mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Cloud security with an Angel
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode we chat with Angel Alonso, a CISO for hire and team lead for the Governance, Risk and Compliance department in mnemonic.
He shares his experience and opinions around the topic of "cloud security," and provides insight into what organizations should be doing to avoid the front pages due to a misconfiguration.
Technical level: 1/5
Host: Robby Peralta
Producer: Paul Jæger
From our headquarters in Oslo, Norway.
Speaker 1Welcome to the mnemonic Security Podcast.
Robby PeraltaToday I have the honor of speaking with Angel Alonso, who is a board member for the Cloud Security Alliance in Norway. He's a chief information security officer for Hire, and he has not one, not two, but three master's degrees within the field of cybersecurity. So today we're going to be talking about cloud security. So sit back and enjoy. So Mr. Alonso, welcome to the podcast.
Angel AlonsoThank you. Thank you so much.
Robby PeraltaIt's great to have you. So in the introduction, I tried to name some of your accreditations, but uh and I looked at your certification list, but I sort of figured that 20 certifications would be take too much time in introduction to name. So tell us a bit tell us a bit about yourself.
Angel AlonsoAbout myself. Thank you for the nice introduction. It was very nice.
Robby PeraltaWhat brought you into security?
Angel AlonsoWhen I started my studies in Spain, I started computer engineering because there was not a proper studies about computer security at that time. But I was very clear that it was a very interesting field. Maybe I was a little bit probably too much conditionated by the TV because at the time it was like the movies hackers and this kind of movies that the hacker was a very cool person in the movies and things like that. So it started to increase this interest about that one. But when when I started to study computer engineering, I started to get into the technology, I actually get very interested in technology. And of course, by that time, still it was very early. It was very naturally because I was always very curious about technology. So when you're curious about technology, security is something that came pretty natural to it.
Robby PeraltaAnd so fast forward today, you're the uh the leader of the governance, risk, and compliance division in mnemonic. Um I called you a CISO for hire in the introduction. Uh topic of today is uh cloud cloud security in general. And uh we're very I want to say we're lucky, but the citizens of Ecuador are not very lucky. As uh I'm sure you've heard, I think it was on Friday or something last week. Uh all of their data has been exposed. I'm not sure if it means it's been leaked or anything. Uh but that that's what I kind of want to talk about with you today is why does this keep happening?
Angel AlonsoBecause cloud is something that goes so fast. So technology goes fast generally, but cloud is incredible. If you look at Amazon, Amazon, I'm not going to uh I'm not going to say that Amazon is the best in cloud, so I'm not going to be a vendor.
Robby PeraltaThey are the biggest also.
Angel AlonsoThey're the biggest. And they have been the first. So they are that's true, that's a fact that they were the first one to started the cloud uh with uh S3 and uh EC2. So it was the worst that started this this uh way of computing. There has been so incredible bunch of features that they put in the cloud. If you look into the features that they they used when they started to what they have now, it's an exponential growth there. So this is incredible, it's almost impossible to follow up all the features and all the cool stuff they have. It's almost impossible. So of course, people is getting is having a hard time getting back. And security is one of the things they're suffering for that.
Robby PeraltaBecause they're maybe not thinking too much before they you know put stuff in the cloud.
Angel AlonsoThat's one reason, of course, but the other one is because maybe they don't have the enough competence neither. So it's like they don't understand the technology well to know what could happen in this in these scenarios, uh like you mentioned before. They are more typical. So this has happened several times. An S3 bucket publicly available in the internet, and everyone can read it. Happened a lot of times, is because people have misconfigured, not intentionally, probably, just a misconfiguration, either because they don't understand it or because they don't have the the knock knowledge or just an unintentional failure.
Robby PeraltaSo you just mentioned S3, which uh, if I'm correct, that's like a database that's hosted in the cloud. Storage, yeah kind of stuff. What are companies uh putting what sort of like information are they putting in the cloud in these S3 buckets? Could be anywhere. Is it just uh what's like the rule of thumb? Is it just like okay, if it's a bunch of data, it's just easier to store it in the cloud? We'll just put it in an S3 bucket.
