Get the Zoom link
Cloud Security Office Hours Banner

Friday, October 9, 2026 - Meeting Recap

Personal Updates and Catch-up Meeting

- Personal Updates and Catch-up Meeting

Quick recap. The Cloud Security Office Hours meeting featured an open discussion on various topics in cloud security and the broader cybersecurity industry. Participants shared personal updates, including job changes and new roles, and discussed challenges in the job market, such as lengthy interview processes and degree requirements. The group analyzed a recent security incident involving the FBI and a contractor, highlighting issues with software liability, patch management, and the role of contractors in government cybersecurity. They debated the effectiveness and pricing of security products, the need for regulation, and the idea of a cyber equivalent to the NTSB for independent incident investigation. The conversation also touched on vulnerability management, the role of CNAs, and the limitations of current approaches to securing software. The meeting included informal networking and introductions for new members, with an emphasis on learning and collaboration.

2026-10VulnerabilitiesEducationCommunity

Personal Updates and Catch-up Meeting

The group had an informal catch-up conversation where Shawn shared that he finally closed a long-pursued deal he called his "white whale" with Amex after 5 years of work. Christopher joined from Texas while apartment hunting, and Stryker discussed getting two new cats and his experience with house-sitting. The conversation included discussions about pet care, travel house-sitting opportunities, and various personal updates among the participants.

Job Interview Challenges Discussion

The group discussed job interview experiences, with Stryker sharing details about being through an extensive interview process at a company that later hired someone with different qualifications. Shawn recounted his own challenging experience with AWS, where he completed multiple interview rounds only to be rejected by a bar raiser who focused on his lack of a degree. The conversation highlighted the challenges of the current job market and the power dynamics involved in job references and recommendations.

Cloud Security Office Hours Meeting

Shawn welcomed 24 attendees to Cloud Security Office Hours, noting it was an early meeting with some new participants joining. He encouraged new members to introduce themselves and make connections in the global group. Shane introduced himself as a new member pursuing a cybersecurity degree at WGU, having recently passed his A+ certification and participating in the National Cyber League with Brady's help. The meeting followed an open forum format with no specific agenda items discussed.

FBI PeopleSoft Security Breach

The group discussed a security incident at the FBI where a critical vulnerability in their PeopleSoft HR platform was exploited by attackers, leading to a significant data breach. Neil shared insights from Jen Easterly's post about the incident, highlighting concerns about the vulnerability's design and implementation, as well as questions about software liability. The discussion touched on the role of contractors in government operations and the potential risks of relying heavily on external contractors, particularly in light of recent personnel changes at government agencies.

CISA Director Role Clarification

Stryker clarified that she will not be becoming the director of CISA, expressing concerns about the impact of purges and hiring practices in cybersecurity that treat people as interchangeable. The discussion touched on challenges in government cybersecurity, including legal constraints, financial limitations, and the difficulty of implementing effective security measures. Neil shared insights about the importance of wrapping security around black-box systems and managing risks when limited control exists over such components.

Healthcare Cybersecurity Challenges Discussion

The group discussed cybersecurity challenges in healthcare and other industries, focusing on the Stryker breach case where inadequate security measures allowed data deletion. Jay highlighted that many smaller organizations struggle with cybersecurity due to high costs and limited resources, often finding it more economical to pay ransomware demands than invest in security measures. The discussion also covered the need for more affordable and effective security tools, with Daniel mentioning South Korea's approach of implementing percentage-based fines that scale with company size.

Cybersecurity Pricing Challenges Discussion

The group discussed pricing challenges in cybersecurity, with Neil sharing a specific example from his time at StackRox about a potential client who had a 90% discount built into their Red Hat contract due to different pricing models. Jay emphasized the importance of vendors providing value beyond just seat counts and suggested a risk-based pricing approach. David shared a personal story about changing his views on regulation after witnessing a bank's response to security-related regulatory demands, leading him to support more robust regulatory oversight.

Cyber NTSB Proposal Discussion

David proposed creating a cyber equivalent of the NTSB, separate from regulatory bodies, to investigate and identify security issues without being accountable to those responsible for implementing solutions. Jay explained that such an independent body could conduct deep investigations into organizational structures and decision-making processes, similar to the NTSB's approach to aviation accidents. Neil suggested that while a coalition like Glasswing might not be effective for finding vulnerabilities, it could potentially work in other security areas, and emphasized that regulation would be necessary to create economic incentives for addressing security issues.

Project Athena Vulnerability Patching Initiative

Neil discussed Project Athena, an initiative led by Chainguard focused on using AI to help patch vulnerabilities rather than just finding them, with 14 previously patched vulnerabilities being documented as actual vulnerabilities this week. The discussion centered around the conflict of interest with CVE numbering authorities (CNAs) and NVD's rating system, with Neil explaining that at ORCA they trusted CNA scores over NVD scores due to CNAs having better technical expertise about their products. Juninho expressed concern about the timing of Flock being authorized as a CVE numbering authority, noting it seemed suspicious given recent public issues with the company, though the group acknowledged the challenge of evaluating trust in CNAs.

↑ All meeting recaps