Cloud Security Podcast
Understanding that technology alone won’t solve security gaps is crucial for organizations facing rising threat complexity and budget pressure. By focusing on process redesign before tool adoption, teams can achieve measurable improvements in SOC efficiency and resilience, making the episode especially relevant as AI security solutions become mainstream.
In this episode the hosts expose a common myth: swapping a legacy SIEM for a shiny, AI‑enabled platform does not constitute a true SOC transformation. Danny Lyman explains that many organizations focus on the technology layer while ignoring the underlying processes that drive detection and response. Without revising playbooks, alert triage workflows, and staffing models, the new tool merely speeds up the same inefficient steps, leaving the security posture unchanged.
The conversation then shifts to the interplay of people, process, and technology. A well‑designed SOC must balance specialized expertise—EDR, NDR, IAM—with a unified set of procedures that enable cross‑team visibility. In federated SOC models, geographic or functional silos can create blind spots unless data, alerts, and decisions are consistently shared. Building guardrails, standardizing hand‑offs, and fostering muscle memory across analysts turn good technology into a strategic advantage, while also addressing talent retention challenges.
Finally, the panel explores AI’s promise and pitfalls. While artificial intelligence could stitch together disparate telemetry streams to generate “super‑rules,” its effectiveness hinges on comprehensive data access. Legacy systems, isolated data lakes, and reluctant teams can starve AI models of the context they need, limiting real‑world impact. Listeners are urged to treat AI as an augmenting layer—not a silver bullet—and to prioritize data centralization, clear governance, and process redesign before banking on automated detection.
Subscribe at YouTube
Subscribe at Spotify
Subscribe at Apple Podcasts
Guest:
Daniel Lyman, VP of Threat Detection and Response, Fiserv
Topics covered:
Resources:
Video version
“In My Time of Dying” book
EP258 Why Your Security Strategy Needs an Immune System, Not a Fortress with Royal Hansen
EP197 SIEM (Decoupled or Not), and Security Data Lakes: A Google SecOps Perspective
The Gravity of Process: Why New Tech Never Fixes Broken Process and Can AI Change It? blog
Do you have something cool to share? Some questions? Let us know:
Web:
cloud.withgoogle.com/cloudsecurity/podcast
Mail:
cloudsecuritypodcast@google.com
Twitter:
@CloudSecPodcast
Comments
Want to join the conversation?
Loading comments...