Angel AlonsoJust think about like a storage place. So if if I need to have some file or something, some information, I will put it there because it's one of the typical deliveries that you get from Amazon. But um Azure has its own and uh Google Cloud has its own. So it's just it's just on a storage place. And of course, it's like if you have your computer here and you have your network, if you put your your hard disk openly exposed to internet, of course, everyone or someone will try to look at it.
Robby PeraltaI just realized I've been putting a lot of documents on my uh on my on my PC that's actually uh available for other people in mnemonic to look at. But I guess it's the same way. You don't know if you're not you put things somewhere and you're not sure who else has access to it. And again, that that's pretty much what's going on in the cloud, right?
Angel AlonsoYeah, because uh it's very easy to make that mistake that open that specific bucket to everyone. It's just a configuration because cloud. Cloud is a one of the beauties of cloud is that you can program everything. You create infrastructure as a code, you do everything by code, and just make a small mistake or just write zero zero zero zero instead of a specific uh range that you put it open to internet. It's so easy like that.
Robby PeraltaSo um you've worked on a lot of projects within this sort of uh I want to say uh risk assessments of putting stuff in the cloud. Um tell us uh some of the lessons you've learned from those risk uh assessments. What are what are the uh what are the what are the customers, your customers thinking about before they do that?
Angel AlonsoThere is very different uh maturity levels there. We have uh seen we have seen from people that just put everything we have thinking about and just think afterwards, okay, have we done something wrong, or people that actually has a proper a proper process where before you put something in the cloud, you make a proper risk assessment, what things could go wrong, and if you find something that should go could go wrong, and you maybe need to put something to prevent it or to mitigate it at least. So I've seen the process in both ways. Obviously, the second the second part is the the the one we like it when you do the first risk assessment and you you decide which measures with controls are you going to put in place before you go out.
Robby PeraltaBut those risk assessments, like uh explain to us, like is that like some is that like an Excel tool you guys use, or you just sit in a room and just say, okay, everybody brainstorm what's the worst thing can happen, or like how do how you know how's that process go?
Angel AlonsoIt's a combination of different things. You have interviews, you have to first understand the business that we are talking, what what is the situation of the customer? Um if the customer is very mature, they always or they will probably have their own uh risk management uh process uh on the top, so we can just connect and use the same probability, uh consequence and so on. Otherwise, sometimes we need to do it uh in our own. Um you have interviews, you try to get a risk assessment at the end is that you try to get as much data as you can, as much information, and put it in a way that people understand it and they can take a good decision. So the risk management is just taking good decisions, have the best data to take a good decision. So the met the more data we can manage to gather, we manage to analyze, we put it in a way that we are not the ones who say this is a risk that you cannot accept or not. It's the customer who has to decide that one. So our job when we get risk assessment is to give you the best information we can so you can make the right decision.
Robby PeraltaAnd that sounds like a process where you should be involving the business itself and not just the security or the IT team. You should actually be talking with the people that are, you know, whatever the business does, you should be talking to the people that are running those lines of the business, correct?
Angel AlonsoAbsolutely correct. That's one of the things that we say, and that's actually it's good because it's something that is changing now. So historically, security was IT responsibility. Now, of course, so much media attention, news every day, uh CEO gets fired because of uh some breach. Or so these things is getting attention, it's getting go up to the C level, it's getting up to the to the board level. So people are starting to realize that this is not something that IT can own. It's not IT who owns the risk. It's the business who owns that risk. When we help a customer, when we help someone and making a risk assessment, even if we need the input from the IT people, the security people, because we need to understand which controls they have in place, which technology they use, there is it shouldn't be their responsibility. They shouldn't owner, they shouldn't be the owner of the risk. It should be that business people, the ones who has the the business, the ones who has to make something with this, who actually say this is okay or not. Because a company, I mean, a company they live because they need to take risk. They are there to make money or to make some another kind of uh benefit for the company. You have to manage the risk. You cannot be risk avoidance at all. You have you have to you have to take risks.
