The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Beyond the Screen
Beyond the Screen artwork

Exploring Zero Trust Networking in a Multi-Cloud Environment

Beyond the Screen · 2024-04-09 · 35 min

0:00--:--

Key moments - from our scoring

Substance score

51 / 100

Five dimensions, 20 points each

Insight Density10 / 20
Originality8 / 20
Guest Caliber13 / 20
Specificity & Evidence9 / 20
Conversational Craft11 / 20

Mohamed Osaimi brings 25 years of IT infrastructure experience to discuss the fundamental shift in how organizations must approach security in cloud-native environments. The conversation centers on zero trust networking - a model where every access request requires authentication and authorization, rather than trusting users based on initial login. Osaimi explains how businesses using multiple cloud providers (AWS, Azure, Google Cloud) can maintain consistent security posture through unified management tools and layered security controls including multi-factor authentication, behavioral analytics (SASE/Secure Access Service Edge), and data loss prevention. The discussion covers practical implementation challenges: the tension between security and user friction, compliance requirements (HIPAA, GDPR), and why most organizations remain reactive - waiting for breaches before investing in security architecture. Osaimi recommends that small businesses start with defined goals, choose appropriate cloud services incrementally, and recognize that 80% of data breaches originate from internal networks. For enterprises managing multi-cloud deployments, he advocates using a single pane of glass management approach while maintaining redundancy across cloud providers to mitigate vendor lock-in and service failure risks.

Key takeaways

  • →Zero trust networking requires every access request - even after initial login - to include additional authentication and authorization steps based on identity, location, device, and application sensitivity.
  • →80% of data breaches originate from internal company networks, not external attackers, making insider threat controls and behavioral monitoring critical components of security design.
  • →Organizations should use multiple cloud providers across different functions (email, apps, backup) to avoid vendor lock-in, reduce failure impact, and maintain cost competitiveness rather than consolidating everything with a single provider.
  • →Security design must balance friction with protection; adding layers like multi-factor authentication and data loss prevention increases latency but is necessary to prevent unauthorized access to sensitive data.
  • →Small businesses should define their security goals first, start with appropriately-sized cloud services, and scale gradually rather than attempting comprehensive cloud migration immediately.

In this episode

  1. 1Career Journey Across IT Infrastructure and Cloud
  2. 2Evolution of Security Threats: From Infrastructure to Data Protection
  3. 3Certifications as Proof of Real-World Cloud Security Knowledge
  4. 4Architectural Complexity in Remote Work and Multi-Cloud Environments
  5. 5Zero Trust Networking: Framework and Implementation
  6. 6Balancing Security Measures with User Experience and Productivity
  7. 7Multi-Cloud Strategy for Cost Optimization and Risk Mitigation
  8. 8Getting Started with Cloud Security for Small Businesses

Mentioned

IonisCloudreachMicrosoftAmazonGoogleEquifaxJoe NashMohamed OsaimiGDPRHIPAA

Guests

Mohamed Osaimi

Topics in this episode

AzureGoogle CloudMulti-factor authentication (MFA)GDPRData loss prevention (DLP)AWSSASE (Secure Access Service Edge)identity and access management (IAM)Data protectionZero-trust networkingcloud servicesTech Podcastdevelopersfront end developersMulti-Cloud Architecture

Questions this episode answers

What is zero trust networking and how does it work?

Zero trust networking means that even after a user logs in with username and password, they must provide additional authentication and authorization for each resource they access. For example, accessing email might require one credential set, while accessing payroll requires separate multi-factor authentication, ensuring every access request is verified rather than inherited from initial login.

How can companies manage security across multiple cloud providers?

Organizations can use unified management tools - a single pane of glass - offered by AWS, Azure, and Google Cloud to monitor and manage security policies across all environments plus on-premises data centers, while also distributing critical systems across different providers to reduce vendor lock-in and provide redundancy.

Why do most companies only invest in security after a breach happens?

Companies typically view security investment as a cost center that doesn't generate revenue, so they delay spending until a breach causes tangible losses (reputation damage, market share loss, compliance penalties) that force them to change strategy.

What percentage of data breaches come from inside company networks?

Approximately 80% of data breaches originate from internal company networks - such as employees connecting unauthorized devices, social engineering attacks on IT staff, or impersonation - rather than external attackers.

What security layers are needed to implement zero trust in a cloud environment?

Key layers include identity and access management, multi-factor authentication (tokens, biometrics), behavioral analytics to detect suspicious locations or times, SASE (Secure Access Service Edge) to assess device and location security, data loss prevention tools, and granular permission controls that define what level of access (view, edit, delete) each user has.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

10 / 20

The episode covers broad security concepts like zero trust, multi-factor authentication, and backup/disaster recovery, but mostly reiterates well-known best practices without novel technical depth. While the guest explains concepts clearly for beginners, there is limited new insight for experienced B2B operators - most frameworks presented (layered security, MFA, backup testing) are industry standards rather than fresh thinking.

Zero Trust networking. In a brief for non IT person, I will give you an example. You are working on a company. You have a username and password. You just logged in and you have access to everything. Applying, uh, zero trust environment means yes, you log in, but to access anything, you still need to also request for authentication and authorization.
you must have a backup plan. Second you must to test it, don't wait for a breach. Then you start to check your backup plan. And third, you should have more than one backup plan.

