so teams do not install unvetted servers. eBPF can capture developer-level telemetry to detect PII exfiltration through MCPs.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When it comes to eBPF, it’s an event-based technology hooking to kernel-level activity. This means that when working with vendors for eBPF monitoring tools, extra care should be taken to ensure enough security testing is performed before adopting.&lt;/li&gt;&lt;li&gt;For secure MCP adoption, enable teams with allowed MCPs, org-level MCP server hosting, policy enforcement, etc. so that teams do not install MCPs on their own which may lack security guardrails.&lt;/li&gt;&lt;li&gt;Utilize eBPF as a way to capture developer-level telemetry to understand if PII is exfiltrated while using MCPs and apply policies to restrict it.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Last9 Story: Scaling Engineering, GTM Strategy, and the Reality of &quot;Overnight Success&quot;</title><link>https://www.scaletozero.com/episodes/the-last9-story-scaling-engineering-gtm-strategy-and-the-reality-of-overnight-success/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-last9-story-scaling-engineering-gtm-strategy-and-the-reality-of-overnight-success/</guid><description>Nishant Modak, founder and CEO of Last9, on scaling engineering, go-to-market strategy, and the reality of building a startup.</description><pubDate>Wed, 04 Feb 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Nishant Modak shares the Last9 journey — from the early engineering decisions to building a go-to-market strategy for an observability platform. He discusses the reality behind so-called overnight success, the importance of founder resilience, and what it takes to scale both the product and the team. His candid perspective covers the hard trade-offs founders face at every stage.&lt;/p&gt;</content:encoded></item><item><title>AWS vs. GCP IAM Architecture &amp; The Future of Security in 2026 with Sneha Malshetti CISSP</title><link>https://www.scaletozero.com/episodes/aws-vs-gcp-iam-architecture-the-future-of-security-in-2026-with-sneha-malshetti-cissp/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/aws-vs-gcp-iam-architecture-the-future-of-security-in-2026-with-sneha-malshetti-cissp/</guid><description>Sneha Malshetti, Senior Security Engineer at Ethos, on IAM differences between AWS and GCP and balancing least privilege with velocity.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Sneha Malshetti argues that IAM in the cloud is underrated and that teams should start with a clear goal and small scope. She recommends leveraging RBAC, periodic access reviews, and monitoring unused access to optimise over time. Balancing least privilege with developer velocity is equally hard in AI and non-AI worlds, so getting the basics right is what matters most.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;IAM in the cloud is underrated. Always start with a clear understanding of the goal and start small. Instead of diving head first with best practices.&lt;/li&gt;&lt;li&gt;Leverage tools &amp;amp; techniques like Role based access control, periodic Access reviews, review unusual access, unused access. Monitor to optimize them.&lt;/li&gt;&lt;li&gt;Striking the balance between least privilege and velocity is hard. The same challenge exists in Non-AI &amp;amp; AI world. So, implement basics really well, utilize above tools &amp;amp; techniques and optimize over time for a better IAM posture.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Zero Trust AI &amp; Human Risk: A Guide to Future-Proofing Security with James Cash</title><link>https://www.scaletozero.com/episodes/zero-trust-ai-human-risk-a-guide-to-future-proofing-security-with-james-cash/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/zero-trust-ai-human-risk-a-guide-to-future-proofing-security-with-james-cash/</guid><description>James Cash on zero trust, AI-driven threats, human risk, and future-proofing organisational security programmes.</description><pubDate>Wed, 26 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;James Cash discusses how zero trust, AI threats, and human risk intersect in modern security programmes. He argues that future-proofing requires addressing all three dimensions simultaneously rather than treating them in isolation. His practical guidance covers programme design, technology adoption, and building a culture that adapts to evolving threats.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Having a good basic understanding of LLM systems, how they work and how they are trained, etc. helps security leaders to prepare &amp;amp; remediate the Risks.&lt;/li&gt;&lt;li&gt;Similar to SBOM for SaaS providers, AI-SBOM is equally important for the AI systems. This helps organizations stay on top of current and potential risks in future.&lt;/li&gt;&lt;li&gt;Least Privilege is a similar challenge in Non-AI &amp;amp; AI world. Access should be limited to least required privilege and also least duration allowed. This helps keep the attack surface to minimum.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Beyond Tech: Building a Security Culture and Navigating AI&apos;s Impact with Dakota Riley</title><link>https://www.scaletozero.com/episodes/beyond-tech-building-a-security-culture-and-navigating-ais-impact-with-dakota-riley/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/beyond-tech-building-a-security-culture-and-navigating-ais-impact-with-dakota-riley/</guid><description>Dakota Riley on building a security culture, focusing on problems over solutions, and the impact of AI on security teams.</description><pubDate>Wed, 12 Nov 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Dakota Riley argues that a strong engineering culture drives alignment on security objectives, and that focusing on the problem rather than jumping to a solution is key. He recommends building momentum through small wins and taking calculated risks instead of a risk-averse stance. Secure SDLC, in his view, depends more on practices like threat modelling than on any single tool.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Having a strong engineering culture helps with alignment of Security objectives. Focusing on the problem vs solution is key for strong security implementation.&lt;/li&gt;&lt;li&gt;To address cultural security challenges focus on Small Wins and build from there. Also, take risks vs a risk averse approach to experimentation.&lt;/li&gt;&lt;li&gt;Secure SDLC is more about better security practices like Threat Modeling or Secure Architecture review than tools. Tools help fix the gaps, but they don’t fix the core issue in an organization.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Kubernetes Security Mastery: Shifting Mindsets for Ephemeral Environments with Dinis Cruz</title><link>https://www.scaletozero.com/episodes/kubernetes-security-mastery-shifting-mindsets-for-ephemeral-environments-with-dinis-cruz/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/kubernetes-security-mastery-shifting-mindsets-for-ephemeral-environments-with-dinis-cruz/</guid><description>Dinis Cruz on Kubernetes security for ephemeral environments, enriching GenAI with quality data, and threat modelling AI stacks.</description><pubDate>Wed, 29 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Dinis Cruz argues that a strong engineering culture is essential for securing ephemeral environments because of their dynamic nature. To get the best value from GenAI, organisations must ingest and enrich with high- quality data. Threat modelling is paramount in the GenAI world, ensuring security is woven into every layer of the AI stack — models, data, and applications.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Having a strong engineering culture is key to setting the basics right for Ephemeral environments and Security with it. As the environments are dynamic in nature, vs static infrastructure.&lt;/li&gt;&lt;li&gt;To get the best value out of GenAI, ingest and enrich with good-quality data. This will determine the accuracy of the output from GenAI platforms.&lt;/li&gt;&lt;li&gt;In the GenAI world, Thread Modeling is paramount. This ensures security is integrated, the right way, into each layer of the AI Application stack, including Models, Data, Apps, and others.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Inside the World of an AWS Partner Solution Architect: Career, Partnerships &amp; Scaling with Marketplace</title><link>https://www.scaletozero.com/episodes/inside-the-world-of-an-aws-partner-solution-architect-career-partnerships-scaling-with-marketplace/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/inside-the-world-of-an-aws-partner-solution-architect-career-partnerships-scaling-with-marketplace/</guid><description>Lalit Khattar, Partner Solution Architect at AWS, on career growth, channel partnerships, and scaling through AWS Marketplace.</description><pubDate>Wed, 15 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Lalit Khattar shares a candid look at the partner solution architect role at AWS, from building technology partnerships to helping customers scale through Marketplace. He discusses the day-to-day realities of bridging business and technology, what five years at AWS taught him, and how channel- focused go-to-market strategies drive growth.&lt;/p&gt;</content:encoded></item><item><title>Securing the SDLC in the AI Era: Challenges and Strategies for Modern Enterprises with Ashish Bhadouria</title><link>https://www.scaletozero.com/episodes/securing-the-sdlc-in-the-ai-era-challenges-and-strategies-for-modern-enterprises-with-ashish-bhadouria/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/securing-the-sdlc-in-the-ai-era-challenges-and-strategies-for-modern-enterprises-with-ashish-bhadouria/</guid><description>Ashish Bhadouria, Security and Privacy Manager at IKEA, on securing the SDLC in the AI era and defending modern enterprises.</description><pubDate>Wed, 01 Oct 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ashish Bhadouria discusses the challenges enterprises face when securing the software development lifecycle as AI tools become embedded in the process. He emphasises designing security controls that work with — not against — developers. His approach combines privacy-by-design principles with practical strategies for modern enterprise environments.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Secure SDLC is as much a Culture challenge as it’s a Process or Tools challenge. Having a strong champions program helps with alignment of Security objectives.&lt;/li&gt;&lt;li&gt;Engage early with other teams &amp;amp; stakeholders in the Development cycle. This will ensure Security is not an afterthought rather it’s baked in to the SDLC process.&lt;/li&gt;&lt;li&gt;In the AI world, Thread Modeling is important. This ensures security is integrated, the right way, into each layer of AI Application stack including Models, Data, Apps and others.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Beyond the Hype: A Founder&apos;s Guide to Proactive Security &amp; Leadership</title><link>https://www.scaletozero.com/episodes/beyond-the-hype-a-founders-guide-to-proactive-security-leadership/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/beyond-the-hype-a-founders-guide-to-proactive-security-leadership/</guid><description>Ashish Garg on proactive security leadership, analysing business risk impact, and cross-team alignment on security roadmaps.</description><pubDate>Wed, 17 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ashish Garg argues that business risk analysis and impact assessment are the keys to successful risk management. Asset management, training, and tabletop exercises form the operational backbone. For cross-team alignment, he recommends engaging leaders on the security roadmap early to build trust and avoid last-minute surprises.&lt;/p&gt;</content:encoded></item><item><title>Designing Security for GenAI With Security Specialist Solutions Architect - Shweta Thapa</title><link>https://www.scaletozero.com/episodes/designing-security-for-genai-with-security-specialist-solutions-architect-shweta-thapa/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/designing-security-for-genai-with-security-specialist-solutions-architect-shweta-thapa/</guid><description>Shweta Thapa, Security Specialist Solutions Architect at AWS, on designing security controls for generative AI applications.</description><pubDate>Wed, 03 Sep 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Shweta Thapa explains that GenAI security controls must account for non- deterministic outputs, novel attack vectors, and semantic validation. She recommends selecting models from trusted providers, validating both input and output, and keeping context front and centre. Guardrails for input/output, authorisation for data access, and feedback loops for bias adjustment are the practical foundations.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;While designing Security controls for GenAI applications, a few things should always be kept in mind: 1. Non-deterministic. 2. Different Attack vectors. 3. Semantic validation for output.&lt;/li&gt;&lt;li&gt;Some of the basics of GenAI application architecture include 1. selecting a model from a Trusted Provider. 2. Validate Input and Output. 3. Context matters the most.&lt;/li&gt;&lt;li&gt;To Secure, utilize Guardrails for input and output. Having authorization in place for data access, and a Feedback loop is key for adjusting bias in output.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Beyond the Debate: Security as an Enabler &amp; GRC Maturity with Winthrop Welch, Fractional CISO</title><link>https://www.scaletozero.com/episodes/beyond-the-debate-security-as-an-enabler-grc-maturity-with-withrop-welch-fractional-ciso/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/beyond-the-debate-security-as-an-enabler-grc-maturity-with-withrop-welch-fractional-ciso/</guid><description>Compliance should feed security, not fight it. Fractional CISO Winthrop (Andy) Welch on GRC maturity, building trust and cutting tool sprawl.</description><pubDate>Wed, 20 Aug 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Winthrop (Andy) Welch argues that security and compliance shouldn&apos;t be at odds: good compliance mandates are security requirements that belong on the program roadmap. He sees GRC maturity as low in many enterprises, where GRC acts as an after-the-fact assessments team, and says it earns its value by moving upstream into development, operations and M&amp;A deal teams. Drawing on a penetration testing engagement, a collapsed acquisition and a healthcare breach response, he shows how trust, shared goals and a value-first approach turn security from a blocker into an enabler.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Instead of debating security versus compliance, treat compliance as a gateway to security use cases and requirements, and prioritize them on the roadmap like any other requirements.&lt;/li&gt;&lt;li&gt;Alignment is the key to collaboration between the security team and the rest of the organization. Building trust and building security champions on the business side goes a long way in designing a successful security program.&lt;/li&gt;&lt;li&gt;The way to beat vendor and tool sprawl is to understand your future state architecture and map out a roadmap to it, then choose the best-fit tool or vendor instead of the new shiny toy.&lt;/li&gt;&lt;li&gt;GRC earns its place by moving upstream: embedding in development, operations and deal teams early, rather than arriving after the fact with a list of findings.&lt;/li&gt;&lt;li&gt;To build a culture of positive friction, start by inviting critique from your direct reports, then widen it once you&apos;re comfortable.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Future CISO: AI, Quantum &amp; Becoming a Multidisciplinary Strategist with Patricia Titus</title><link>https://www.scaletozero.com/episodes/the-future-ciso-ai-quantum-becoming-a-multidisciplinary-strategist-with-patricia-titus/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-future-ciso-ai-quantum-becoming-a-multidisciplinary-strategist-with-patricia-titus/</guid><description>Patricia Titus on the future CISO, AI and quantum security challenges, and becoming a multidisciplinary security strategist.</description><pubDate>Thu, 07 Aug 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Patricia Titus discusses how the CISO role is evolving into a multidisciplinary strategist position that spans AI, quantum, and traditional security. She emphasises the need for CISOs to understand emerging technologies deeply enough to make informed risk decisions. Building cross-functional influence and staying current with the changing threat landscape are central to her advice.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;With the increasing adoption of AI, Security Leaders would have to become deep specialists. This would enable security experts to not only leverage but also defend against threats.&lt;/li&gt;&lt;li&gt;Context is king. With AI, it’s essential for security leaders to focus on context focused behavioral aspects than the policy driven aspects.&lt;/li&gt;&lt;li&gt;From a governing perspective, NIST and ISO have AI Governance Frameworks. Leverage those as starting points.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Cracking the $3M Deal: Sales Wisdom, AWS Marketplace Success &amp; Life Lessons with Faraz Khan, AWS Marketplace Leader</title><link>https://www.scaletozero.com/episodes/cracking-the-3m-deal-sales-wisdom-aws-marketplace-success-life-lessons-with-faraz-khan-aws-marketplace-leader/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/cracking-the-3m-deal-sales-wisdom-aws-marketplace-success-life-lessons-with-faraz-khan-aws-marketplace-leader/</guid><description>Faraz Khan on cracking enterprise deals, AWS Marketplace success, and go-to-market strategy for security startups.</description><pubDate>Wed, 23 Jul 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Faraz Khan shares his experience leading digital transformation for enterprise customers and driving AWS Marketplace adoption. He offers candid sales wisdom on closing large deals, building channel partnerships, and the life lessons that shaped his career in go-to-market strategy.&lt;/p&gt;</content:encoded></item><item><title>Zero to Zero Trust: Implementation, Challenges &amp; AI&apos;s Future Role with Uttej Badwane</title><link>https://www.scaletozero.com/episodes/zero-to-zero-trust-implementation-challenges-ais-future-role-with-uttej-badwane/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/zero-to-zero-trust-implementation-challenges-ais-future-role-with-uttej-badwane/</guid><description>Uttej Badwane, Senior Security Engineer at Carta, on zero-trust implementation challenges and the future role of AI in security.</description><pubDate>Wed, 09 Jul 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Uttej Badwane discusses the practical challenges organisations face when implementing zero trust, from identity sprawl to legacy-system integration. He explores how AI can accelerate security operations and where it falls short. His advice centres on taking an incremental approach to zero trust and measuring progress against clear milestones.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Zero Trust is a significant initiative and it requires Human effort and budget. Getting Leadership buy-in early would help fast pace the program tremendously.&lt;/li&gt;&lt;li&gt;There are 3 areas of Zero Trust. Identity, Devices and Policy Engine. Having checks and balances at each of these areas are key to the implementation of the Zero Trust program.