Robby PeraltaYeah, there's a great quote by uh Roar Thon , who is the um Yeah, he works for the National Security Authority in Norway, and he said, uh there's no there's no company in the world that's been established with the intent of being secure. Because then you don't have any customers, you don't have any employees, you don't have any infrastructure whatsoever, you don't do anything, and then you're secure because there's no risk.
Angel AlonsoYeah, there's no risk, but that's that's the reason is it's the business who has to decide what is acceptable for them or not. That's how security should work, not just put it in IT. That has been the trend that fortunately that's changing now. That's very good to in the security market to see that that's that's an evolution there.
Robby PeraltaSo uh if you've had to share some advice on some of the projects you've been a part of, uh some tips and tricks, or maybe help whoever's listening to cut some corners. What would be some of those uh tips you come with in regards to the cloud and security?
Angel AlonsoI guess the most important is uh people, man. Of course, always we talk about process, people and technology. Process and people in this case, I think is very important. Garner, for example, and many others, they predictions 2022-2020. Most of the ch fails in cloud security it will be because of a because of a misconfiguration. Because not because the cloud provider, not because the cloud provider make a fail or lose your data. No, no, it will be your data. It will be your fault because something that you have done wrong.
Robby PeraltaBut it must be really hard. I mean, like uh shouldn't there just be a button that says make this private or make this public? Like why aren't people pressing the that button?
Angel AlonsoMaybe you should be able to like that one.
Robby PeraltaA bigger button, maybe.
Angel AlonsoBut that's and and that's also something that the security people working in cloud could actually help with. Because one of the also the beauties of the cloud is that you come we talked before, infrastructure as a code. Everything will be code. You create a server just as some lines of code. In the same way you can create some lines of code that make security. That's what, for example, Amazon and others call it guardrails. So you give them some guardrails where people can move. So you say make it private, maybe public. So that's something that the security community can build or the security expert can build into the code automatically because one of the benefits of cloud is this automation orchestration also.
Robby PeraltaSo if you're gonna look into your crystal ball uh regarding cloud security, what's gonna be happening in the next couple years?
Angel AlonsoI won't answer that question. I I don't like predictions. I cannot predict, I don't think I will I will I will be able to make a prediction. What I would like to tell you is what I think it won't change. Because this progress that we see in cloud is still continues and continues and continues. So this need for knowledge, this need for to increase the competence of the people, but not only the security people, everyone. Everyone involved in cloud because cloud is the new reality. So before it was data centers, everything, but now everyone has a relation with the cloud, everyone in a company has a direct relation with the cloud. We need to increase that competence. We need to make all the people interacting with the cloud a little bit more knowledgeable about what is cloud and which things are okay, which things are not okay. And that's one of the things we do in uh cloud security alliance. In the Nobel Charter of Cloud Security Alliance, one of the goals that we have is actually help to help the people to increase this uh this knowledge. And in many different ways for security people, of course, you have courses and trainings, but we also are creating or adapting this uh cloud security control matrix that has some controls to be used maybe in the public sector. So everyone has the same understanding, everyone talks about the same things and not it won't be completely different uh levels of knowledge. Depends where you are.
Robby PeraltaSo yeah, you you are a board member of the Cloud Security Alliance in Norway. Uh and I've been following that for I think you spend it in Norway for what, three or four years now. What is uh how has the maturity growth been?
Angel AlonsoI'm not sure we can say the maturity of the Norwegian market has been higher, but absolutely that tension in the Norwegian market has been higher. So people is much more interested in hear, okay, there is something we can use already. We don't need to reinvent the wheel. There is people who has already look into cloud and look into what is the problems there, what are the risks. So there is interest in people. They want to know, they want to understand, they are they know the city is a problem.
Robby PeraltaBut is do you think that in that sort of interest is coming from what they're you know reading about in the newspapers that company X is being hacked and company Y? Because that's been there for that's been in the news for so long, and it's uh I mean it's wasn't last year that the first S3 bucket got compromised, it was like whenever S3 bucket came along. So what what do you think is driving that awareness and that interest?
