Guest:
Alex Shulman-Peleg, Global CISO at Kraken
Topics:
You mentioned that centralized security can't work anymore. Can you elaborate on the key changes—driven by cloud, SaaS, and AI—that have made this traditional model unsustainable for a modern organization?
Why do some persist at centralized, top down approach to security, despite that?
What do you mean by "Freedom, Responsibility and distributed security"?
Can you explain the difference between "centralized security" and what you define as "security with distributed ownership"? Is this the same "federated"?
In our conversation you mentioned "cloud and AI- native", what do you mean by this (especially "AI-native") and how is this changing your approach to security?
You introduce the concept of "Security as quality" suggesting that a security-unaware developer is essentially a bad software developer. How do you shift the culture and internal metrics to make security an inherent quality standard, rather than a separate, compliance-driven checklist?
You likened the central security team's new role to a "911 emergency service." Beyond incident response, what stays central no matter what, and how does the central team successfully influence the security posture of the entire organization without being directly responsible for the day-to-day work.
Resources:
Video version
EP129 How CISO Cloud Dreams and Realities Collide
EP258 Why Your Security Strategy Needs an Immune System, Not a Fortress with Royal Hansen
EP212 Securing the Cloud at Scale: Modern Bank CISO on Metrics, Challenges, and SecOps