Skip to content
Scale To Zero by Cloudanix

Topic

Cloud Security

Securing AWS, Azure and GCP estates at scale: posture, architecture, guardrails and the operating model that keeps cloud risk in check.

66 episodes · 6 questions answered

Cloud Security: questions answered

How do you stop treating compliance as a checklist?

Advait says treating compliance as a document checklist no longer works. Patching, visibility, logs and tracking who accessed or changed what need to be in place from day one, not added after something is found. With controls, guardrails and visibility from the start, you are not scrambling when auditors arrive, and engineers feel confident in the product and in passing any security or compliance review.

Advait Patel · Broadcom

How should just-in-time access change IAM in 2026?

Manual access requests — file a ticket, wait for IT security and manager approval — can take a day or several, frustrate developers and slow development. Advait says that has to go: developers should request just-in-time access that is checked against predefined controls and granted in seconds or minutes. Security is not locking everything; it is locking what needs to be locked and granting what needs to be granted.

Advait Patel · Broadcom

What KPIs should security leaders track once AI is part of security operations?

Advait says traditional KPIs — mean time to react, detect and resolve — are not wrong but are no longer enough. He adds signal quality (is AI improving existing workflows), engineer efficiency (is a problem fixed faster than before), decision quality (does AI recommend well enough that you are not deciding every low-risk task) and automation safety (how often AI-driven automations are correct).

Advait Patel · Broadcom

What IAM anti-patterns should organizations avoid?

What works for 100 engineers will not work for 10,000, so IAM has to fit your company. The anti-pattern Advait calls out is starting from the top — granting admin or power-user access and removing what goes unused after 30 days. Instead, start from zero trust and minimal permissions, assign roles by team (a database team needs services like DynamoDB or Cloud SQL, not VMs), and add permissions as needed.

Advait Patel · Broadcom

How can SREs use AI agents for root cause analysis?

Agents can track changes, collect logs, find patterns in production alerts, trace the root cause, check whether an incident has happened before, and write incident runbooks. But agents cost you visibility, so you need to know what they are doing and what they are capable of. Advait starts with low-risk tasks rather than handing an agent a production API key with no human intervention.

Advait Patel · Broadcom

Will AI agents become fully autonomous in production?

Advait sees the industry heading toward autonomous agents, but says you should never fully trust anything, especially AI, with a production system that touches customers and your company's reputation. Use autonomous AI for low-risk tasks where you are fine without visibility and confident in the results; if you are even 0.01% in doubt, he doubts people will use it in production.

Advait Patel · Broadcom

Episodes

Into the Dark Web with Brett Johnson

Brett Johnson on the dark web, credential-stuffing attacks, MFA bypass techniques, and why humans are the weakest link.

Brett Johnson

Zero Trust Architecture With Vincent Romney

Vincent Romney, Head of Global Security Architecture at Nu Skin, on zero-trust architecture, programme design, and security planning.

Vincent Romney · Nu Skin Enterprises

Cloud Security Reviewed With Ski

Ski on building a security-centric culture, improving cross-team relationships, and aligning certifications with controls.

Ski

New episodes twice a month

No security question left unanswered.

Follow Scale To Zero wherever you listen, or send us the question your team is stuck on and we will put it to an expert.