Angel AlonsoI guess because there is more companies that already are in the cloud. So this uh the business has decided we go to cloud. There is benefits. So forced to force to learn about it, yeah. So some people have just to go with it. So let's try to make this one in the most secure way. Because there is, I mean, there is a lot of benefits to go to cloud. So you have the flexibility, you have the elasticity. So if you are a retail, if you are a retail company, why do you need to buy so many servers when you can just go for a cloud service and the scale when you need it? It's Christmas, very good. I put many servers, as much servers as I need. There is uh uh vacation time, maybe there is also a peak, or maybe it's very low sales. I don't need to pay for resources I don't use. I understand that from a business perspective is really good. But actually, I would like also to challenge there because many people have said we don't go to cloud because of security issues. And could be the case. That's a new one, yeah. That could be the case. But actually, I would like to see the cloud as an opportunity, not the opposite. One thing I have to say about thinking about cloud security is think about responsibilities. One of the most important things is this concept of responsibility matrix or responsibility. The cloud provider, Amazon, Microsoft, Google, they are responsible for the security of the cloud. That means the data centers, the physical servers, even if you go up in the stack, if you have infrastructure as a service, they have that, but you have uh they could also get up to the uh virtualization layer, the application layer, and so on.
Robby PeraltaBut basically making sure that somebody doesn't walk in with the USB and plug it in. That's what they're responsible for, right?
Angel AlonsoThat's in all the level in all the models, but of course, if you go, if you go, for example, for the basic model is infrastructure as a service. That is they get more, let's say the physical part. But you also have uh you also have platform as a service where they get also the operating system. So they are responsible to patch the operating system of these virtual systems. Also, you go to application as a service, they have also responsibility to patch the application they're running there. And also now, if we move to serverless, there is even less, so they get all the stack. But that concept of responsibility. So the cloud providers they are really good in the security responsibility they have. They have much more resources than the normal company to have a good data center, good security guard. So many people working on this patching systems. They they have resources, they can put people, a lot of people there, much more than any average company could do. But that's the reason, is their responsibility, but your responsibility. That responsibility is the one who is gonna make them fails. It's the custom responsibility, responsibility in the cloud. The data you put in the cloud, who has access to that data? That's the part that the user has to understand and has to be more aware of.
Robby PeraltaYou have one job. People often say that the cloud is cheaper, and I've heard arguments for and against that. What are what are your um sort of thoughts on that? Is the cloud cheaper?
Angel AlonsoHalf a quite high loads uh uh in the cloud, it could become quite expensive. The the benefit of the cloud is that you don't need to make in front investment. That's the biggest difference. Yeah, pay as you go model. You don't need to invest or put that at a center, you don't need to put all the physical servers. And also, it's a price that will change over time. So if your business goes well, you have a lot of traffic, you probably will be able to pay more because you have more traffic, but that's okay because your business goes well.
Robby PeraltaYeah, exactly.
Angel AlonsoSo if your business goes doesn't go so well, you pay less.
Robby PeraltaSo if you need to be flexible, then the cloud's definitely an attractive option. Yeah. I think those are the people those are the companies that uh kind of uh adopted the cloud first are the ones that needed to be flexible like that.
Angel AlonsoYeah, but do you see, for example, uh Netflix? Netflix is one of the the biggest, biggest uh cloud provid uh cloud uh uh consumers. They I mean how many how many millions of streams uh they they do. They manage to use the cloud, so they are they are they are cloud-based, and they they they don't need to think about home capacity, they don't need to think about these problems. The many customers they will have more need, they just like that get new get new servers.
Robby PeraltaEarlier that uh when you're using the cloud, you you don't really have to think about patching. You don't have to think about those sort of things because the cloud vendor sort of uh it's their response. They're gonna take care of patching because they have a routine for it.
Angel AlonsoUh depends on which depends on which level. But at least the physical patching, the physical servers, yes, we will take it. Uh if you are infrastructure as a service, nice, you have to patch the operating system of the virtual servers or the guest operating system yourself. So it depends on the level.
