What Practitioners Actually Think

Cloud Security Office Hours has met on Zoom every Friday since February 2023, and every session gets a published recap. These digests read back across that archive one topic at a time and report what the room actually said, including the arguments nobody won. Not vendor takes, not predictions, and not a maturity model.

· · Vendor-neutral · View source on GitHub

Three ground rules, applied to every digest here: no individual attendee is named, every claim links to the recap it came from so you can check it, and opinions are labeled as opinions rather than promoted to facts. Where a session named a vendor or a product, that is reported as one person's experience and not as an evaluation.

A topic only gets a digest once enough sessions have genuinely worked through it. Several obvious candidates do not have one yet, and that is deliberate.

On this page

  1. The digests
  2. How these are made
  3. What does not have one yet
  4. FAQ
  5. Where next

The digests

Five so far, ordered by how much of the archive each one draws on.

How these are made

Cloud Security Office Hours is a free, open Zoom that runs every Friday morning. Practitioners drop in, someone asks a question, the room works through it, and every session gets a published recap. That archive now runs to more than a hundred sessions.

A digest starts by finding the sessions where one topic was genuinely argued rather than mentioned in passing, then synthesizes them into a single page. The result is deliberately different from the reference pages elsewhere on this site. A reference page tells you how something works. A digest tells you what people who do it for a living said to each other about it, which includes being wrong, changing their minds, and failing to reach agreement.

The constraints exist because the Friday call is a conversation, not a publication. People think out loud and speak about their employers informally. Attributing opinions to named individuals would change what people are willing to say, so no attendee is named. Guest speakers who presented publicly are named, because presenting is a public act.

Every claim carries a link to the recap it came from. If a digest tells you the room split on something, you can open the session and check.

What does not have one yet

Several topics that clearly belong here do not have a digest, because the archive does not yet carry enough substantive discussion to support one. Detection engineering, incident response, Kubernetes, and identity all come up regularly but so far in passing rather than in depth.

Security conferences are the closest to ready. The material that exists is unusually pointed, covering the declining relevance of the big events and the operational security of speaking at them, but it currently rests on a handful of sessions. That will change after the late-summer conference season.

Padding a thin topic out to page length would undercut the ones built on real coverage, so these wait. If a topic you care about is missing, the fastest way to fix that is to turn up on a Friday and argue about it.

FAQ

Is this an official position of Cloud Security Office Hours?

No. Each digest is a synthesis of what attendees said on the live Friday call. CSOH is vendor-neutral and takes no house position on any of these topics. Where attendees disagreed, both sides are reported rather than reconciled, and opinions are labeled as opinions rather than promoted to facts.

Why are no individual attendees named?

The Friday session is open to anyone, but it is a conversation, not a publication. People think out loud, change their minds, and talk about their employers informally. Attributing opinions to named individuals would change what people are willing to say. Guest speakers who presented publicly are named, because presenting is a public act.

How is a digest built?

By reading the recaps where one topic was genuinely worked through rather than mentioned in passing, then synthesizing them into a single page. Every claim links to the specific recap it came from, so any reader can check the source. The number of sessions behind each digest is stated on its own page and on the cards above.

Why does my topic not have a digest?

Almost certainly because the archive does not carry enough substantive discussion of it yet. Padding a thin topic out to page length would undercut the digests built on real coverage, so the answer is to wait, or to come and raise it on a Friday.

Can I join the Friday session?

Yes. It runs every Friday, it is free, there is no pitch, and there is no requirement to speak. Details are on the sessions page, and every past session has a published recap.

Where next

The best way to use these pages is to disagree with them in real time. The room is small enough that your question gets answered and open enough that nobody minds if you have never touched the topic before.