&lt;/li&gt;&lt;li&gt;AI is a double edged sword. Where in It can help with effective and faster automations. It can also cause damage as well especially with Agent AI / Autonomous decision making AI agents running around and performing actions. Basics of Zero Trust does not change even though the technology changes. Ensure basics are followed properly.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>IAM, AI &amp; Cloud Security: Unlocking Scale &amp; Battling New Threats with Stephen Kuenzli</title><link>https://www.scaletozero.com/episodes/iam-ai-cloud-security-unlocking-scale-battling-new-threats-with-stephen-kuenzli/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/iam-ai-cloud-security-unlocking-scale-battling-new-threats-with-stephen-kuenzli/</guid><description>Stephen Kuenzli on IAM, AI-driven cloud security, and using agents and MCPs to improve security decision-making at scale.</description><pubDate>Wed, 25 Jun 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Stephen Kuenzli points out that security is too often treated as a dedicated resource when it should be shared across the organisation, and that least privilege is far more nuanced than it sounds. He argues that security teams should enable others with self-serve playbooks and guardrails like AWS data perimeters. AI&apos;s reasoning skills can be leveraged through MCPs and agents to improve research, decision-making, and productivity.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;One big misconception when it comes to security, or particularly in IAM, is that folks see security as a dedicated resource versus it&apos;s often a shared resource in the organization. And the other one is like least privilege is like very standard, very boilerplate. Whereas it&apos;s very nuanced depending on the organization.&lt;/li&gt;&lt;li&gt;The second one is security organization should enable teams by providing self-serve playbooks and also setting up processes around it. Of course, with guardrails on top of it, like using like data parameter in AWS.&lt;/li&gt;&lt;li&gt;AI has reasoning skills, which was missing in software development for decades. So leverage AI, MCPs, agents to improve not only research, but also decision making, and hence the productivity gain.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Beyond the Spreadsheet: Mastering Cybersecurity Risk Management with Joseph Haske</title><link>https://www.scaletozero.com/episodes/beyond-the-spreadsheet-mastering-cybersecurity-risk-management-with-joseph-haske/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/beyond-the-spreadsheet-mastering-cybersecurity-risk-management-with-joseph-haske/</guid><description>Joseph Haske on cybersecurity risk management, stakeholder communication, and qualitative-vs-quantitative frameworks.</description><pubDate>Wed, 11 Jun 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Joseph Haske argues that communication is the single most important aspect of running a risk programme — understanding your landscape and stakeholders&apos; goals is where it starts. He recommends using qualitative methods for decision-making and quantitative scoring for depth. Prioritisation, in his view, must account for other teams&apos; asks before engaging.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Communication is the key aspect of running a successful security risk program. In order to do it well, understand your landscape, understand stakeholders and their goals.&lt;/li&gt;&lt;li&gt;When choosing Qualitative vs Quantitative risk management approach, the framework you can use is use Qualitative for decision making framework and Quantitative for in-depth scoring.&lt;/li&gt;&lt;li&gt;Prioritization plays a major role in risk management programs. Understand your asks and prioritization of other teams in the organization before engaging.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>AI in AppSec: The Paradigm Shift with Brad Geesaman</title><link>https://www.scaletozero.com/episodes/ai-in-appsec-the-paradigm-shift-with-brad-geesaman/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/ai-in-appsec-the-paradigm-shift-with-brad-geesaman/</guid><description>Brad Geesaman on adopting AI in application security, managing non-deterministic LLMs, and knowing when agentic AI fits.</description><pubDate>Wed, 28 May 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Brad Geesaman recommends starting small with AI adoption — break work into specific tasks rather than attempting a full overhaul. LLMs are non- deterministic, so teams should define their risk tolerance and optimise around it rather than chasing perfection. He warns that over-reliance on AI systems can erode craftsmanship and curiosity, and advocates using them as an aid rather than a replacement.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Building / Adoption of AI Systems should start small. Breakdown projects into smaller and specific tasks and apply AI on it. Instead of doing a complete revamp at once.&lt;/li&gt;&lt;li&gt;LLMs today are non-deterministic. Define your risk tolerance level and optimize around it. Perfection would be a challenge to building / adoption.&lt;/li&gt;&lt;li&gt;With increased adoption of AI Systems, Complexity Increases, Craftmanship and Curiosity takes a hit. Use AI Systems as a aid vs replacement.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Good and Lasting Cloud Security with Lalit Kumar</title><link>https://www.scaletozero.com/episodes/the-good-and-lasting-cloud-security-with-lalit-kumar/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-good-and-lasting-cloud-security-with-lalit-kumar/</guid><description>Lalit Kumar on building good and lasting cloud security, transforming AWS India Security, and advising CXOs on cloud posture.</description><pubDate>Wed, 07 May 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Lalit Kumar draws on over 20 years of security leadership to discuss what makes cloud security programmes last. He shares lessons from transforming the AWS India Security Division and collaborating with CXOs across BFSI, digital-native, and government sectors. His advice centres on balancing enterprise rigour with the agility that cloud demands.&lt;/p&gt;</content:encoded></item><item><title>Scaling Security Champions: From Zero to Hero With Bonnie Viteri</title><link>https://www.scaletozero.com/episodes/scaling-security-champions-from-zero-to-hero-with-bonnie-viteri/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/scaling-security-champions-from-zero-to-hero-with-bonnie-viteri/</guid><description>Bonnie Viteri on building a security-champions programme from scratch, enablement vs empowerment, and measuring impact.</description><pubDate>Wed, 23 Apr 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Bonnie Viteri identifies interest in security, knowledge of the tech stack, and integration skills as the signals to look for when selecting champions. She argues that enablement and empowerment are the two key success factors — champions need to learn and to influence. For programme design, she recommends yearly planning, goal-driven metrics, and deep retrospection to understand real impact.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Some of the signals to look for while looking for Security Champions is to see the interest in security, knowledge of tech stack and the understanding of how they integrate.&lt;/li&gt;&lt;li&gt;Enablement and empowerment are two key factors of success of security champions program. This helps security champion to not only learn but also influence security programs.&lt;/li&gt;&lt;li&gt;While designing Security Champions Program, do a yearly planning, make it goal-driven and define success metrics. Perform deep retrospection at the end of the year to understand the impact and areas of improvement.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Securing Production: A Deep Dive into AWS IAM Best Practices with Rowan Udell</title><link>https://www.scaletozero.com/episodes/securing-production-a-deep-dive-into-aws-iam-best-practices-with-rowan-udell/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/securing-production-a-deep-dive-into-aws-iam-best-practices-with-rowan-udell/</guid><description>Rowan Udell on AWS IAM best practices for production environments, least-privilege strategies, and role-based access patterns.</description><pubDate>Wed, 09 Apr 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Rowan Udell shares deep practical guidance on securing production AWS environments through IAM best practices. He covers least-privilege strategies, role-based access patterns, and the operational trade-offs teams face when tightening permissions without slowing down development.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Visibility of IAM principals, permissions, and activities is key to defining the right IAM policies for the organization. CloudTrail and AWS Access Analyzer help tremendously for this need.&lt;/li&gt;&lt;li&gt;Permissions management is a continuous process. Assign permissions based on need, monitoring them, analyze the usage, and optimize based on the usage. Leveraging some of out of the box IAM capabilities of AWS like AWS Identity Center, SCPs, RCPs, Access Analyzer, Data Perimeter, Session Policies helps in this regard.&lt;/li&gt;&lt;li&gt;Implementation of different IAM best practices like Least Privilege, JIT, etc. depend on organization’s maturity level. These are advanced-level IAM security implementations.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Secrets of Product Security with Anshuman Bhartiya</title><link>https://www.scaletozero.com/episodes/anshuman-bhartiya/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/anshuman-bhartiya/</guid><description>Anshuman Bhartiya on product security, risk-driven prioritisation, and building secure-by-default development practices.</description><pubDate>Wed, 26 Mar 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Anshuman Bhartiya argues that the foundation of product security is understanding the organisation&apos;s risk appetite through a unified approach to risk quantification. He advocates for secure-by-default libraries, golden images, and IDE plugins so insecure code does not fall through the cracks. Culture and empathy toward end-users and engineers are, in his view, what make security programmes successful.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The key to application and product security is understanding the risk appetite of the organization. And in order to understand this, organization needs to have an unified approach to risk quantification utilizing context.&lt;/li&gt;&lt;li&gt;A key trick to incorporate security practices into SDLC is to work with secure-by-default libraries / frameworks. Building golden images, IDE Plugins, Git wrappers, etc. This ensures insecure code does not fall through the cracks.&lt;/li&gt;&lt;li&gt;Culture is key to application and product security. One key aspect of it is to have empathy towards end-users, and engineers. This helps with building relationship with other stakeholders and building relatable &amp;amp; successful security programs.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Magical World Of Digital Forensics With Jason Jordaan</title><link>https://www.scaletozero.com/episodes/the-magical-world-of-digital-forensics-with-jason-jordaan/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-magical-world-of-digital-forensics-with-jason-jordaan/</guid><description>Jason Jordaan on digital forensics, the importance of meticulous documentation, and preparing organisations for investigations.</description><pubDate>Wed, 12 Mar 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jason Jordaan stresses that constant learning is the key to success in digital forensics as technology evolves rapidly. Documentation must be as detailed as possible — leaving even a small gap can derail an entire investigation. Organisations can prepare by setting up logging, training employees on basic forensics, partnering with vendors, and maintaining playbooks.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;As the technology moves rapidly, one key skill to success in Digital Forensics is constant learning. Stay up to date with new the tools, technologies like GenAI, Quantum Computing. These bring new challenges and opportunities to Digital Forensic Analysts.&lt;/li&gt;&lt;li&gt;For Digital Forensics, one of the key factors for success is documentation. As detailed as it can get. Because, leaving even a tiny fraction of trace could derail the entire investigation.&lt;/li&gt;&lt;li&gt;In order to help with Digital Forensics, organization can do some basic prep like setting up logging, training employees on basic forensics techniques, partnering with vendors, and have playbooks in place.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>From Reactive to Proactive: A Conversation on Modern Threat Detection</title><link>https://www.scaletozero.com/episodes/from-reactive-to-proactive-a-conversation-on-modern-threat-detection/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/from-reactive-to-proactive-a-conversation-on-modern-threat-detection/</guid><description>Reanna Schultz, founder of CyberSpeak Labs, on modern threat detection, false-positive handling, and staying ahead of threats.</description><pubDate>Wed, 12 Feb 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Reanna Schultz argues that effective detection engineering requires deep understanding of network architecture, the application ecosystem, and the people on the network. Before marking an alert as a false positive, she recommends waiting for at least three occurrences — the second could be a coincidence. Staying ahead of threats, in her view, relies on security advisories via RSS, Discord, Reddit, and following threat researchers.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For Detection Engineering, understanding your network architecture, application ecosystem and people of network plays a major role.&lt;/li&gt;&lt;li&gt;In order to treat an alert as false positives, wait for at least three occurrences. Second could be a co-incidence. But, marking an alert as false positive on the first occurrence could be misleading. Constantly re-evaluate and verify the audit logs for over corrections.&lt;/li&gt;&lt;li&gt;Best way to stay ahead or close to latest threats is via security advisories. It can be done via RSS Feeds, Discord Servers, Reddit, Hacker news, following threat researchers and more such sources.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Human Element: AI, Deepfakes, and the Evolving Threat Landscape with Perry Carpenter</title><link>https://www.scaletozero.com/episodes/the-human-element-ai-deepfakes-and-the-evolving-threat-landscape-with-perry-carpenter/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-human-element-ai-deepfakes-and-the-evolving-threat-landscape-with-perry-carpenter/</guid><description>Perry Carpenter on the human element in security, AI-powered deepfakes, and the evolving social-engineering threat landscape.</description><pubDate>Wed, 22 Jan 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Perry Carpenter explores how AI-powered deepfakes and social-engineering techniques are reshaping the threat landscape. He argues that the human element remains the most exploitable attack surface and that awareness programmes must evolve to address AI-generated threats. His practical guidance covers training, detection techniques, and building organisational resilience.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;​​Security with AI can be bucketed into two areas. Detection based (where humans detect the spam using past experience, tone, etc in conversations) and Process based (using tools to block spams).&lt;/li&gt;&lt;li&gt;​​AI should leveraged for automating tedious manual activities. At the same time it should be verified before the knowledge is amplified.&lt;/li&gt;&lt;li&gt;Measuring security programs should be Impact driven, focusing on outcomes and behavior based assessments rather than only focusing on attendance. Role playing is a key exercise to help employees understand attackers mindset.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>From Awareness to Action: Building a Resilient Security Culture with Mauricio Duarte</title><link>https://www.scaletozero.com/episodes/from-awareness-to-action-building-a-resilient-security-culture-with-mauricio-duarte/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/from-awareness-to-action-building-a-resilient-security-culture-with-mauricio-duarte/</guid><description>Mauricio Duarte on building resilient security culture, behaviour-based awareness programmes, and incident-response speed vs accuracy.</description><pubDate>Wed, 08 Jan 2025 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Mauricio Duarte argues that risk-based prioritisation is the key to successful cybersecurity programmes. Awareness programmes should be behaviour-based rather than tool-based, covering both individual and organisational goals with clear objectives. During incident response, finding the right balance between speed and accuracy matters — analysing before acting improves stakeholder communication.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For the success of CyberSecurity Programs, Prioritization is the Key. Follow a Risk based approach for prioritization.&lt;/li&gt;&lt;li&gt;CyberSecurity awareness programs should be behavior based vs tool based. It should also cover both individual and organizational goals. Most importantly, programs should have clear objectives since the landscape changes frequently be it because of new tools like ChatGPT or new attacks.&lt;/li&gt;&lt;li&gt;In case of Incident Response, find the right balance between speed and accuracy. Analyzing the incident before acting on it helps a lot with Internal and external stakeholder communication.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>From Detection to Recovery: Understanding Incident Response Lifecycle with Giorgio Perticone</title><link>https://www.scaletozero.com/episodes/from-detection-to-recovery-understanding-incident-response-lifecycle-with-giorgio-perticone/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/from-detection-to-recovery-understanding-incident-response-lifecycle-with-giorgio-perticone/</guid><description>Giorgio Perticone on the incident-response lifecycle from detection to recovery, staying calm under pressure, and containment.</description><pubDate>Wed, 18 Dec 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Giorgio Perticone stresses that one of the most important skills in incident response is staying calm and analysing the situation before acting. Preparation means defining processes, playbooks, documenting the landscape, and planning stakeholder communication ahead of time. Containment is key to limiting impact and preventing repeat attacks — quick decisions backed by solid analysis make the difference.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;One of the key skills necessary during Incident Response is to stay calm. Analyze the incident before acting on it. Find the right balance between Speed and Accuracy of Analysis&lt;/li&gt;&lt;li&gt;For Preparedness, Define Processes, Playbooks, Document Landscape and Stakeholder Communication plans to avoid figuring things out during an incident. Reducing the stress on the Incident Response Team.&lt;/li&gt;&lt;li&gt;Containment is key to limit the impact and also avoid repeat breaches / attacks of the same kind. Quick decision making and proper incident analysis will help in containment plan in future.