Robby PeraltaYeah, and that's actually part of the there that's a responsibility to know if you're responsible for for patching. Yeah.
Angel AlonsoSo that's so uh for example, in infrastructure as a service, you will be responsible from platform as a service app is the is the the cloud provider who is responsible.
Robby PeraltaAnd I've never seen a cloud contract from like Amazon or Microsoft. That's never been, you know, something on my desk that I'm looking at. Does it say like, by the way, you're responsible for patching, or is it sort of buried in the 35 long, 35-page-long document of like responsibilities? How is that?
Angel AlonsoUh the at least the big the big uh cloud providers they are quite good to explain this one. So I must say that uh Amazon Amazon, for example, they have an amazing, an amazing description of the responsibility matrix. They don't came directly into the contra, maybe, but it's in the terms of use and these kind of things. Is it it's uh it's his own interest also, of course.
Robby PeraltaYeah, because it's not it's not uh it's definitely not positive for Amazon that they're uh constantly in the news. But then nobody's blaming them really either. Like you said, it's the uh it's the customer's responsibility to think about what's in the cloud. Tools, free tools, any sort of tools, uh organizations, give uh give the listeners some advice since you've been in this space for a while. What what sort of um what things should they be aware of? What things could they be using?
Angel AlonsoIf we start thinking first, um to set requirements, for example. So we start in the in the first phase. So which requirements would do you need there, you can use uh the cloud control matrix, for example, so has uh has uh different controls of of the things that you should think when you go to cloud.
Robby PeraltaCloud control matrix, okay. Yeah, is that something for free? That's just on the internet.
Angel AlonsoYeah, it's it's it's part of the cloud security alliance uh also. Yeah, you can download it. Also, you have this uh questionnaire assessment, Kike from CSA. That is also, let's say, the question. Version of this cloud control matrix so you can send to the service pro to the cloud provider or say, okay, how you do this, how you do that. The Amazon Azure, all the big ones, they have already pre-filled. So you get answered to those questions quite fast. That's when you start in the first phase requirements.
Robby PeraltaThe thinking specification.
Angel AlonsoWhen you go more into the into the into the operation phase or design phase, they are every or most of the big again, big players in cloud security, they will offer you a lot of a bunch of tools there inside. So you have tools from uh to login, tools for um uh malicious activity. So they have a lot of tools embed inside that you can you can use. Of course, there is also commercial tools that you can uh you can use because one of the challenges is if you use different cloud providers, how you combine all that information together. So that's where it came typical produce that they will be like in the middle between all those cloud services. Uh that's typical the uh cloud access brokers uh uh cloud access brokers um sector. Yeah. Um but also there is um many other ways to just put the data. The important is that you get one of the challenges visibility when you go to different cloud vendors. So you have to in some way take all those data from the different places, make sense of it in some place, in some common centralized place.
Robby PeraltaYeah, I um when it comes to security monitoring, right? You want to have if you have a security operations team, you need to make sure that all the data they want to analyze is going through like the same correlation engines, right? So I I see that being kind of difficult if you have, yeah, I mean, hybrid cloud strategy, right? Then it it gets hard to put everything in one place to analyze it.
Angel AlonsoYeah, it absolutely gets hard. So you have to have a good solution for that one because also before you could just put everything in the server that you have in your data center and just keep it there, but now a server in the cloud can can just be up and run in two hours and be deleted and gone. Yeah. So all the data and everything is gone. Yeah. So how do you make forensics in that?
Robby PeraltaYeah, and you also have to pay to get the data down from the cloud and for some providers.
Angel AlonsoUm some providers they offer like extra extra possibilities for forensic activity.
