AWS SECURITY IN A LARGE REGULATED ENTERPRISE! - HOUSTON HOPKINS, CAPITAL ONE

AWS SECURITY IN A LARGE REGULATED ENTERPRISE! - HOUSTON HOPKINS, CAPITAL ONE

In this episode of the Virtual Coffee with Ashish edition, we spoke with Houston Hopkins, Director CyberSecurity, Capital One

In this episode, Houston & Ashish spoke about

  • What was your path into CyberSecurity?
  • How Capital one pioneered as bank moving into AWS Cloud?
  • What immediate security challenges does Cloud Security in a Hybrid world look like, without going into tools.
  • Do you prefer to use AWS native tools for security observability or a vendor product?
  • What are some of the Security challenges to solve when looking at a large cloud landscape? (threat detection at scale, continuous compliance etc)
  • Is accountability a challenge for Cloud at Scale?
  • Does this change quite a bit for security in one cloud compared to another? (resources that know multiple cloud etc)
  • Which approach do you recommend - Standardizing security vs Operationalize and Manage with more staff for effective security across multi-cloud environments?
  • Immediate challenges around multi-cloud - Maintaining visibility of assets and secure configurations in a large multi-cloud environment
  • What does detection and prevention look like in a cloud landscape?
  • How do you keep track of all the AWS services?
  • What security controls across compute heavy vs serverless vs containers in a multi-cloud world
  • How do you get visibility in the current poly-cloud or multi-cloud world?

ShowNotes and Episode Transcript on www.cloudsecuritypodcast.tv

Twitter - @kaizenteq @hashishrajan

If you want to watch videos of this and previous episodes:

- Twitch Channel: https://lnkd.in/gxhFrqw

- Youtube Channel: https://lnkd.in/gUHqSai

Jaksot(343)

Browser Security Explained: Consent Phishing, "Click Fix" Attacks & The Limits of EDR

Browser Security Explained: Consent Phishing, "Click Fix" Attacks & The Limits of EDR

Is your security team treating your Identity Provider (IDP) like a firewall? In this episode, Adam Bateman (CEO & Co-founder of Push Security) explains why that's a dangerous mistake and how modern at...

10 Maalis 46min

Is AI Hallucinations a Myth and the Real Threat from AI

Is AI Hallucinations a Myth and the Real Threat from AI

Are attackers really using AI to run end-to-end cyber campaigns? In this episode, Edward Wu (Founder and CEO, DropzoneAI) joins Ashish to separate the hype from reality when it comes to AI-driven atta...

6 Maalis 40min

Why AI Infrastructure is Harder to Secure Than Cloud

Why AI Infrastructure is Harder to Secure Than Cloud

Is AI security just "Cloud Security 2.0"? Toni De La Fuente, creator of the open-source tool Prowler, joins Ashish to explain why securing AI workloads requires a fundamentally different approach than...

20 Helmi 34min

How Attackers Bypass AI Guardrails with Natural Language

How Attackers Bypass AI Guardrails with Natural Language

In the world of Generative AI, natural language has become the new executable. Attackers no longer need complex code to breach your systems, sometimes, asking for a "poem" is enough to steal your pass...

10 Helmi 46min

Vulnerability Management vs. Exposure Management

Vulnerability Management vs. Exposure Management

In this episode, Brad Hibbert (COO & Chief Strategy Officer at Brinqa) joins Ashish to explain why traditional risk-based vulnerability management (RBVM) is no longer enough in a cloud-first world .We...

6 Helmi 39min

Is Developer Friendly AI Security Possible with MCP & Shadow AI

Is Developer Friendly AI Security Possible with MCP & Shadow AI

Is "developer-friendly" AI security actually possible? In this episode, Bryan Woolgar-O'Neil (CTO & Co-founder of Harmonic Security) joins Ashish to dismantle the traditional "block everything" approa...

5 Helmi 1h 3min

Why AI Can't Replace Detection Engineers: Build vs. Buy & The Future of SOC

Why AI Can't Replace Detection Engineers: Build vs. Buy & The Future of SOC

Is the AI SOC a reality, or just vendor hype? In this episode, Antoinette Stevens (Principal Security Engineer at Ramp) joins Ashish to dissect the true state of AI in detection engineering.Antoinette...

21 Tammi 52min

AI Vulnerability Management: Why You Can't Patch a Neural Network

AI Vulnerability Management: Why You Can't Patch a Neural Network

Traditional vulnerability management is simple: find the flaw, patch it, and verify the fix. But what happens when the "asset" is a neural network that has learned something ethically wrong? In this e...

13 Tammi 41min