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The CISO&apos;s Dilemma: Balancing Security, Innovation, and Burnout with Ross Young</title><link>https://www.scaletozero.com/episodes/the-cisos-dilemma-balancing-security-innovation-and-burnout-with-ross-young/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-cisos-dilemma-balancing-security-innovation-and-burnout-with-ross-young/</guid><description>Ross Young on the CISO&apos;s dilemma — balancing security, innovation, and burnout — and building cross-functional champions.</description><pubDate>Wed, 04 Dec 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ross Young argues that CISOs should cross-train beyond their specialty into incident management, GRC, and people management. Communication is essential — he offers two tips: tailor the message to each team, and build champions at the leadership or exec level to promote cybersecurity programmes. Before implementing a new programme, he advises gauging whether it will be cheaper, faster, and better in a year.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Cross-training is key for CISOs. CISOs specializing in AppSec should also focus on other areas like Incident Management, GRC, and People Management to name a few areas. And remember Perfection is the enemy of good.&lt;/li&gt;&lt;li&gt;Communication is an essential skill for CISOs &amp; Security Leaders. 2 Pro Tips. Tailor your message according to the Team.&lt;/li&gt;&lt;li&gt;Similar to Security Champions in Engineering, Socialize and build champions in Leadership or Exec Level so that they become your voice to promote CyberSecurity Programs.&lt;/li&gt;&lt;li&gt;Before implementing a new Security Program, gauge the effectiveness of the program in a year&apos;s time. Check if it’s Cheaper, Faster, and better than the current program. This is where hiring/surrounding yourself with experts/smart people will help.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Unraveling the Mysteries of Privacy Engineering: A Deep Dive with Apoorvaa Deshpande</title><link>https://www.scaletozero.com/episodes/unraveling-the-mysteries-of-privacy-engineering-a-deep-dive-with-apoorvaa-deshpande/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/unraveling-the-mysteries-of-privacy-engineering-a-deep-dive-with-apoorvaa-deshpande/</guid><description>Apoorvaa Deshpande, Senior Privacy Engineer at Google Cloud, on privacy engineering, privacy by design, and GenAI data governance.</description><pubDate>Wed, 20 Nov 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Apoorvaa Deshpande explains that privacy engineering focuses on responsible handling of user data and finding the balance between utility and protection. Privacy by design integrates these practices into each step of the SDLC, reducing rework and hard conversations with other teams. For GenAI, she highlights emerging techniques like secure training, machine unlearning, and data sanitisation.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Privacy engineering focuses on implementing privacy best practices for users and organizations. The core focus is user&apos;s privacy and responsible handling of their data. Finding the balance between experience and fatigue is key.&lt;/li&gt;&lt;li&gt;Privacy by design enables teams to incorporate privacy engineering practices to each steps of SDLC. Ensuring less rework, better prioritization and to avoid hard conversations with other teams. Communication plays a major role in this entire process.&lt;/li&gt;&lt;li&gt;For gen AI data privacy, promising technologies such as secure training and inference, machine unlearning are being developed. For today, companies should invest in data sanitization, data governance and using synthetic data.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Getting Started with Cloud Pentesting with Scott Weston</title><link>https://www.scaletozero.com/episodes/getting-started-with-cloud-pentesting-with-scott-weston/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/getting-started-with-cloud-pentesting-with-scott-weston/</guid><description>Scott Weston, senior consultant at NetSPI, on cloud penetration testing, the GCPwn tool he created, and how to get started with cloud security testing.</description><pubDate>Wed, 06 Nov 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;gcpwn (modeled after Pacu) is a great tool for pentesting covering enumeration and lateral movement. There are many more capabilities coming up soon with support for more Services and APIs. Annual Pen Testing is a good start. But, pentesting should be as close to continuous as possible. It helps organizations stay up to date with their attack surface. Scott Weston explains how GCPwn, his open-source tool modeled after Pacu, helps penetration testers enumerate GCP environments and track credential permissions. He advocates for continuous or near-continuous pentesting rather than annual assessments to keep up with evolving attack surfaces. For those new to cloud pentesting, he recommends starting with IAM, since it connects all other services. - &quot;gcpwn (modeled after Pacu) is a great tool for pentesting covering enumeration and lateral movement. There are many more capabilities coming up soon with support for more Services and APIs.&quot; - &quot;Annual Pen Testing is a good start. But, pentesting should be as close to continuous as possible. It helps organizations stay up to date with their attack surface.&quot; - &quot;When starting to pentest, start with IAM. It connects all other services together and the most impactful. For environments, create a seggregated cloud environment for pentesting and tear it down once it’s not used anymore.&quot;&lt;/p&gt;</content:encoded></item><item><title>Mastering Zero Trust: A Comprehensive Guide with Dr. Natalia Semenova</title><link>https://www.scaletozero.com/episodes/mastering-zero-trust-a-comprehensive-guide-with-dr-natalia-semenova/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/mastering-zero-trust-a-comprehensive-guide-with-dr-natalia-semenova/</guid><description>Dr. Natalia Semenova on zero-trust architecture, the challenges of asset and identity discovery, and identity as the core of zero trust.</description><pubDate>Wed, 23 Oct 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Dr. Natalia Semenova emphasises that zero trust is a continuous journey, not a set-and-forget programme. The biggest adoption challenges centre on discovering all assets and identities and understanding their roles. Identity is the core component — an IAM assessment that segregates human, non-human, and external identities helps organisations map their attack surface.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Zero Trust is a continuous journey. It’s not like a set it and forget it type of program. Organizations need to invest not only to set it up initially but also to keep monitoring and improving the program.&lt;/li&gt;&lt;li&gt;For adoption of zero trust, some of the biggest challenges arise from Assets discovery and Identities discovery. Having a clear picture of all the assets, identities and their role in the overall organization.&lt;/li&gt;&lt;li&gt;Identity is a core component of Zero Trust. IAM Assessment and Segregation (between Humans, Non-Humans and External Identities) help organizations understand the Attack Surface and plan for the best possible Zero Trust Policy.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Ultimate Guide to Cloud Security: A Deep Dive with Richard Stiennon</title><link>https://www.scaletozero.com/episodes/the-ultimate-guide-to-cloud-security-a-deep-dive-with-richard-stiennon/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-ultimate-guide-to-cloud-security-a-deep-dive-with-richard-stiennon/</guid><description>Richard Stiennon on the ultimate guide to cloud security, the evolving threat landscape, and building defence in depth.</description><pubDate>Wed, 09 Oct 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Richard Stiennon provides a comprehensive look at cloud security, drawing on decades of industry analysis to explain how the threat landscape is evolving. He argues for defence in depth and layered controls rather than reliance on any single solution. His practical guidance covers prioritisation, vendor selection, and aligning security investments with business risk.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Vendor / Platform selection should be based on organization goals. CISOs &amp;amp; Security leaders should prioritize selection based on current posture and look at achieving a set of future goals vs compliance needs or by following a checkbox approach.&lt;/li&gt;&lt;li&gt;Vendor health is an important aspect of determining a platform/vendor. For agent-based solutions, avoid &amp;amp; delay automatic updates from vendors.&lt;/li&gt;&lt;li&gt;When rolling out vendor tools, follow a phased rollout and add the rollout as part of a contract clause. This will push vendors to prioritize implementation, support &amp;amp; training.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Mastering Cloud Incident Response with Hilal Ahmad Lone</title><link>https://www.scaletozero.com/episodes/mastering-cloud-incident-response-with-hilal-ahmad-lone/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/mastering-cloud-incident-response-with-hilal-ahmad-lone/</guid><description>Cloud incident response with Hilal Ahmad — monitoring MTTD and MTTR, and why out-of-the-box security tools are never enough.</description><pubDate>Wed, 25 Sep 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Hilal Ahmad argues that a defined incident-response process and team alignment are the foundations of a successful programme. Continuously monitoring MTTD and MTTR drives steady improvement. Out-of-the-box security tools — whether open source, cloud native, or vendor-provided — never offer full coverage; customisation is always needed.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Having a defined Incident Response Process and Alignment among the team are key for a successful Incident Response Program&lt;/li&gt;&lt;li&gt;Monitor your MTTD and MTTR and use that to constantly improve your Incident Response Program.&lt;/li&gt;&lt;li&gt;When it comes to the Security of your organization, Open Source or Native security tools or vendor tools do not provide 100% coverage. It always needs customization as these lack the context.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Rethinking the Framework: Addressing Inherent Cybersecurity Risks with Gretchen Ruck</title><link>https://www.scaletozero.com/episodes/rethinking-the-framework-addressing-inherent-cybersecurity-risks-with-gretchen-ruck/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/rethinking-the-framework-addressing-inherent-cybersecurity-risks-with-gretchen-ruck/</guid><description>Gretchen Ruck on rethinking cybersecurity frameworks, addressing inherent risk, and measuring security effectiveness.</description><pubDate>Wed, 18 Sep 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Gretchen Ruck challenges organisations to rethink how they use frameworks by addressing inherent cybersecurity risks rather than treating frameworks as checklists. She emphasises measuring the actual effectiveness of security controls and adapting programmes as risk evolves. Her practical approach focuses on what matters most to the organisation&apos;s threat landscape.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;GenAI Tools are good at generic information. But, it often lacks contextual awareness. Building contextual awareness it into the GenAI tooling to get the maximum benefit of this technology trend.&lt;/li&gt;&lt;li&gt;Data privacy &amp;amp; Privacy Enhancing Technology (PET) plays a critical role in organisation’s GenAI strategy. Enough guardrails should be put in place to ensure privacy is at the top of mind.&lt;/li&gt;&lt;li&gt;Inherent risks are difficult to understand. Some of the cybersecurity frameworks gloss over it. But, it’s equally important for success of cybersecurity programs.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Auto Remediation on AWS with Lily Chau</title><link>https://www.scaletozero.com/episodes/auto-remediation-on-aws-with-lily-chau/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/auto-remediation-on-aws-with-lily-chau/</guid><description>Lily Chau on auto-remediation in AWS, overcoming stakeholder buy-in challenges, and prioritising security fixes.</description><pubDate>Wed, 11 Sep 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Lily Chau stresses two essentials for cloud security: strong preventive baselines and reactive remediation for drifts. The biggest challenge with remediation programmes is getting buy-in from engineering, DevOps, and leadership — she recommends demonstrating MTTR improvements. Prioritisation of what to remediate is tied to the organisation&apos;s security maturity.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;There are two essentials to focus in cloud security. Strong security foundations / baselines for preventive measures and remediations for drifts from a reactive measures stand point.&lt;/li&gt;&lt;li&gt;Biggest challenge with remediation programs is buy-in from other stakeholders like Engineering, DevOps, Leadership. To get the buy-in, show the current MTTR vs future golden standard.&lt;/li&gt;&lt;li&gt;Prioritization of remediation is co-related with security maturity of the organization. In areas like Misconfiguration, Threat Intel, Attack Surface amongst others.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Demystifying Identity and Access Management with John Giglio</title><link>https://www.scaletozero.com/episodes/demistifying-identity-and-access-management-with-john-giglio/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/demistifying-identity-and-access-management-with-john-giglio/</guid><description>John Giglio on demystifying IAM, the security-vs-compliance debate, and data-perimeter controls for read, write, and download.</description><pubDate>Wed, 04 Sep 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;John Giglio explains that the IAM landscape is always a moving target, so understanding the organisational structure and cloud-service usage is the first step. He argues that when security basics are implemented correctly, compliance follows naturally. For data-perimeter security, he recommends applying different DLP controls for read, write, and download based on user activity and network logs.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;In an organization, the IAM landscape is always a moving target. So, understand the organizational structure and usability of cloud services before setting up the foundation.&lt;/li&gt;&lt;li&gt;Security vs Compliance is an age-old debate. When the security basics are implemented the right way, compliance automatically follows.&lt;/li&gt;&lt;li&gt;For data perimeter security, use different levels of controls at DLP. Read, Write, and Download data should have different controls. This should be derived from user activity and network logs.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The intersection of Security and Human Behavior ft. Classie Clark</title><link>https://www.scaletozero.com/episodes/intersection-of-security-and-human-behavior-ft-classie-clark/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/intersection-of-security-and-human-behavior-ft-classie-clark/</guid><description>Cassie Clark on the intersection of security and human behaviour, choice architecture, and continuous awareness programmes.</description><pubDate>Wed, 28 Aug 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Cassie Clark argues that infusing security into daily engineering practices — like adding security review to the code-review process — enhances programme effectiveness. Training and awareness should be continuous, actionable, and focused on behavioural risks alongside technical controls. Choice architecture plays a major role: offering a specific password manager or MFA provider, rather than just the concept, nudges better security decisions.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;To enhance security program effectiveness, infuse security into daily practices of engineering and others. A simple example could be doing a security review as part of the [code review](https://www.cloudanix.com/blog/top-10-code-security-best-practices-for-developers) process in SDLC.&lt;/li&gt;&lt;li&gt;Training and Awareness programs should be continuous and actionable with a focus on behavioral risks in addition to technical controls.&lt;/li&gt;&lt;li&gt;Choice architecture plays a major role in implementing security programs at organizations. A few examples could be the option of a password manager vs a specific password manager. Option of using a specific MFA provider vs support for multiple providers.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Building Security Foundation and Security Boundaries with Kushagra Sharma</title><link>https://www.scaletozero.com/episodes/building-security-foundation-and-security-boundaries-with-kushagra-sharma/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/building-security-foundation-and-security-boundaries-with-kushagra-sharma/</guid><description>Kushagra Sharma, Senior Platform Security Engineer at Booking.com, on security baselines, boundaries, and layered defences.</description><pubDate>Wed, 21 Aug 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Kushagra Sharma argues that security baselines and boundaries together define an organisation&apos;s security foundation — covering network, IAM, infrastructure, and data. Baselining is a continuous cycle of defining, measuring, monitoring, and refining. There is no one-size-fits-all baseline; grouped and layered baselines are the way to scale.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security baseline along with security boundaries define the security foundation for Organizations. There are various types of security baselines organizations should incorporate like Network, IAM, Infra, and Data.&lt;/li&gt;&lt;li&gt;Baselining is a continuous process. Define it, measure it, monitor it, and refine it using internal and external audits &amp;amp; findings.&lt;/li&gt;&lt;li&gt;There’s no one-size-fits-all security baseline. However, define grouped and layered baselines to scale security practices in organizations.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Trust &amp; Security: The Cornerstones of a Resilient Organization! With Sandeep Agarwal</title><link>https://www.scaletozero.com/episodes/trust-security-the-cornerstones-of-a-resilient-organization-with-sandeep-agarwal/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/trust-security-the-cornerstones-of-a-resilient-organization-with-sandeep-agarwal/</guid><description>Sandeep Agarwal on trust and security as the cornerstones of organisational resilience, leadership alignment, and building durable programmes.</description><pubDate>Wed, 14 Aug 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Sandeep Agarwal argues that trust and security together form the foundation of a resilient organisation. He discusses how to build durable security programmes that survive leadership changes and budget cycles. Aligning security goals with broader business objectives is, in his view, what earns and sustains executive support.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For organizations, alignment between Revenue Goals vs Cost vs Risk is key for success. Instead of teams working in isolation, collaborate to improve the security of the organization.&lt;/li&gt;&lt;li&gt;Security is seen as a team of No. Instead of saying No, security teams should show the path to Yes for business.&lt;/li&gt;&lt;li&gt;The most important asset in Security is not the Tools or Processes but the People. And people consider what they observe as culture vs what’s preached. Practice security basics to set a solid foundation.