Robby PeraltaUh logging is for free unless you want to use them. Well, as a part of your job and your you know engagements as a chief information security officer, uh, you have a C in your title, so you're obviously talking to you know executives in these companies working with, whether it's a CIO, a CFO, or CEO. And uh it's not like I've run around with a bunch of CEOs and had them as friends, but uh in my conversations I have had, I I kind of asked them, why is security or how much how much do you care about security? And the kind of between the lines answer I got was, well, I'm worried about you know making sure that uh we're filling, we're we're selling our product. I'm making sure that we have people to sell our product. They're worried about like larger factors. So how do you translate the value of security to somebody that thinks totally different than than we do traditionally in security?
Angel AlonsoI I actually understand that this happens because traditionally security people have been really bad to talk about business. So that has and that's one of the changes that you also see in the thesor role. So there is no anymore that IT person they are down in into the details. They're starting to move more to the C level, as you say, and they need to talk in business terms. And the C level or the CEO doesn't care about the IT probably because there is no one of at least there is one of the core business of the company, Sir Comp Sir Fogel, uh of course. That's that's not something that they they think about every day. So is the security expert who has to change the way they talk. So they need to be able to talk about the business. And when you talk about the business, you need to use the same language that they use in the in the in the in the board. So you need to you need to understand first what is your uh big value your your crowns, where they are. So when you understand what those ones is when you can start to make it appropriate protection and defense around those ones. And you can explain to the CEO, yeah, if we lose this one here, yeah, we are going to be able to sell, or we are going to be down for three weeks, we are going to lose our intellectual property, so we won't be able to be the first in the market. When we start to change the way we speak, if we want if we change to this business uh way of talking, that will make automatically communication easier. For example, as in uh in our department, we we like to we we we like to use SABSA. SABSA is a way and an architectural framework to connect the business driver or the business objective to business driver for security, or from security down to the controls that you actually put. So you actually could say to a CEO, yes, we are doing this because if we don't do this, you won't be able to be the preferred company that you want to be. So you need to start to talk about these terms.
Robby PeraltaYeah, you gotta put it in monetary terms for them.
Angel AlonsoYeah.
Robby PeraltaThat's why you took a business degree on top of your cybersecurity degrees.
Angel AlonsoThat was one of the main reasons because you need to change the way. So if you have a very technical background like me, so you are not used to to speak in financial terms, you're not to speak in these uh management uh terms. So that helps a lot to actually change the way you speak. And if you put together that one, so you put together this language in a way they can understand it, in a way that understands you have to protect your house. You cannot give the keys to your house to everyone. So you have to protect your house, you have to put in the safe the things because they have value. And that value that you have there is the is the value that has a repercussion in your business. So I won't be able to sell more products. My webs my website is uh compromised. My my boats cannot ship, my industrial processes cannot go. Yeah, millions and millions lost. We have seen examples.
Robby PeraltaAlright, Mr. Alonso. So is there any um closing comments or any uh final wishes?
Angel AlonsoUm maybe just uh encourage everyone uh who is uh listen to us that join the Cloud Security Alliance knowledge chapter is free. So you just need to to find us in LinkedIn and just uh join the join the group and you will you will be able to follow up the activities. Also we make some uh members uh meetings uh every quarter or something like that. So please join us.
Robby PeraltaAnd how is that how do those meetings work? They people come there and they share their projects and their ideas and just get feedback from their counterparts, or is that yes?
Angel AlonsoUh they are like mem there is uh members meeting. So um we organize some speakers normally, get two, three speakers to to explain some use case or share shared experience. No sellers there, no sellers, shared uh share basic. We we we prefer, of course, customer experience and use cases, how they have used it, what have been the challenge. And uh normally we do that after work, so it's more like a networking social event. Maybe one hour with some uh lectures like this one, and afterwards some food, beer, drinks. Cool.
Robby PeraltaCool. And some cloud. Well, Mr. Alonso, thank you very much for your time.
Angel AlonsoThank you so much. That's been really fun.
Robby PeraltaWe'll be sure to follow your progress, uh, the cloud's progress moving forward. Thank you. Well, that's all for today, folks. Thank you for tuning into the mnemonic security podcast. If you have any ideas or concepts that you would like us to discuss, please feel free to send a mail to podcast @mnemonic.no.