Google Cloud CISO Phil Venables has a theory on cloud adoption and how it improves customers’ security posture without requiring any extra effort on their part. He calls it “the concept of the digital immune system,” and says it played a big role in his decision to join Google Cloud as its first chief information security officer a little over a year ago.
“For the first time in history, we’ve got this feedback loop happening,” Venables said.
Google ships hundreds of security updates to customers every month, across all of its products and services, he explained. These may be improvements in default settings, for example enabling encryption by default. Or they may include security updates to patch a vulnerability that one of its bug bounty programs found or that its penetration testing team discovered.
“There’s this huge amount of data that’s coming in to us about what new security features we should be building in,” Venables said. At the same time Google Cloud customers with large security teams provide “a constant source of requests about what new features they want to see,” he added.
In other words, all of Google Cloud’s security updates are informed by a real-life or hypothesized vulnerability or threat, or another organization’s experience. And enterprise IT teams can use this feedback loop to get better protection across their cloud environments.
“If you’re a customer that doesn’t have a large security team — or even if you do have a large security team — one of your best strategies is just to sit back and take every update we give you, knowing that it’s been informed by this collective view from the entire ecosystem of customers, plus the ecosystem of what we see not just as Google Cloud, but what we see across all of Google, from all of our threat intelligence,” Venables said. “And that’s a huge win for everybody.”
Google Cloud’s First CISOVenables is Google Cloud’s first CISO, and he joined the cloud provider after spending a couple decades on the enterprise side. Most recently, he was a partner at Goldman Sachs where he worked as the investment banker’s first CISO for 17 years. He also was chief risk officer for the firm’s operational risks, and a senior advisor to clients and Goldman Sachs’ leadership on cybersecurity and digital risk.
Venables also serves on the Information Security and Privacy Advisory Board of the National Institute of Standards and Technology, and he helped found the financial sector’s Center for Internet Security.
This background informs his security strategy at Google Cloud, and it also shaped his view on eight megatrends that Venables says IT decision makers should pay attention to this year and beyond.
“I was always motivated by not just how to protect the company I was working for, but how can we make security better for everybody? And in particular: How to scale security so that it could be embedded in more things so that more people and companies and governments could get the benefit of security without always having to invest the maximum amounts themselves,” he said. “How do we embed security in everything?”
Venables detailed these megatrends in a blog post, and the first one is economy of scale — how decreasing the marginal cost of security raises the baseline. This is unique to large public cloud providers compared with on-premises environments, he said. Organizations can reduce the unit cost of the security because Google embeds security across its products. “You’re able to amortize that cost by embedding it across many of your products, so you’re able to invest more in security,” Venables said.
“We invest in, for example, things like our Titan security chips that we embed in every one of our servers,” he continued. This lets organizations invest in security “knowing that you can amortize that across the overall infrastructure. That works with software investments as well. So that economy of scale really benefits customers.”
Comments