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding the Continuous Security and Incident Response Landscape</title><link>https://www.scaletozero.com/episodes/understanding-the-continuous-security-and-incident-response-landscape/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-the-continuous-security-and-incident-response-landscape/</guid><description>Jan Hertsens, Senior Security Consultant at AWS, on continuous security, the compliance debate, and incident-response segmentation.</description><pubDate>Wed, 07 Aug 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jan Hertsens recommends that organisations understand the different personas and agendas around compliance and security, then establish a governing body for prioritisation. He advises starting with basic security practices and focusing on one programme at a time. Network segmentation, in his view, plays a major role in incident response by reducing the blast radius.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For the compliance and security debate, understand different personas and their agendas, have a governing body that works with all of these personas, and helps with prioritization.&lt;/li&gt;&lt;li&gt;Always start with basic security practices and focus on one program at a time so that it doesn&apos;t get out of hand when it comes to implementing security practices or compliance controls.&lt;/li&gt;&lt;li&gt;Network segmentation plays a major role when it comes to incident response. It helps with reducing the blast radius.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Network Security Fortress: Master Network Segmentation with Tom Adamski</title><link>https://www.scaletozero.com/episodes/network-security-fortress-master-network-segmentation-with-tom-adamski/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/network-security-fortress-master-network-segmentation-with-tom-adamski/</guid><description>Tom Adamski on network segmentation, risk assessment before design, and layering AWS security tools for defence in depth.</description><pubDate>Wed, 24 Jul 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Tom Adamski recommends performing a risk assessment of the business and infrastructure before designing network segmentation — let the drivers (compliance, security, or management) shape the approach. Segmentation should stay at a broader level to remain operable; overly granular rules become difficult to maintain. AWS security tools like security groups, NACLs, subnets, and firewalls are additive, not interchangeable.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;​​Before working on NS, Perform Risk Assessment of the business &amp;amp; infrastructure. Depending on the need like compliance or security or management or others, build your Network Segmentation.&lt;/li&gt;&lt;li&gt;Network Segmentation should be performed more at a broader level instead of very granular. This would become difficult to operate and maintain.&lt;/li&gt;&lt;li&gt;Security tools are AND and not OR in AWS. Depending on the use cases, leverage the security tools and appliances like Security Groups, NACLs, Subnets, Transit Gateways, Firewalls, etc.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding the role of logging and monitoring in detective controls with Kailash Havildar</title><link>https://www.scaletozero.com/episodes/understanding-the-role-of-logging-and-monitoring-in-detective-controls-with-kailash-havildar/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-the-role-of-logging-and-monitoring-in-detective-controls-with-kailash-havildar/</guid><description>Kailash Havildar on logging, monitoring, and detective controls in cloud security — what to capture and how to act on it.</description><pubDate>Wed, 10 Jul 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Kailash Havildar discusses the critical role of logging and monitoring as detective controls in cloud environments. He covers what to capture, how to structure alerts, and the operational practices that turn raw data into actionable security insights. His advice centres on building a monitoring programme that scales with the organisation.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Standardization of logs is very important when designing a Centralized Logging and Monitoring solution. Both from a security and also from an engineering perspective.&lt;/li&gt;&lt;li&gt;When it comes to Logging, start with User Logs, System Logs, Config Logs, Network Logs, in that order to analyze for Detecting Security issues.&lt;/li&gt;&lt;li&gt;For Prevention Controls, start with Regions, Services, Access and Configuration controls. This helps organizations approach security in a structured manner.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Building Cybersecurity Teams with Matthew Marji</title><link>https://www.scaletozero.com/episodes/building-cybersecurity-teams-with-matthew-marji/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/building-cybersecurity-teams-with-matthew-marji/</guid><description>Matthew Marji on building cybersecurity teams, evaluating communication skills in hiring, and aligning security with business.</description><pubDate>Wed, 26 Jun 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Matthew Marji argues that written and oral communication are critical skills for security engineers and should be assessed during hiring. Assessing business risk helps decide whether to hire a contractor, a pentester, or a CISO. Security alignment with the business, in his view, is just as important as engineering alignment.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Communication, both written and oral, are key skills for security engineers and organizations should evaluate for this during the hiring process.&lt;/li&gt;&lt;li&gt;For startups while hiring, assessing the business risk has a huge impact because it helps you decide whether to hire a contractor or a pen tester or a CISO and also whether you should hire someone internally or work with an external agency.&lt;/li&gt;&lt;li&gt;Alignment is key for business success. So similarly, Security alignment is key for success of security programs.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding Threat Modeling and Secure by Design Concept with Adam Shostack</title><link>https://www.scaletozero.com/episodes/understanding-threat-modeling-and-more/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-threat-modeling-and-more/</guid><description>Adam Shostack on threat modelling fundamentals, secure-by-design principles, and making threat analysis accessible to all teams.</description><pubDate>Wed, 12 Jun 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Adam Shostack shares his approach to making threat modelling practical and accessible, emphasising that it is not just for security experts. He discusses secure-by-design principles and how to integrate threat analysis into development workflows. His guidance covers common frameworks, team enablement, and measuring the outcomes of a threat-modelling programme.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Secure by design is a key step in building a healthy security program. It should not be done, or rather it should be done while designing and building applications and not as an afterthought.&lt;/li&gt;&lt;li&gt;When it comes to threat modeling, taking a pause and asking questions about possible threats is equally important as finding a solution to the threats.&lt;/li&gt;&lt;li&gt;Communication is key to evangelizing and championing security programs in the organization. And it goes both ways, security to non-security teams and vice versa.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Conquering Enterprise Risk Management with Amit Subhanje</title><link>https://www.scaletozero.com/episodes/conquering-enterprise-risk-management-with-amit-subhanje/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/conquering-enterprise-risk-management-with-amit-subhanje/</guid><description>Amit Subhanje on enterprise risk management, balancing proactive and reactive strategies, and shared security responsibility.</description><pubDate>Wed, 29 May 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Amit Subhanje argues that risk management must balance proactive and reactive strategies rather than leaning entirely reactive. Continuous and targeted training is key to a healthy security programme. Security, in his view, is a shared organisational responsibility — not something confined to the security team.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Risk Management should not only be reactive. It has to have the right balance between proactive and reactive strategies.&lt;/li&gt;&lt;li&gt;Continuous training and awareness programs are key for running a healthy and successful security program. Also, when it comes to training, it should be targeted vs generic.&lt;/li&gt;&lt;li&gt;Security is a Shared responsibility and not a responsibility restricted to security teams. Organizations should nurture a culture where everyone in the organization feel accountable.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Exploring the World of Incident Response and Detection with Pablo Vidal</title><link>https://www.scaletozero.com/episodes/exploring-the-world-of-incident-response-and-detection-with-pablo-vidal/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/exploring-the-world-of-incident-response-and-detection-with-pablo-vidal/</guid><description>Pablo Vidal on incident response and detection, cross-team collaboration, and hiring for mutual fit in security roles.</description><pubDate>Wed, 15 May 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Pablo Vidal argues that security engineers should not work in isolation — cross-team collaboration drives programme success. He recommends having a rubric for incident detection and response to reduce stress on engineers during an event. When hiring, both the organisation and candidate should look for mutual fit in skills, goals, and scope.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;In order to ensure success of security programs, security engineers should not work in Isolation. Instead, they should collaborate across teams and organization.&lt;/li&gt;&lt;li&gt;For Incident Detection and Response, organizations should have a rubrik. It reduces the stress on engineers to figure out the right plan of action and next steps.&lt;/li&gt;&lt;li&gt;When it comes to hiring the Security Engineers, both Organizations and Candidates should look for Mutual Fit in terms of Skillsets, Future goals and Scope of the work.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Building Cybersecurity Teams and Virtuous Circle With Clients ft. Jesse Miller</title><link>https://www.scaletozero.com/episodes/building-cybersecurity-teams-and-virtus/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/building-cybersecurity-teams-and-virtus/</guid><description>Jesse Miller on building cybersecurity teams, creating a virtuous cycle with clients, and taking a risk-centric approach.</description><pubDate>Wed, 17 Apr 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jesse Miller advocates for a culture of knowledge, learning, and growth — it helps both with hiring and retaining security talent. For startups, he recommends hiring a generalist as the first security role to build trust between security and other teams. He favours a risk-centric over a tool- centric approach, arguing that without a solid security programme, tools alone cannot meet security goals.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Create and Practice a Culture of Knowledge, Learnings and Growth. This not only helps you in hiring new Security Roles but also helps in Retaining them.&lt;/li&gt;&lt;li&gt;For a Startup, hire a generalist as a First Role. This helps in Building the Trust and relationship foundation between Security and other Teams for Longer Term.&lt;/li&gt;&lt;li&gt;Follow a Risk Centric vs a Tool Centric Approach for building Security Practice in the Organization. Unless you have a solid security program, tools can’t make you meet your security goals.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Beyond the Basics: Understanding Threat Hunting and Security Research with Josh Pyorre</title><link>https://www.scaletozero.com/episodes/beyond-the-basics-understanding-threat-hunting-and-security-research-with-josh-pyorre/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/beyond-the-basics-understanding-threat-hunting-and-security-research-with-josh-pyorre/</guid><description>Josh Pyorre on threat hunting, creative security research, and the role of GenAI in uncovering new attack vectors.</description><pubDate>Wed, 03 Apr 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Josh Pyorre explains that threat researchers use hunting to learn about trends and correlations, narrowing their focus and raising awareness inside organisations. He stresses that following a checklist limits discovery — creative, out-of-the-box thinking is what finds novel attacks. GenAI is a boon for researchers but needs guardrails to prevent data leaks and new AI- inspired attacks.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Threat researchers use threat hunting to learn about trends, and correlations, to narrow focus of the research. And they use this information to watch for other threats and also to help bring awareness in organizations.&lt;/li&gt;&lt;li&gt;Threat research needs creative and out-of-the-box thinking. By following a checklist, threat researchers often do not get, often do not find out novel or unique attacks. So it doesn&apos;t help. It doesn&apos;t aid in threat hunting process.&lt;/li&gt;&lt;li&gt;GenAI platforms are a boon for researchers. They can quickly get started, learn about new attack vectors. At the same time, guardrails should be put in place to ensure that data is not leaked or employees should be trained to learn about new GenAI-based or inspired attacks.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Keeping Pace with Cloud Security: A Guide to Maturity Models with Rich Mogull</title><link>https://www.scaletozero.com/episodes/keeping-pace-with-cloud-security-a-guide-to-maturity-models-with-rich-mogull/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/keeping-pace-with-cloud-security-a-guide-to-maturity-models-with-rich-mogull/</guid><description>Rich Mogull on cloud security maturity models, the mindset shift from on-prem, and setting realistic expectations with leadership.</description><pubDate>Wed, 20 Mar 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Rich Mogull argues that cloud security demands a different mindset from on- prem and that a maturity model helps bridge that gap. The biggest challenge is expectation setting — working with leadership to define what is realistic. He recommends evaluating your current level, setting a clear goal, and tracking progress toward it.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When it comes to Cloud Security, it needs a mindset shift vs on-prem security. And Cloud Security Maturity Model helps with that.&lt;/li&gt;&lt;li&gt;Biggest challenge with Adoption of Cloud Security Maturity Model is expectation setting. Work with Leadership to set the right expectations.&lt;/li&gt;&lt;li&gt;Before acting on Maturity Model, evaluate the current Level, set a Goal and work towards it. This helps teams to monitor, measure, communicate about and achieve the goal.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>The Cloud Security Saga with Joseph South</title><link>https://www.scaletozero.com/episodes/the-cloud-security-saga-with-joseph-south/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/the-cloud-security-saga-with-joseph-south/</guid><description>Joseph South on the cloud security journey, starting with common misconfigurations, and using the Cloud Controls Matrix.</description><pubDate>Wed, 21 Feb 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Joseph South argues that teams should focus on basic and common cloud misconfigurations first, tackling edge cases only after those are resolved. Securing the pipeline is essential for prevention — infrastructure deployed into the cloud must be verified before it lands. He recommends the Cloud Security Alliance&apos;s Cloud Controls Matrix as a starting point.&lt;/p&gt;</content:encoded></item><item><title>Understanding the concepts of Supply Chain Security, Container Images, SBOMs, and more with Aung</title><link>https://www.scaletozero.com/episodes/understanding-the-concepts-of-supply-chain-security-container-images-sboms-and-more-with-aung/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-the-concepts-of-supply-chain-security-container-images-sboms-and-more-with-aung/</guid><description>Htet Naing Aung on supply-chain security, container-image signing, SBOMs, and using SCA tools in CI/CD pipelines.</description><pubDate>Wed, 07 Feb 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Htet Naing Aung argues that SBOMs are key to supply-chain security, helping organisations understand dependencies and their vulnerabilities. He recommends integrating a software-composition-analysis tool into the CI/CD process. For image signing, best practices include using a key-management solution with rotation, secure root and private keys, and a trusted registry with continuous monitoring.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Software Bill of Material (SBOM) is key for Supply Chain Security. It helps organizations understand dependencies and vulnerabilities associated with the dependencies.&lt;/li&gt;&lt;li&gt;To analyze SBOMs, utilize a Software Composition Analysis (SCA) Tool and integrate is as part of CI/CD Process.&lt;/li&gt;&lt;li&gt;Some of the best practices of Image Signing are using a Key Management Solution which has capabilities like Rotation, Secure Root and Private Keys, Use of a Trusted Registry with Continuous Monitoring on it to name a few.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Navigating the Identity and Access Management Landscape with Joseph South</title><link>https://www.scaletozero.com/episodes/navigating-the-identity-and-access-management-landscape-with-joseph/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/navigating-the-identity-and-access-management-landscape-with-joseph/</guid><description>Joseph South on the cloud IAM landscape, why IAM is the new perimeter, and getting leadership buy-in for security practices.</description><pubDate>Wed, 24 Jan 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Joseph South argues that cloud IAM requires a fundamentally different mindset — once credentials are compromised, attackers gain access to all infrastructure, making IAM the new perimeter. He recommends tagging IAM resources, cleaning up inactive roles with over-permissions, and optimising duplicates. Leadership buy-in is essential for enforcing best practices collaboratively.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security of Cloud IAM requires a different mindset than traditional IAM. Once credentials are breached, attackers gain access to all infrastructure in a Cloud environment. This is one of the Primary Reasons why IAM is the new Perimeter.&lt;/li&gt;&lt;li&gt;To address IAM security gaps, start with Tagging of IAM Resources, Cleanup Inactive, Roles with Over Permissions, and optimizing duplicate permissions.&lt;/li&gt;&lt;li&gt;Security Buy-In is key from Leaders. This helps Security teams collaboratively enforce Security Best Practices.