Three ground rules, applied to every digest here: no individual attendee is named, every claim links to the recap it came from so you can check it, and opinions are labeled as opinions rather than promoted to facts. Where a session named a vendor or a product, that is reported as one person's experience and not as an evaluation.
A topic only gets a digest once enough sessions have genuinely worked through it. Several obvious candidates do not have one yet, and that is deliberate.
On this page
The digests
Five so far, ordered by how much of the archive each one draws on.
AI security and governance
From "keep the data out" in late 2024 to governing budgets and scanning agent skills in 2026. The room has never agreed on whether AI needs new tooling or an extension of what we already run.
Breaking into cloud security
Certifications, the experience paradox, referrals versus cold applications, and what hiring managers in the room say they look for. Includes the discouraging parts most career guides leave out.
Vulnerability management
Nobody defends CVSS as a prioritization mechanism and nobody has replaced it. Includes why the enrichment pipeline quietly broke, and the split over whether the patch-everything model is the wrong shape.
Supply chain and CI/CD
Mostly recorded while a fresh compromise was still landing. SBOMs draw the sharpest split, and egress control is the fix everyone agrees on and nobody can afford.
Regulation and liability
Broadly cynical about fines, broadly serious about regulation anyway. The one instrument credited with moving engineering practice did it by requiring an artifact, not by threatening a penalty.
How these are made
Cloud Security Office Hours is a free, open Zoom that runs every Friday morning. Practitioners drop in, someone asks a question, the room works through it, and every session gets a published recap. That archive now runs to more than a hundred sessions.
A digest starts by finding the sessions where one topic was genuinely argued rather than mentioned in passing, then synthesizes them into a single page. The result is deliberately different from the reference pages elsewhere on this site. A reference page tells you how something works. A digest tells you what people who do it for a living said to each other about it, which includes being wrong, changing their minds, and failing to reach agreement.
The constraints exist because the Friday call is a conversation, not a publication. People think out loud and speak about their employers informally. Attributing opinions to named individuals would change what people are willing to say, so no attendee is named. Guest speakers who presented publicly are named, because presenting is a public act.
Every claim carries a link to the recap it came from. If a digest tells you the room split on something, you can open the session and check.
What does not have one yet
Several topics that clearly belong here do not have a digest, because the archive does not yet carry enough substantive discussion to support one. Detection engineering, incident response, Kubernetes, and identity all come up regularly but so far in passing rather than in depth.
Security conferences are the closest to ready. The material that exists is unusually pointed, covering the declining relevance of the big events and the operational security of speaking at them, but it currently rests on a handful of sessions. That will change after the late-summer conference season.
Padding a thin topic out to page length would undercut the ones built on real coverage, so these wait. If a topic you care about is missing, the fastest way to fix that is to turn up on a Friday and argue about it.
FAQ
Is this an official position of Cloud Security Office Hours?
No. Each digest is a synthesis of what attendees said on the live Friday call. CSOH is vendor-neutral and takes no house position on any of these topics. Where attendees disagreed, both sides are reported rather than reconciled, and opinions are labeled as opinions rather than promoted to facts.
Why are no individual attendees named?
The Friday session is open to anyone, but it is a conversation, not a publication. People think out loud, change their minds, and talk about their employers informally. Attributing opinions to named individuals would change what people are willing to say. Guest speakers who presented publicly are named, because presenting is a public act.
How is a digest built?
By reading the recaps where one topic was genuinely worked through rather than mentioned in passing, then synthesizing them into a single page. Every claim links to the specific recap it came from, so any reader can check the source. The number of sessions behind each digest is stated on its own page and on the cards above.
Why does my topic not have a digest?
Almost certainly because the archive does not carry enough substantive discussion of it yet. Padding a thin topic out to page length would undercut the digests built on real coverage, so the answer is to wait, or to come and raise it on a Friday.
Can I join the Friday session?
Yes. It runs every Friday, it is free, there is no pitch, and there is no requirement to speak. Details are on the sessions page, and every past session has a published recap.
Where next
The best way to use these pages is to disagree with them in real time. The room is small enough that your question gets answered and open enough that nobody minds if you have never touched the topic before.
- Friday Zoom sessions - every Friday, free, no pitch. These pages exist because people show up.
- All meeting recaps - the full archive every digest is built from, searchable by topic and date.
- Recap RSS feed - one item every Friday, so you get the raw material as it lands.
- Breach kill chains - the technical counterpart: incidents reconstructed step by step from published post-mortems.
- Resource directory - the curated reference material behind the opinions.