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Unlock the Secrets to Successful Cloud Security with Andre Rall</title><link>https://www.scaletozero.com/episodes/unlock-the-secrets-to-successful-cloud-security-with-andre-rall/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/unlock-the-secrets-to-successful-cloud-security-with-andre-rall/</guid><description>Andre Rall on the secrets to successful cloud security, building strong foundations, and aligning security with cloud strategy.</description><pubDate>Wed, 10 Jan 2024 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Andre Rall shares what separates successful cloud security programmes from those that struggle. He emphasises building strong foundations — identity, access, and visibility — before layering on advanced controls. Aligning the security roadmap with the overall cloud strategy and demonstrating value to leadership are, in his view, the keys to sustained investment.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;IAM is the critical component when moving workloads from On-Prem to Cloud. Special attention should be paid to Right Sizing of Permissions early on as part of Cloud Security strategy.&lt;/li&gt;&lt;li&gt;Visibility of Cloud Assets is important. Implement Automation for workloads and follow DevSecOps best practices to ensure Security is incorporated in all phases of SDLC.&lt;/li&gt;&lt;li&gt;When it comes to filling Cyber Security skill gap, start with Hands on Webinars, Workshops, attend Cloud Security conferences and go for Certifications to validate your learnings.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Guardian Code: Safeguarding Applications in the AI Era with Jim Manico</title><link>https://www.scaletozero.com/episodes/guardian-code-safeguarding-applications-in-the-ai-era-with-jim-manico/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/guardian-code-safeguarding-applications-in-the-ai-era-with-jim-manico/</guid><description>Jim Manico on safeguarding applications in the AI era, verifying AI-generated code, and applying OWASP best practices on top of frameworks.</description><pubDate>Wed, 27 Dec 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jim Manico advises teams to trust but verify code generated by AI tools — always run it through static and dynamic scans in the DevSecOps pipeline. During prompt engineering, he recommends avoiding sensitive data and requesting low cyclomatic-complexity output. On top of any framework&apos;s built-in protections, teams should still apply OWASP Top 10 security best practices.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When it comes to Code generation using Gen AI tools, Trust but Verify. Always run those through your DevSecOps pipelines for Static &amp;amp; Dynamic Scans.&lt;/li&gt;&lt;li&gt;During Prompt engineering, stay away from feeding sensitive information and ask for Low Cyclomatic Complexity recommendations. It’s simpler and easier to maintain.&lt;/li&gt;&lt;li&gt;On top of adding Security capabilities, when using any framework like React or Ruby on Rails, use them securely and apply application security best practices on top of it. Like OWASP Top 10 recommendations.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Guardians of Trust: Navigating Third-Party Risk Across Business Realms with Jeffrey Wheatman</title><link>https://www.scaletozero.com/episodes/guardians-of-trust-navigating-third-party-risk-across-business-realms-with-jeff/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/guardians-of-trust-navigating-third-party-risk-across-business-realms-with-jeff/</guid><description>Jeffrey Wheatman, Cyber Risk Evangelist at Black Kite, on third-party risk management, vendor prioritisation, and procurement decisions.</description><pubDate>Wed, 13 Dec 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jeffrey Wheatman argues that vendor security questionnaires go stale within a month and continuous assessment is far more important. Prioritising vendors by business value and impact — categorising them as critical, important, or nice-to-have — prevents overwhelm. For procurement decisions, understanding the cost-vs-value factor is essential since security is ultimately accountable.&lt;/p&gt;</content:encoded></item><item><title>Security that speaks to heart; understanding emotional intelligence and third-party risk management with Shivani Arni</title><link>https://www.scaletozero.com/episodes/security-that-speaks-to-heart-understanding-emotional-intelligence-and-third-party-risk-management-with/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/security-that-speaks-to-heart-understanding-emotional-intelligence-and-third-party-risk-management-with/</guid><description>Shivani Arni, CISO at TransUnion CIBIL, on emotional intelligence in security leadership and third-party risk management.</description><pubDate>Wed, 29 Nov 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Shivani Arni explores how emotional intelligence strengthens security leadership — understanding team dynamics, stakeholder motivations, and organisational politics. She discusses third-party risk management strategies and the importance of balancing due diligence with operational pragmatism. Building trust with partners and internal teams is, in her view, what makes security programmes sustainable.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;From a culture perspective, create an environment where your Team feels comfortable in taking Risks. Without Risk Taking, there’s no Innovation.&lt;/li&gt;&lt;li&gt;When it comes to Security, show the ROI to the Leadership and do not forget to recognize effort and celebrate small wins.&lt;/li&gt;&lt;li&gt;Assign Tiers to vendors based on Business Criticality. This helps in prioritization in future.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Identity and Access Management in the Cloud: Beyond Mere Access Control</title><link>https://www.scaletozero.com/episodes/identity-and-access-management-in-the-cloud-beyond-mere-access-control/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/identity-and-access-management-in-the-cloud-beyond-mere-access-control/</guid><description>Chad Lorenc, Security Practice Manager at AWS, on cloud IAM beyond access control, showing value to leadership, and production-account security.</description><pubDate>Thu, 16 Nov 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Chad Lorenc recommends mapping IAM improvements to business outcomes — cost savings from audits, developer productivity gains, and faster MTTD/MTTR. To keep cloud security manageable, he advises consolidating data sources like SIEM, SOAR, and IDS/IPS and monitoring posture continuously. For production accounts, he argues for zero human access and no access keys — use IaC and pipelines instead.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;To Show Value of IAM improvements to Leadership, map them to outcomes like Cost Improvement from Audit/SOX perspective, Developer Productivity Gains via Provisioning improvements and MTTD &amp;amp; MTTR from Incident Response perspective.&lt;/li&gt;&lt;li&gt;To keep Cloud Security complexity to minimum, bring all your data sources (like SIEM, SOAR, IDS/IPS) together and Monitor your Security Posture.&lt;/li&gt;&lt;li&gt;For your Production Account security, avoid providing access to Humans and definitely a no Access Keys. Implement IaC and Pipelines for Provisioning.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Unleash the power of DevSecOps and Cloud-Native Security with Kayra Otaner</title><link>https://www.scaletozero.com/episodes/unleash-the-power-of-devsecops-and-cloud-native-security-with-kayra-otaner/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/unleash-the-power-of-devsecops-and-cloud-native-security-with-kayra-otaner/</guid><description>Kayra Otaner on DevSecOps, cloud-native security, and unleashing security capabilities without slowing engineering teams.</description><pubDate>Fri, 10 Nov 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Kayra Otaner discusses how to bring DevSecOps and cloud-native security together in a way that empowers rather than blocks engineering teams. He shares strategies for embedding security into the pipeline, choosing the right tools, and measuring the impact of a DevSecOps programme. His focus is on practical, achievable steps for teams at any maturity level.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Organizational alignment is the most important factor for Security roadmap. Pro tip - when speaking with Business, Security Teams should use the Business Language instead of Technical Language.&lt;/li&gt;&lt;li&gt;Build a One team culture. Brown Bags, Lightning Talks, Dojos, etc are great ways to collaborate with Engineering and Product teams to build relationships, show value and impact of Security function to other parts of the organization.&lt;/li&gt;&lt;li&gt;When it comes to Cloud Migration, Lyft and Shift does not work. Follow Cloud Best practices from a packaging and containerization perspective. And, focus on 4 Cs - Code, Container, Cluster and Cloud from a security perspective.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Revolutionize your approach to SDLC using DevSecOps techniques with Matt Tesauro</title><link>https://www.scaletozero.com/episodes/revolutionize-your-approach-to-sdlc-using-devsecops-techniques-with-matt-tesauro/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/revolutionize-your-approach-to-sdlc-using-devsecops-techniques-with-matt-tesauro/</guid><description>Matt Tesauro on revolutionising the SDLC with DevSecOps, automation for team velocity, and training security professionals.</description><pubDate>Fri, 27 Oct 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Matt Tesauro argues that DevSecOps should be integrated at every stage of the SDLC, not bolted on at the end. He leverages automation to maximise team velocity and advocates for training both emerging and senior security professionals. Open-source projects and community involvement, in his view, are essential drivers of DevSecOps adoption.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Context is key. When looking at Vulnerabilities do not just look at CVSS Base score, instead, understand your Risk Profile and add the Environmental elements for better prioritization.&lt;/li&gt;&lt;li&gt;In order to adhere to DevSecOps practices, be pragmatic. Instead of a Big Bang approach, start small and iterate to incorporate Security into existing DevOps practices.&lt;/li&gt;&lt;li&gt;When it comes to Prioritization of findings from SAST or SCA or Vulnerability Management or Security tools in general, Let the Security team jump in and add context to help with information overload and prioritization.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Shielding Your Supply Chain: Strengthening Security Measures with Francois Proulx</title><link>https://www.scaletozero.com/episodes/francois/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/francois/</guid><description>François Proulx, Senior Product Security Engineer at Boost Security, on supply-chain security, threat modelling, and SBOMs.</description><pubDate>Fri, 13 Oct 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;François Proulx argues that application security should start with threat modelling that includes full architectural context, thinking like an attacker. For open-source dependencies, he recommends a baseline vulnerability scan followed by a continuous review process. Understanding SBOMs and verifying dependency validity — using tools like deps.dev — is essential for supply-chain security.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For Application Security, start with Threat Modeling including Context. Look at all our architecture diagrams and start evaluating from an attacker&apos;s mind.&lt;/li&gt;&lt;li&gt;When using Open Source dependencies, start with a Baseline Vulnerability Scan and do a continuous process to review and evaluate dependencies.&lt;/li&gt;&lt;li&gt;Understand dependencies, SBOM to verify validity of dependencies. One of the tools to do this is deps.dev.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding Vulnerability Management, Supply Chain Security, &amp; SBOMs with Yotam Perkal</title><link>https://www.scaletozero.com/episodes/understanding-vulnerability-management-supply-chain-security-sboms-with-yotam-perkal/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-vulnerability-management-supply-chain-security-sboms-with-yotam-perkal/</guid><description>Yotam Perkal on vulnerability management, supply-chain security, SBOMs, and prioritising the risks that matter most.</description><pubDate>Fri, 29 Sep 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Yotam Perkal discusses how SBOMs and vulnerability management intersect, giving organisations a clearer picture of their software supply chain. He argues that prioritising vulnerabilities by context and exploitability is more effective than treating every CVE equally. His practical guidance covers tooling, process design, and making vulnerability management sustainable at scale.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Context is key when it comes to Vulnerability Management. Instead of focusing on Vulnerabilities by severity, organizations should evaluate the exploitability and actively exploited vulnerabilities for Prioritization.&lt;/li&gt;&lt;li&gt;When looking at Vulnerabilities do not take CVSS Base score at face value, organizations should understand &amp;amp; utilize Temporal and Environmental elements and the score as well.&lt;/li&gt;&lt;li&gt;From a Supply Chain Security perspective, start with basics like SBOM to help with Visibility and add additional layers like CISA KEV Threat Intel, EPSS Score, Asset Information &amp;amp; SSVC for context and prioritization.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Navigating Threat Modeling and Vulnerability Management Challenges with Kalyani Pawar</title><link>https://www.scaletozero.com/episodes/navigating-threat-modeling-and-vulnerability-management-challenges-with-kalyani-pawar/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/navigating-threat-modeling-and-vulnerability-management-challenges-with-kalyani-pawar/</guid><description>Kalyani Pawar on threat modelling, scaling security with checklists and champions, and celebrating small wins.</description><pubDate>Fri, 08 Sep 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Kalyani Pawar argues that deep understanding of a particular capability combined with an overview of the entire architecture is critical for threat modelling. To scale security, she recommends checklists, involving all teams, and investing in a security-champions programme. Security is a journey, not a destination — celebrating small wins makes a real difference.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Detailed Understanding on particular capability with overview of entire architecture is very important from a Threat Modeling perspective.&lt;/li&gt;&lt;li&gt;Create Checklists to scale security in an organization. Involve all teams, and when possible invest and nurture a security champions program.&lt;/li&gt;&lt;li&gt;Security is a journey not a destination. Celebrate small wins. We often miss to do this. They make a lot of difference.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding the Role of Asset Management and Kubernetes in the Cloud with Kesten Broughton</title><link>https://www.scaletozero.com/episodes/understanding-the-role-of-asset-management-and-kubernetes-in-cloud-with-kesten-broughton/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-the-role-of-asset-management-and-kubernetes-in-cloud-with-kesten-broughton/</guid><description>Kesten Broughton on asset management, Kubernetes in the cloud, and why visibility is the foundation of cloud security.</description><pubDate>Fri, 25 Aug 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Kesten Broughton argues that asset management and visibility are the foundation of any cloud security programme — you cannot protect what you cannot see. He discusses the unique challenges of managing assets in Kubernetes environments and how to build an inventory that keeps pace with dynamic infrastructure. His practical advice focuses on automation, tagging, and cross-team accountability.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When it comes to asset management, always start from outside in, like DNS, to understand your dangling subdomains or public IPs, which are sort of overexposed and work your work towards inside of your infrastructure.&lt;/li&gt;&lt;li&gt;For asset inventory, get data from multiple sources so that you can use that to enrich the data that you have in your data lake.&lt;/li&gt;&lt;li&gt;Security teams should understand the point of friction with engineering teams and enable them to move faster and roll out more and more features.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Practical strategies for defending a Kubernetes cluster with Divyanshu Shukla</title><link>https://www.scaletozero.com/episodes/practical-strategies-of-defending-a-kubernetes-cluster-with-divyanshu-shukla/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/practical-strategies-of-defending-a-kubernetes-cluster-with-divyanshu-shukla/</guid><description>Divyanshu Shukla on practical strategies for defending Kubernetes clusters, detection techniques, and open-source defence tools.</description><pubDate>Fri, 04 Aug 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Divyanshu Shukla walks through hands-on defensive strategies for Kubernetes clusters, covering detection techniques and security best practices. This is the final part of a three-part series that moves from fundamentals to attack simulation to defence, giving practitioners a complete picture of cluster security.&lt;/p&gt;</content:encoded></item><item><title>Restorative Justice Framework: A New Way to Solve Conflict with Michele Chubirka</title><link>https://www.scaletozero.com/episodes/restorative-justice-a-new-way-to-solve-conflict/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/restorative-justice-a-new-way-to-solve-conflict/</guid><description>Michele Chubirka on restorative justice as a new framework for resolving cybersecurity conflict and restoring team trust.</description><pubDate>Fri, 28 Jul 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Michele Chubirka introduces restorative justice as an alternative framework for handling security conflicts and breaches within organisations. The approach centres on repairing harm, restoring relationships, and learning from incidents rather than defaulting to punitive measures. She argues this mindset can improve trust and collaboration across security teams.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;First Security hire for an organization should be a Generalist and has necessary soft skills to work with other teams to improve overall security. Soft Skills and Relationship building is key at the early stage of an organization.&lt;/li&gt;&lt;li&gt;Security Champions are important for a successful Security program implementation. Collaborate with Engineering and enable them to own the Security Roadmap.&lt;/li&gt;&lt;li&gt;When it comes to Kubernetes, Cloud providers abstract security for the managed pieces. Self hosting is another option but it brings many operational, security challenges with it. Unless absolutely necessary for business reasons, avoid self hosting and use a cloud managed k8s offering.&lt;/li&gt;&lt;li&gt;For Kubernetes security, use of Open Source tooling is a good start. On top of that, follow a threat modeling approach rather than just a checklist approach.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Workshop on Attacking a Kubernetes Cluster</title><link>https://www.scaletozero.com/episodes/workshop-on-attacking-a-kubernetes-cluster/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/workshop-on-attacking-a-kubernetes-cluster/</guid><description>Divyanshu Shukla on red-teaming Kubernetes clusters, understanding attacker mindset, and exploiting common cluster weaknesses.</description><pubDate>Fri, 14 Jul 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Divyanshu Shukla walks through approaches for attacking a Kubernetes cluster from a red-teaming perspective, helping defenders understand how attackers think. This is part two of a multi-part series, following the fundamentals covered in part one. He covers exploitation techniques, common cluster weaknesses, and the tools attackers use in the wild.&lt;/p&gt;</content:encoded></item><item><title>Master the art of Incident Response, Digital Forensics, and Threat Intelligence with Gerard Johansen</title><link>https://www.scaletozero.com/episodes/master-the-art-of-incident-response-digital-forensics-threat-intelligence-gerard-johansen/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/master-the-art-of-incident-response-digital-forensics-threat-intelligence-gerard-johansen/</guid><description>Gerard Johansen on incident response, digital forensics, threat intelligence, and training engineers on evidence collection.</description><pubDate>Fri, 07 Jul 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Gerard Johansen argues that playbooks are critical to every phase of incident response — evidence collection, triage, and retrospection. The four key factors to understand are initial access, execution, lateral movement, and command-and-control. Training engineers on architecture, data flows, and evidence preservation is a must for effective response.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Playbooks have an important role in the Incident Response Process, from all aspects, including Evidence Collection, Triage, Retrospection.&lt;/li&gt;&lt;li&gt;There are 4 key factors which need to be understood in Incident Response - Initial Access, Execution, Lateral Movement and Command &amp;amp; Control.&lt;/li&gt;&lt;li&gt;Training your engineers on Architecture (Cloud or Hybrid setup), Data flows, Evidence Collection &amp;amp; Preserve methods is a must for ideal Incident Response.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Attacking and Defending Kubernetes Cluster with Divyanshu Shukla</title><link>https://www.scaletozero.com/episodes/attacking-and-defending-kubernetes-cluster-with-divyanshu-shukla-scaletozero/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/attacking-and-defending-kubernetes-cluster-with-divyanshu-shukla-scaletozero/</guid><description>Divyanshu Shukla on attacking and defending Kubernetes clusters in a hands-on workshop-style session.</description><pubDate>Fri, 30 Jun 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Divyanshu Shukla walks through Kubernetes security from both the attacker and defender perspective in a workshop-style episode. He demonstrates common attack paths against clusters and pairs each with the corresponding defensive measures and detection techniques.&lt;/p&gt;</content:encoded></item><item><title>Cloud-Native Realm: A Comprehensive Look at Kubernetes Security with Steve Giguere</title><link>https://www.scaletozero.com/episodes/cloud-native-realm-a-comprehensive-look-at-kubernetes-security-with-steve-giguere/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/cloud-native-realm-a-comprehensive-look-at-kubernetes-security-with-steve-giguere/</guid><description>Steve Giguere on Kubernetes security, when monoliths beat containers, and vetting open-source dependencies with SBOMs.</description><pubDate>Fri, 23 Jun 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Steve Giguere argues that Kubernetes is not a universal solution — the right choice depends on company growth stage and team expertise, and monoliths can be better in some cases. He advocates shifting left with policy-as-code, SCA, code signing, and SBOM generation in the pipeline. Before adopting open-source tools, teams should evaluate contributor support, community engagement, and release frequency.&lt;/p&gt;</content:encoded></item><item><title>Digging Deeper on DevOps &amp; DevSecOps with Kyle Fossum</title><link>https://www.scaletozero.com/episodes/digging-deeper-with-devops-devsecops-kyle-fossum-s2-ep5-scale-to-zero/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/digging-deeper-with-devops-devsecops-kyle-fossum-s2-ep5-scale-to-zero/</guid><description>Kyle Fossum on DevOps and DevSecOps practices, self-serve security tooling, and why hardware security keys beat SMS-based MFA.</description><pubDate>Fri, 16 Jun 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Kyle Fossum acknowledges that security is additional overhead for DevOps but argues that self-serve tooling eases the gap between engineering and security. Best practices include keeping secrets out of code, standardising through config management and IaC, and investing in observability. He strongly recommends hardware security keys like YubiKeys over SMS or time- based MFA.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security is definitely an additional overhead for DevOps practices. Self-Serve tooling helps ease the gap between Engineering and Security.&lt;/li&gt;&lt;li&gt;Some of the best practices of DevOps are: Do not embed secrets in Code. Follow Standardization via Config Management, automation (IaC) and Observability.&lt;/li&gt;&lt;li&gt;It’s highly recommended to use Hardware Security tokens like Yubikeys vs SMS or Time based authentication tools for MFA. Use SSO for user management.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Master Application Security, Threat Modeling, and Security Resilience with Dustin Lehr</title><link>https://www.scaletozero.com/episodes/master-application-security-threat-modeling-and-security-resilience/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/master-application-security-threat-modeling-and-security-resilience/</guid><description>Dustin Lehr on application security, threat modelling, and building security-champion programmes through long-term relationships.</description><pubDate>Fri, 09 Jun 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Dustin Lehr advises organisations to start by securing production systems and then work backwards toward the source code, bridging the gap between the ideal and the current state. He acknowledges that security is not always the top priority — a pre-product-market-fit startup may rightly prioritise growth. For security champion programmes, he emphasises long-term relationships, speaking the right language, and demonstrating value with clear metrics.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For an organization starting to incorporate Security into their systems, start right (as in securing your Production Systems) and make progress towards securing the Source Code. This helps bridge the gap between best case scenario and current state.&lt;/li&gt;&lt;li&gt;Security is not always the highest priority. Depending on the stage of the organization, Business Growth is of higher priority than Security. For example, a pre-product market fit startup.&lt;/li&gt;&lt;li&gt;Security is driven by culture of the organization. For a security champion program to work, focus on Building Long Term relationships, Communicate using the right language and show value by using the right metrics among other things.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Uncovering The Secrets Of Threat Modeling With Brook Schoenfield</title><link>https://www.scaletozero.com/episodes/uncovering-the-secrets-of-threat-modeling-with-brook-schoenfield/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/uncovering-the-secrets-of-threat-modeling-with-brook-schoenfield/</guid><description>Brook Schoenfield on the secrets of effective threat modelling, integrating threat analysis into design, and scaling the practice.</description><pubDate>Tue, 06 Jun 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Brook Schoenfield shares how to make threat modelling a practical, repeatable part of the design process rather than an academic exercise. He discusses scaling threat modelling across teams and embedding it in the development lifecycle. His guidance covers common pitfalls, proven techniques, and how to measure the value threat modelling delivers.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Threat Modeling is a continuous activity and should be part of every phase of SDLC starting from Design phase itself.&lt;/li&gt;&lt;li&gt;For Threat Modeling, start with something as simple as STRIDE framework and as the organization matures, review and utilize other frameworks as needed.&lt;/li&gt;&lt;li&gt;For resource constrained organizations, start with Open Source like Semgrep or use Community versions of Security tools to improve Code Security before investing in Wholistic &amp;amp; Expensive Tools.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Comprehending Security Culture with Ariel Shin</title><link>https://www.scaletozero.com/episodes/comprehending-security-culture-with-ariel-shin/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/comprehending-security-culture-with-ariel-shin/</guid><description>Ariel Shin on balancing production speed with security, the advisory role of security teams, and the value of empathy.</description><pubDate>Fri, 26 May 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ariel Shin argues that finding the right balance between speed and security is a shared prioritisation exercise, not a security-only concern. She sees the security team as an adviser while product and engineering own implementation, making strong cross-team relationships essential. Empathy, in her view, is a key skill that helps security teams demonstrate value to stakeholders.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Finding right balance between Production Speed and Security is all about right Prioritization. It’s a shared responsibility between Security &amp;amp; other teams.&lt;/li&gt;&lt;li&gt;Security Team is an advisor where as Product &amp;amp; Engineering owns the implementation. So, building relationship with other Teams is highly important.&lt;/li&gt;&lt;li&gt;Empathy is one of the key skills for Security Teams. It helps with showing value to stakeholders when getting budget, resources, etc.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Learning Application Security With Chris Romeo</title><link>https://www.scaletozero.com/episodes/learning-application-security-with-chriss-romea/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/learning-application-security-with-chriss-romea/</guid><description>Chris Romeo on application security beyond tools, prioritising with a data-driven approach, and starting with open source.</description><pubDate>Fri, 19 May 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Chris Romeo argues that AppSec is not just about tools — people, process, and governance are equally important. For resource-constrained organisations, he recommends starting with open-source tools targeting high- impact areas before investing in expensive products. Rather than following every OWASP guideline, a data-driven approach that targets the highest-value areas of CI/CD and supply-chain security is more effective.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security Tools does not mean AppSec. There are other factors to Security as well like People, Process and Governance.&lt;/li&gt;&lt;li&gt;For resource constrained organizations, start with Open Source to improve Security for high impact areas before investing in Wholistic &amp;amp; Expensive Tools.&lt;/li&gt;&lt;li&gt;Instead of following all the best practices like OWASP Top 10, and others follow a Data Driven approach and pick High Value sections for CI/CD Security, Supply Chain Security and other areas.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Data Loss, DevOps, and More!</title><link>https://www.scaletozero.com/episodes/data-logs-devops-and-more/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/data-logs-devops-and-more/</guid><description>Chris Hodson, CSO of Cyberhaven, on threat modelling across the SDLC, communicating security value, and DevSecOps trade-offs.</description><pubDate>Fri, 12 May 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Chris Hodson argues that threat modelling is the highest-return activity for incorporating security into the SDLC — especially when you train the whole team to spot gaps. When engaging other teams and executives, he recommends speaking their language and showing how security adds business value rather than flashing dashboards. There is no one-size-fits-all approach to DevSecOps; it always depends on industry, budget, and resources.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Threat modeling is key for incorporating security in each phase of SDLC. More importantly, training the team to look out for gaps in security and then using that for threat modeling will have the highest return for organizations.&lt;/li&gt;&lt;li&gt;When working with other teams and execs show how security can bring in value and use the language that resonates with them instead of showing off the capabilities or dashboards from different security tools.&lt;/li&gt;&lt;li&gt;No one size fits all approach when it comes to security or DevSecOps. It always depends on the industry regulations, budget, resource availability, and many more factors.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding Jupyter Notebooks with Ashwin Patil</title><link>https://www.scaletozero.com/episodes/understanding-jupyter-notebooks-with-ashwin-patil/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-jupyter-notebooks-with-ashwin-patil/</guid><description>Ashwin Patil on security applications of Jupyter notebooks, data analysis for threat detection, and interactive investigation workflows.</description><pubDate>Fri, 28 Apr 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ashwin Patil explores how Jupyter notebooks can be applied to security — from threat detection to forensic analysis and interactive investigation workflows. He discusses the benefits of combining code, visualisation, and narrative in a single document for security teams. His practical examples show how notebooks improve collaboration and reproducibility in security operations.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When it comes to threat hunting exercises, instead of focusing on the top fives of the world, focus on areas which are applicable and can be exploited in your architecture.&lt;/li&gt;&lt;li&gt;As part of your incident response plan, conduct frequent fire drill or tabletop exercises to evaluate preparedness.&lt;/li&gt;&lt;li&gt;Learning from a security incident is one of the best ways to improve threat hunting process.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding Threat Modeling with Jeevan Singh</title><link>https://www.scaletozero.com/episodes/understanding-threat-modeling-with-jeevan-singh/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-threat-modeling-with-jeevan-singh/</guid><description>Jeevan Singh on threat modelling, integrating security into the development workflow, and scaling with limited resources.</description><pubDate>Fri, 21 Apr 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jeevan Singh discusses how to embed threat modelling into development workflows without overwhelming teams. He shares practical techniques for scaling security practices when resources are limited. His advice covers prioritisation, tool selection, and building a threat-modelling culture across engineering teams.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Threat modeling is the most cost effective way to improve security, and it helps in avoiding future costs incurred, like through bug bounties or breaches or pen testing.&lt;/li&gt;&lt;li&gt;While prioritizing threat modeling areas, instead of boiling the ocean, focus on the most important assets, the critical assets, and their exploitability.&lt;/li&gt;&lt;li&gt;Security should always be a joint collaboration between the execs and the engineers. Execs need to influence and support the engineers so that they can build a strong security system.&lt;/li&gt;&lt;li&gt;Train your engineers on threat modeling and ask security questions. It helps in building a strong security foundation.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Vulnerability management deep dive with Walter Haydock</title><link>https://www.scaletozero.com/episodes/vulnerability-management-deep-dive-with-walter-haydock/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/vulnerability-management-deep-dive-with-walter-haydock/</guid><description>Walter Haydock on vulnerability management, prioritisation strategies, and building a vulnerability programme that scales.</description><pubDate>Fri, 14 Apr 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Walter Haydock argues that the Exploit Prediction Scoring System (EPSS) offers a data-driven way to prioritise vulnerabilities by the probability they will actually be exploited. He recommends documenting the process, designing playbooks for patches and updates, and defining thresholds and actions for identified vulnerabilities. There is no one-size-fits-all approach — the starting point is understanding your asset inventory and its exploitability.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Exploit prediction scoring system which is also known as EPSs is a better way to understand and prioritize vulnerabilities as it uses data driven approach to determine the likelihood or probability of a vulnerability to be exploited.&lt;/li&gt;&lt;li&gt;As part of vulnerability management programs document the process design playbooks for like patches and updates and define thresholds and actions for the identified vulnerabilities to prioritize vulnerability actions.&lt;/li&gt;&lt;li&gt;There is no one size fits all approach. Instead understand your asset inventory and its exploitability.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Into the Dark Web with Brett Johnson</title><link>https://www.scaletozero.com/episodes/into-the-dark-web-with-brett-johnson/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/into-the-dark-web-with-brett-johnson/</guid><description>Brett Johnson on the dark web, credential-stuffing attacks, MFA bypass techniques, and why humans are the weakest link.</description><pubDate>Fri, 07 Apr 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Brett Johnson warns that credential stuffing is a massive problem and that attackers have already found workarounds to MFA through techniques like evil proxy — hardware keys are his recommendation. He urges organisations to understand their exposure and cybercrime value: what an attacker gains by targeting them. Humans are the key link because they are wired to trust, making them prime targets for social engineering.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Credential Stuffing is a massive problem. Attackers have already found workarounds to MFA with techniques like Evil Proxy. Use of Hardware keys is recommended.&lt;/li&gt;&lt;li&gt;Understand your exposure and cyber crime value. Cyber crime value is what can an attacker benefit by attacking you or your organization.&lt;/li&gt;&lt;li&gt;Humans are the key link in Data Privacy issues. Because, humans are by default designed to trust and that’s what makes them target of Social Engineering or Phishing attacks. Train your team and conduct frequent table top or fire drill exercises to evaluate preparedness.&lt;/li&gt;&lt;li&gt;Culture is important. Open &amp;amp; engaging environment is a key factor in building a healthy &amp;amp; solid cyber security hygiene in an organization.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Dealing with Social Engineering Attacks with Emily Zakkak</title><link>https://www.scaletozero.com/episodes/dealing-with-social-engineering-attacks-with-emily-zakkak/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/dealing-with-social-engineering-attacks-with-emily-zakkak/</guid><description>Emily Zakkak, cybersecurity specialist at Senowit, on defending against social engineering, phishing, and MFA best practices.</description><pubDate>Fri, 24 Mar 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Emily Zakkak stresses that an incident-response plan is a must for fighting phishing and social engineering attacks. Security awareness is the responsibility of the entire organisation, not just the security team. Wherever possible, MFA should be implemented across applications and implicit trust eliminated to limit the blast radius of breaches.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Incident Response Plan is a must in order to fight phishing or social engineering attacks.&lt;/li&gt;&lt;li&gt;Security is the responsibility of the entire and not just of the security team to bring awareness. Security awareness training should be conducted with other teams in the organization.&lt;/li&gt;&lt;li&gt;Whenever possible, implement MFA across applications and avoid implicit trust across applications. This would help in avoiding large scale data breaches.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Blue Team And Digital Forensics with Karan Dwivedi</title><link>https://www.scaletozero.com/episodes/blue-team-and-digital-forensics-with-karan-dwivedi/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/blue-team-and-digital-forensics-with-karan-dwivedi/</guid><description>Karan Dwivedi on blue-team operations, partnering with red teams, and preserving forensic data accuracy.</description><pubDate>Fri, 17 Mar 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Karan Dwivedi argues that deep understanding of the threat model is essential for blue-team success. He sees red teams as partners rather than adversaries in improving defence programmes. Forensic data accuracy should never be sacrificed for speed — compromised evidence undermines the entire analysis.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Understanding the threat model in depth is very important for Blue Team to be successful.&lt;/li&gt;&lt;li&gt;Red Team should be considered as partners rather than adversaries in building and improving the threat defense program.&lt;/li&gt;&lt;li&gt;Accuracy of digital forensic data is key for analyzing and improving security difference programs. It should not be compromised in order to move fast.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Discussing GRC and Data Privacy With Alyssa Ahmann</title><link>https://www.scaletozero.com/episodes/discussing-grc-and-data-privacy-with-alyssa-ahmann/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/discussing-grc-and-data-privacy-with-alyssa-ahmann/</guid><description>Alyssa Ahmann on GRC setup, data privacy, and why documentation and training underpin successful security programmes.</description><pubDate>Fri, 10 Mar 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Alyssa Ahmann argues that the first step in building a solid security programme is understanding the scope and current setup thoroughly. Documentation and organisational training are essential for a successful GRC practice. Data privacy, in her view, has no one-size-fits-all approach — it depends on industry, geography, and regulations.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;The very first step in setting up a solid security program is to understand the scope and the current set up really well.&lt;/li&gt;&lt;li&gt;Documentation of the security process and organizational training are super important for the successful GRC setup.&lt;/li&gt;&lt;li&gt;When it comes to data privacy, there is no one size fits all approach. It always depends on various factors like industry, geography, regulations and anymore.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>AWS Security And Monitoring With Rodrigo Montoro</title><link>https://www.scaletozero.com/episodes/aws-security-and-monitoring-with-rodrigo-montoro/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/aws-security-and-monitoring-with-rodrigo-montoro/</guid><description>Rodrigo Montoro on AWS security monitoring, threat modelling for new services, and restricting high-impact IAM permissions.</description><pubDate>Mon, 06 Mar 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Rodrigo Montoro argues that cloud practitioners should threat-model every new AWS service to understand attack paths and set the right permissions. He advises restricting high-impact write permissions using IAM conditions like source-IP and VPN constraints. He also recommends disabling IMDSv1 via SCP to prevent credential theft.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Before using any new service or thinking about any new service, thinking about security for any new service cloud practitioners should do threat modeling exercise to understand the attack paths because that helps in defining the right set of permissions policies for the service.&lt;/li&gt;&lt;li&gt;Limit impact of any attacks always apply restrictions on high impact permissions like write or put permissions in the im policies and for that you can use conditional clause like conditions clause where you can restrict it to a vpn ips or your particular ips or IP certs.&lt;/li&gt;&lt;li&gt;For IMDSV one vulnerability define policies in scp to disable creation of any new EC. Two instances with imds v one enabled&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Learning Red, Blue, and Purple Team With Paul Dyer</title><link>https://www.scaletozero.com/episodes/learning-red-blue-and-purple-team-with-paul-dyer/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/learning-red-blue-and-purple-team-with-paul-dyer/</guid><description>Paul Dyer on red, blue, and purple team operations, threat-landscape awareness, and open-source security with SBOMs.</description><pubDate>Fri, 24 Feb 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Paul Dyer recommends that before investing in red or purple teaming, organisations should understand their threat landscape, security maturity, and detection capabilities. Certifications like SOC 2 or HIPAA provide a foundation, but continuous risk assessment is where lasting value lies. For open-source usage, he stresses SBOMs, regular security assessments, and evaluating alternatives when better options exist.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For organizations before investing in threat hunting or Red teaming, blue teaming or Purple teaming, understand your threat landscape, your security maturity, and have threat detection capabilities via different tooling.&lt;/li&gt;&lt;li&gt;Certifications like soc. Two hipaa, et cetera are a good foundation, but invest in continuous security risk assessment.&lt;/li&gt;&lt;li&gt;For open source usage and security of it. Invest in understanding software, bill of materials like the spawns, and perform regular security assessment and look for alternate solutions wherever necessary, wherever there are better security options available.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding Kubernetes and Governance With Jim Bugwadia</title><link>https://www.scaletozero.com/episodes/kubernetes-governance-jim-bugwadia/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/kubernetes-governance-jim-bugwadia/</guid><description>Jim Bugwadia on Kubernetes governance, workload security responsibilities, and image-signing best practices with Sigstore.</description><pubDate>Fri, 17 Feb 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jim Bugwadia explains that in managed Kubernetes, hyperscalers handle the control plane, but workload and worker-node security remain the user&apos;s responsibility. He recommends implementing resource quotas, resource limits, image signing, and CVE scanning for ingress controllers. Sigstore&apos;s keyless signature approach using manifests is worth evaluating for workload protection.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For managed kubernetes hyper scalers are sort of responsible for control plane, key value store like, etc. But when it comes to security of the workloads or worker notes, it’s the user’s responsibility.&lt;/li&gt;&lt;li&gt;In case of Kubernetes, like securing. Kubernetes best practice is to implement a few poor security policies like resource quotas, resource limits, signing of images and checking for CVS for the ingress controllers.&lt;/li&gt;&lt;li&gt;To avoid attack on workload security. One of the measure is to use image signing and Sigstore offers a keyless signature approach using the manifest. It should be taken a look at.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Prepare , Plan and Budget Organizational Security with Nader Zaveri</title><link>https://www.scaletozero.com/episodes/org-security-culture-nader-zaveri/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/org-security-culture-nader-zaveri/</guid><description>Nader Zaveri on organisational security culture, planning and budgeting for security, and incident-response preparedness.</description><pubDate>Fri, 10 Feb 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Nader Zaveri argues that incident-response preparation means defining a plan, socialising it across the organisation, and running tabletop or fire-drill exercises to test readiness. To defend against social engineering and doxing, he treats MFA as a must and recommends layering one-time-passcode or hardware- key authentication on top. Building a security-centric culture, in his view, rests on the idea that security is everyone&apos;s responsibility and that accountability is key.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For incident response. Always prepare a plan and socialize that within the organization and perform tabletop or fire drill exercises to check for the preparedness of those.&lt;/li&gt;&lt;li&gt;Avoid social engineering and doxing attacks. MFA is a must. And on top of that, use onetime passcode based or the hardware keybased authentication to improve the security even further.&lt;/li&gt;&lt;li&gt;Security is everyone’s responsibility and accountability is one of the key areas to building a security centric culture.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Data Privacy And Governance With Adam Smith</title><link>https://www.scaletozero.com/episodes/data-privacy-and-governance-with-adam-smith/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/data-privacy-and-governance-with-adam-smith/</guid><description>Adam Smith on data privacy governance, building personal-data inventories, and fostering a privacy-first culture.</description><pubDate>Fri, 03 Feb 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Adam Smith advocates for personal-data inventories and data-flow maps so teams understand how sensitive data moves through the organisation. For governance, he stresses the importance of cataloguing and building a knowledge base to improve visibility. Recognition — even simple shout-outs or pins — is an effective way to nurture a privacy-first culture.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Prepare personal data inventory data flow maps for teams to understand how data, particularly crown jewels, are being referred and used or should be used throughout the organization.&lt;/li&gt;&lt;li&gt;For data governance, cataloging is important. Build a knowledge base to improve visibility and awareness of the governance process.&lt;/li&gt;&lt;li&gt;Recognition is an important part of building a security or privacy first culture. It can be as simple as shoutouts or stickers or pins.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Kubernetes Security And Misconfigurations With Jimmy Mesta</title><link>https://www.scaletozero.com/episodes/kubernetes-security-and-misconfigurations-with-jimmy-mesta/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/kubernetes-security-and-misconfigurations-with-jimmy-mesta/</guid><description>Jimmy Mesta on Kubernetes misconfigurations, continuous security checks, and when to choose managed K8s over self-hosting.</description><pubDate>Fri, 27 Jan 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Jimmy Mesta explains that the shared-responsibility model covers the control plane but leaves workload secrets, base images, RBAC, and logging to the user. Kubernetes misconfiguration checks should be continuous, not one-time, covering manifests, CI/CD pipelines, and runtimes against CIS benchmarks or the NSA hardening guide. Self-hosting brings significant operational and security challenges, so managed offerings are preferable where possible.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;As part of the shared responsibility model, cloud providers take care of a few areas like the control plane or data HCD, key value store and stuff like that. But there are areas like your own workload secrets, base images. There is RBAC dashboard and logs, which users need to be careful about. So that is the first one.&lt;/li&gt;&lt;li&gt;Kubernetes misconfig checks should be a continuous process instead of a one time scan and done type of thing. There are many areas when it comes to misconfig like your manifest, your CI/CD pipeline, mission controls, run times, etc. So focus on coverage using the CIS benchmarks or NSA hardening guide or OWASP Top 10.&lt;/li&gt;&lt;li&gt;With self-hosting. There are many operational and security challenges that come with it. Cloud providers are good at abstracting these security aspects from a managed perspective. For the managed pieces, if possible, avoid self-hosting and use a cloud managed K8s offering.&lt;/li&gt;&lt;li&gt;For Kubernetes Security instead of just relying on open source understand Kubernetes and Kubernetes Security Security in details, follow a threat modeling based approach rather than a checklist based approach.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Network Perimeter Security With Syeed Shareef</title><link>https://www.scaletozero.com/episodes/network-perimeter-security-with-syeed-sharee/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/network-perimeter-security-with-syeed-sharee/</guid><description>Syed Shareef, Senior Security Engineer at AWS, on data perimeters, combining SCP and IAM policies, and use-case-driven security.</description><pubDate>Fri, 20 Jan 2023 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Syed Shareef explains that AWS data perimeters combine SCPs, resource policies, identity policies, and network policies to build a perimeter around data. He recommends addressing all areas — identity, network, and resource — when defining perimeter policies. Security should focus on use cases rather than the latest tools, because technology is a means to an end.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Data Perimeter provides additional security capabilities on top of current AWS offerings by combining power from SCP, Resource Policies, Identity Policies, Network Policies, etc. to build a perimeter around your data.&lt;/li&gt;&lt;li&gt;It’s recommended to focus on all the areas of Data Perimeter like Identity, Network &amp;amp; Resource while defining policies.&lt;/li&gt;&lt;li&gt;When it comes to Security focus should be on Use cases and not on the latest and greatest tools. Technology is means to an end and not an end in itself.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Focusing On Cloud Vulnerability With Ray Espinoza</title><link>https://www.scaletozero.com/episodes/focusing-on-cloud-vulnerability-with-ray-espinoza/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/focusing-on-cloud-vulnerability-with-ray-espinoza/</guid><description>Ray Espinoza on cloud vulnerability management, leading with empathy, and transparent communication during incidents.</description><pubDate>Fri, 16 Dec 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ray Espinoza argues that improving security culture starts with empathy — understanding existing processes before introducing new ones. Continuous learning and engagement are essential for better collaboration between security and other teams. During incidents like phishing or zero-day exploits, staying calm and communicating transparently is critical for all stakeholders.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;To build and improve security culture in an organization, lead with empathy. Understand current culture and processes before introducing new ones.&lt;/li&gt;&lt;li&gt;Alignment is a key factor in improving collaboration between the security team and other teams in an organization. Continuous learning and engagement is a must.&lt;/li&gt;&lt;li&gt;In case of an incident like, let’s say, phishing attack or zero-day vulnerability. It’s utmost important to be calm. Transparent communication is critical for internal and external stakeholders.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Measuring Security Debt With Garrett Smiley</title><link>https://www.scaletozero.com/episodes/measuring-security-debt-with-garrett-smiley/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/measuring-security-debt-with-garrett-smiley/</guid><description>Garrett Smiley on measuring security debt, context-driven risk prioritisation, and using KRIs over KPIs for security teams.</description><pubDate>Tue, 06 Dec 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Garrett Smiley argues that security-debt priority is always context-driven — organisations should re-evaluate risks based on liability and exploitability. Building a security culture depends on clear messaging from leadership and team motivation. He suggests replacing KPIs with KRIs (key risk indicators) as a more realistic measure of a security team&apos;s effectiveness.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Priority of security debt is always context driven. Businesses should reevaluate the risks depending on liability or exploitability of it and how it applies to the business.&lt;/li&gt;&lt;li&gt;Building a security centric culture always depends on two aspects. First is the messaging from the leadership of the execs. And the other one is how motivated the team is, how motivated the team is in general.&lt;/li&gt;&lt;li&gt;KPIs may not be the best metric to determine success of security team members. The more realistic metric could be Kri, where R stands for risk.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Mastering Organizational Security Culture with Trupti Shiralkar</title><link>https://www.scaletozero.com/episodes/mastering-organizational-security-culture-with-trupti-shiralkar/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/mastering-organizational-security-culture-with-trupti-shiralkar/</guid><description>Trupti Shiralkar on organisational security culture, joint backlog reviews for security debt, and supply-chain security standards.</description><pubDate>Fri, 18 Nov 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Trupti Shiralkar recommends building security awareness through focused sessions like brown bags or lunch-and-learns on topics such as XSS or cryptojacking. For managing security debt, she advocates joint backlog reviews between engineering and security rather than separate discussions. Supply-chain security requires defining standards for open-source components and tooling to evaluate them.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;To build a security centric culture, first educate other teams about security roadmap &amp;amp; improve security awareness. It can be as simple as Brown Bags or Lunch &amp;amp; Learns focused on specific Security Areas like XSS or Cryptojacking.&lt;/li&gt;&lt;li&gt;In order to prioritize &amp;amp; address security debt, have a combined Backlog Review discussion between Engineering &amp;amp; Security teams. Instead of separate discussions.&lt;/li&gt;&lt;li&gt;To work with today’s Supply Chain Security challenges, define &amp;amp; follow standards for Open Source components &amp;amp; have tooling in place to evaluate these components.&lt;/li&gt;&lt;li&gt;For Risk Management, focus on Thread Modeling &amp;amp; Threat Agents for quantification &amp;amp; prioritization of Security Risks.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Setting the Line of Defence  in Cloud Security with Charles Mendoza</title><link>https://www.scaletozero.com/episodes/setting-the-line-of-defence-in-cloud-security-with-charles-mendoza/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/setting-the-line-of-defence-in-cloud-security-with-charles-mendoza/</guid><description>Charles Mendoza on setting the line of defence in cloud security, layered controls, and incident-response readiness.</description><pubDate>Fri, 04 Nov 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Charles Mendoza argues for a layered approach to cloud defence, combining preventive, detective, and corrective controls. He discusses how to set clear lines of defence that match the organisation&apos;s risk appetite. Incident-response readiness — knowing who does what before an event occurs — is a recurring theme in his advice.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Measure your current risk posture using existing tools. This helps in justification of the spend and budget planning.&lt;/li&gt;&lt;li&gt;Data privacy is a shared responsibility across all members in the organization. It’s not a tools problem.&lt;/li&gt;&lt;li&gt;MFA should be set up for all the apps and services as a first line of defense. It’s the basic security that we should all adhere to.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Security debt and prioritizing risks with Aakash Yadav</title><link>https://www.scaletozero.com/episodes/security-debt-and-prioritizing-risks-with-aakash-yadav/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/security-debt-and-prioritizing-risks-with-aakash-yadav/</guid><description>Aakash Yadav on security debt, risk prioritisation, and building a pragmatic approach to reducing organisational risk.</description><pubDate>Fri, 21 Oct 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Aakash Yadav argues that security debt must be prioritised alongside other engineering work, using risk impact and exploitability as the primary drivers. He advocates a pragmatic approach: fix what matters most first and build a continuous process for reducing risk over time. Communication with stakeholders about what is being deferred and why is essential.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security program should be risk driven rather than compliance driven. So risk assessment is the key for designing a good security program.&lt;/li&gt;&lt;li&gt;Continued reevaluation of the risks in your risk matrix is the key to prioritization. It also helps in addressing security depth.&lt;/li&gt;&lt;li&gt;Prior to using any open source software, do a security review in terms of support from the contributors. How big is the community release frequency and how engaged is the community for that open source software?&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Understanding Information Security and Risk Management With Parul Khanna</title><link>https://www.scaletozero.com/episodes/understanding-information-security-and-risk-management-with-parul-khanna/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-information-security-and-risk-management-with-parul-khanna/</guid><description>Parul Khanna on information security, risk management, and bridging the gap between incident response and business priorities.</description><pubDate>Fri, 07 Oct 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Parul Khanna draws on her background in incident response, cybersecurity investigations, and software engineering to discuss practical risk management. She argues that bridging the gap between security operations and business priorities requires clear communication and stakeholder alignment. Her advice covers programme design, certification strategy, and building resilience.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For risk management, have security baked in early in your SDLC process. This helps in your security debt prioritization as well.&lt;/li&gt;&lt;li&gt;Follow the Information Security triad, which is also known as CIA Triad. The confidentiality, integrity and availability. For Data Protection and Cyber security, apply the NIST framework for identification, detection and analysis of your critical assets.&lt;/li&gt;&lt;li&gt;To avoid phishing, social engineering or even doxing attacks. Follow the basics of security properly, like use of a multifactor authentication or use of strong passwords and use VPN at minimum.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Big Mistakes in Cybersecurity With Mel Reyes</title><link>https://www.scaletozero.com/episodes/big-mistakes-in-cybersecurity-with-mel-reyes/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/big-mistakes-in-cybersecurity-with-mel-reyes/</guid><description>Mel Reyes on the biggest mistakes in cybersecurity, top-down security mandates, and setting up foundations for startups.</description><pubDate>Fri, 30 Sep 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Mel Reyes argues that security should be mandated top-down but implemented in partnership with the individual contributors who own the systems. He advises starting small with frameworks like NIST or CIS, understanding risk tolerance, and performing gap analysis along the way. For startups, he recommends working with advisory boards or VC security groups if dedicated hiring is not yet feasible.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security should be mandated from top down and it should be implemented in partnership with individual contributors or the doors, right? Who own the implementation.&lt;/li&gt;&lt;li&gt;From a security standpoint, start small with frameworks like Nest, CIS, sock one and understand your risk tolerance. Do the gap analysis during the process as well.&lt;/li&gt;&lt;li&gt;For startups. Start early if hiring insecurity is a challenge, working with partners or VCs groups or security like advisory boards or cloud advisory groups to set up a solid foundation.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Part 2 - Zero Trust Architecture With Vincent Romney</title><link>https://www.scaletozero.com/episodes/zero-trust-architecture-vincent-romney/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/zero-trust-architecture-vincent-romney/</guid><description>Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture and overcoming organisational resistance.</description><pubDate>Fri, 23 Sep 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Vincent Romney recommends understanding your current architecture first and then introducing zero trust layer by layer, following the NIST 800-207 guidelines closely. He frames security debt as tech debt for security and stresses clear communication with leadership to balance business growth against risk reduction. When working with executives, he tailors the message and adds context to make the risk and infrastructure challenges concrete.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;To implement Zero Trust as part of the security program, understand the current Architecture first and then introduce Zero Trust in each layer one by one. Follow the NIST 800-207 guidelines closely.&lt;/li&gt;&lt;li&gt;Security debt is nothing but Tech Debt for Security. Have clear communication with Leadership team to find a balance between business growth and reducing the risk.&lt;/li&gt;&lt;li&gt;When working with Executives, tailor the message &amp;amp; add context to show the Risk and challenges in the security infrastructure.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Zero Trust Architecture With Vincent Romney</title><link>https://www.scaletozero.com/episodes/zero-trust-architecture-with-vincent-romney/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/zero-trust-architecture-with-vincent-romney/</guid><description>Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture, programme design, and security planning.</description><pubDate>Thu, 15 Sep 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Vincent Romney argues that the CIS Benchmarks 1 and 2 are the most important starting point for zero trust, beginning with drawing and understanding the inventory architecture. Identity is a core component that feeds into zero trust — he recommends defining and enforcing policies to extend zero trust across the infrastructure. MFA is a must, and he favours hardware-based options like YubiKey as the strongest choice.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;For Zero Trust CIS 1 &amp;amp; 2 Benchmarks are the most important. To start, Draw &amp;amp; Understand the Inventory architecture.&lt;/li&gt;&lt;li&gt;Identity is one of the core components of Zero Trust and it feeds into Zero Trust. Define the Policies and enforce the policies to incorporate zero trust through out the infra.&lt;/li&gt;&lt;li&gt;MFA is a must in today’s world. Hardware Device based MFAs like YubiKey are the best options.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Preparing For Potential Cloud Data Breaches With Nat Shere</title><link>https://www.scaletozero.com/episodes/cloud-security-data-breaches-with-nat-shere/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/cloud-security-data-breaches-with-nat-shere/</guid><description>Nat Shere on preparing for cloud data breaches, incident response planning, and lowering MTTD and MTTR.</description><pubDate>Fri, 02 Sep 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Nat Shere argues that breach preparation must cover both business risk and financial impact, backed by an incident response plan and frequent simulations. When communicating security needs to executives, he recommends tailored messaging that resonates with each audience. The two metrics every security team should track are mean time to detect and mean time to recover.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When it comes to Preparation for data breaches or ransomware attacks, focus on both Business Risk &amp;amp; Financial Impact. Have an Incident Response Plan &amp;amp; Perform frequent simulations with all the stakeholders to check your preparedness.&lt;/li&gt;&lt;li&gt;When working with other Teams &amp;amp; Executives, use Tailored Messaging to educate &amp;amp; bring consensus on the Security needs for the organization.&lt;/li&gt;&lt;li&gt;There are 2 Key metrics which every security team should follow. First, keep lower MTTD (Mean time to Detect) and lower MTTR (Mean time to Recovery).&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Cloud Security Planning With An Ethical Hacker Aseem Shrey</title><link>https://www.scaletozero.com/episodes/cloud-security-simplified-with-aseem-shrey/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/cloud-security-simplified-with-aseem-shrey/</guid><description>Aseem Shrey, security engineer at Rippling, on responding to ethical hacker reports, preparing for data breaches, and building a security career.</description><pubDate>Wed, 24 Aug 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Aseem Shrey argues that organizations should acknowledge and build trust with ethical hackers who report findings, rather than ignoring them. He advises security leaders to use data-driven metrics and clear objectives when budgeting for breach preparedness. For those starting in security, he recommends getting hands-on experience across multiple areas before specializing.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;When a hacker reports a finding. We sometimes ignore it. It’s not wise to do so. Instead, Acknowledge and work with the Hackers to improve your Security Posture.&lt;/li&gt;&lt;li&gt;In order to prepare an organization for potential data breaches or attacks, use a Data Driven approach and define clear Objectives.&lt;/li&gt;&lt;li&gt;When starting your career in Security, always start small and get your hands dirty in various areas of Security. This will help you in finding the right path for your career.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Solutions To Roadblocks In Cloud Security With Chris Neggel</title><link>https://www.scaletozero.com/episodes/roadblocks-in-cloud-security-with-chris-neggel/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/roadblocks-in-cloud-security-with-chris-neggel/</guid><description>Chris Neggel, Regional CSO at Okta, on the roadblocks teams face in cloud security and strategies to overcome them.</description><pubDate>Mon, 08 Aug 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Chris Neggel draws on his experience at Okta and LinkedIn to identify the most common roadblocks in cloud security — from misaligned incentives to organisational silos. He shares practical strategies for overcoming these barriers, including building customer trust, thought leadership, and cross- functional collaboration.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Security is not just a checkbox. Certifications should be used as a measurement tool rather than a goal. Continuous security improvement has much more impact than just getting certifications like SOC2, ISO, HIPAA, etc.&lt;/li&gt;&lt;li&gt;In order to setup IAM in the most accurate way, understanding Who needs access to What, When and Why are the most important factors. IT should enable teams to own IAM rather than becoming the roadblock. For a quick win, enforce MFA at minimum.&lt;/li&gt;&lt;li&gt;In terms of data breaches or attacks, every incident is different. So, focus more on defining a solid Incident Response Program and Organization chain of command rather than specific tactics.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Cloud Security Reviewed With Ski</title><link>https://www.scaletozero.com/episodes/cloud-security-reviewed-with-ski/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/cloud-security-reviewed-with-ski/</guid><description>Ski on building a security-centric culture, improving cross-team relationships, and aligning certifications with controls.</description><pubDate>Fri, 29 Jul 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Ski argues that transparency, executive support, and regular training are the pillars of a security-centric culture. To improve working relationships with other teams, security should engage early and define a go-to-market security strategy collaboratively. Certifications become easier when the underlying controls and baselines are already properly set and monitored.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;To build a security centric culture, Transparency with teams, getting Executive Support and Investing in Regular Training are utmost important.&lt;/li&gt;&lt;li&gt;In order to improve working relationships with other teams, Security Teams should Start interacting early in the journey and define Go To Market Security Strategy along with the teams.&lt;/li&gt;&lt;li&gt;Regarding Certifications, always start with security controls. Set the proper controls, baselines and have frequent monitoring in place. Align it with the Vision of the organization. Certification would be easier if controls are defined properly.&lt;/li&gt;&lt;/ul&gt;</content:encoded></item><item><title>Best Approach To Cloud Security With Gary Dylina</title><link>https://www.scaletozero.com/episodes/best-approach-to-cloud-security-with-garry-dylina/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/best-approach-to-cloud-security-with-garry-dylina/</guid><description>Gary Dylina of Narvar on preparing for large-scale events, SOC2, IAM setup, and when to make a first security hire.</description><pubDate>Fri, 24 Jun 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Gary Dylina advises security teams to provision for expected load with safety margin, scan for vulnerabilities, and run penetration tests before large-scale events. He explains that SOC2 and ISO certifications build customer trust, but some customers will want deeper proof of your security posture. On IAM, he recommends SSO, MFA, and role-based access controls with periodic reviews, and suggests the right time for a first security hire depends on the existing team&apos;s capabilities. Gary Dylina advises security teams to provision for expected load with safety margin, scan for vulnerabilities, and run penetration tests before large-scale events. He explains that SOC2 and ISO certifications build customer trust, but some customers will want deeper proof of your security posture. On IAM, he recommends SSO, MFA, and role-based access controls with periodic reviews, and suggests the right time for a first security hire depends on the existing team&apos;s capabilities.&lt;/p&gt;</content:encoded></item><item><title>Bizzare Cloud Security Facts With Gaurav Batra</title><link>https://www.scaletozero.com/episodes/bizzare-cloud-security-facts-with-gaurav-batra-2/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/bizzare-cloud-security-facts-with-gaurav-batra-2/</guid><description>Gaurav Batra, founder and CEO of CyberFrat, on surprising cloud security facts and building security awareness culture.</description><pubDate>Fri, 24 Jun 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Gaurav Batra shares lesser-known cloud security insights and discusses what organisations get wrong when securing their cloud environments. He emphasises the importance of cross-training and building a security-centric mindset across teams, drawing on his experience at Mondelez International and as founder of CyberFrat.&lt;/p&gt;</content:encoded></item><item><title>Cloud Security Made Simple With Swati Anuj Arya</title><link>https://www.scaletozero.com/episodes/cloud-security-made-simple-with-swati-anuj-arya-2/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/cloud-security-made-simple-with-swati-anuj-arya-2/</guid><description>Swati Anuj Arya, CISO Office leader at Amazon Pay, on simplifying cloud security and responding to data breaches.</description><pubDate>Fri, 24 Jun 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Swati Anuj Arya explains that in a confirmed data breach the first step is identifying whether regulated data was impacted and who must be notified within the legal timeline. Containment is critical — the breach should not ripple into other systems. A thorough root-cause analysis drives both short- term and long-term fixes and satisfies regulators.&lt;/p&gt;</content:encoded></item><item><title>Understanding Cyber Security With Aseem Rastogi</title><link>https://www.scaletozero.com/episodes/understanding-cyber-security-with-aseem-rastogi/</link><guid isPermaLink="true">https://www.scaletozero.com/episodes/understanding-cyber-security-with-aseem-rastogi/</guid><description>Aseem Rastogi, Head of Cybersecurity and Compliance at Meesho, on building cybersecurity and compliance programmes from the ground up.</description><pubDate>Fri, 17 Jun 2022 00:00:00 GMT</pubDate><content:encoded>&lt;p&gt;Aseem Rastogi shares his experience leading cybersecurity and compliance at both Razorpay and Meesho. He discusses the challenges of building a programme from scratch, earning stakeholder trust, and creating a culture where security is everyone&apos;s responsibility. His practical advice covers prioritisation, tooling, and aligning security with fast-moving product teams.&lt;/p&gt;</content:encoded></item></channel></rss>