Originality

8 / 20

The guest recycled established security doctrine (zero trust has been mainstream since ~2017, MFA is ubiquitous, backup testing is routine). The airport security and hospital visit analogies are relatable but not novel. The discussion of AI risks and compliance evolution touches on current topics but lacks contrarian or first-principles argumentation that would distinguish this from dozens of similar security podcasts.

Zero Trust networking...every step, uh, need to be checked to be known that you are who you are and this is your credential.
Every cloud service provider has to manage their environment as a public cloud environment

Guest Caliber

13 / 20

Mohamed Osaimi is a legitimate senior cloud architect at Cloudreach with 25 years of IT experience spanning infrastructure, networks, and cloud security. He demonstrates real practitioner knowledge and has clearly led infrastructure deployments. However, his communication is sometimes unclear (grammatical errors, meandering answers), and he comes across as more of a vendor/generalist architect than a deep specialist or category authority who would command premium attention from C-suite operators.

Mohamed Osaimi who for 20 years has been working in the IT industry across the Middle east and the USA
I'm currently a senior cloud architect at AH cloudreach. He has a successful record of identifying key solution gaps, business and project impacts

Specificity & Evidence

9 / 20

The episode contains some concrete examples (Equifax breach, hospital analogy, a Middle East government data loss incident, Amazon ransomware case with a friend) but lacks named customer projects, quantified metrics, timelines, budget figures, or measurable outcomes. The Middle East government example is mentioned but not detailed enough to extract actionable learning. Most guidance remains abstract (e.g., 'start small,' 'define your goals') without specific company case studies or technical implementation data.

80% from data breaches...hadn't come from internal data network from the internal company network, not from outside.
I remember 20 years ago there is a government in the Middle east has a big problem. He has a very expensive system that host the data of all people looking for a job. And suddenly the system stopped working...the last backup they had is six months before

Conversational Craft

11 / 20

The host asks sensible opening questions and shows genuine interest, but rarely pushes back, challenges assumptions, or pursues follow-up depth. When the guest mentions AI risks, compliance changes, or internal breach statistics, the host accepts these largely uncritically. There are no sharp technical probes, no disagreement, and few attempts to extract more specificity from vague claims. The conversation reads as a friendly introductory primer rather than a rigorous practitioner dialogue.

Interesting. Okay, so that I imagine has various influences on um, how staff are working with the network, how they're working with the resources. From a technical standpoint, how do you as a cloud architect, structure a business's network to provide for that facility?
That's a great metaphor. I like that a lot.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B68%
  • Speaker A32%

Most-used words

cloud43access39data34security18problem17start15backup15different14environment12industry10secure10sure10public10plan10apps9technology9

Episode notes

Insights from Mohammad Ossaimee of Cloudreach Welcome to Beyond The Screen: An IONOS Podcast, hosted by Joe Nash. Our podcast is your go-to source for tips and insights to scale your business’s online presence and e-commerce vertical. We cover all tech trends that impact company culture, design, accessibility, and scalability challenges - without all the complicated technical jargon. Our guest today is Mohammad Ossaimee, Senior Cloud Architect at Cloudreach. Join us as we discuss: • The concept of zero-trust networking • Learning from previous breaches • Using security management tools in a multi-cloud environment • Transparent and proactive sharing of data breaches with customers • The positive and negative impact of AI Mohammad Ossaimee has been in the IT industry for over twenty years, with strategic, architectural, and implementation experience. He has a proven record of successfully identifying key solution gaps, business and project impacts, and creative solutions to ensure the delivery of projects on time and within budget. Mohammad is an expert at leading large, complex, and global IT infrastructure deployments.

Full transcript

35 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: M welcome to beyond the Screen, an Ionis podcast where we share insights and tips to help you scale your business's online presence. Hosting genuine conversations with the best in the web and IT industry and exploring how the Ionis brand can help professionals and customers with their hosting and cloud issues. I'm your host, Joe Nash. Welcome to another episode of beyond the Screen, an Iona's podcast. Joining us today is Mohamed Osaimi who for 20 years has been working in the IT industry across the Middle east and the USA for from Cairo to Riyadh to Michigan. Mohammed is currently a senior cloud architect at AH cloudreach. He has a successful record of identifying key solution gaps, business and project impacts and providing creative solutions to ensure delivery of projects on time and within budget leading global IT infrastructure deployments. Today he's here to talk about cloud security and how businesses can adapt to an ever evolving threat. Welcome Mohammed. Thanks so much for joining me today. How are you doing?

Speaker B: Thank you. Pleasure was mine.

Speaker A: I'm very excited to have you here with us today. You know we've had a number of really interesting cybersecurity guests but I think your experience is going to add a real new twist to this really important topic. So to dive in, we always like to ask our guests about their careers and what has brought them to the show and to this place. So can you start by telling us a little bit about your career to date and the kind of roles and responsibilities that you've held.

Speaker B: As you mentioned earlier about myself M. I've been in the IT field over 25 years and I worked in different roles wearing different hats, working with different companies in different countries. I started as a computer engineer once I graduated assembling PCs, selling those PCs to end user and then moving to enterprise building networks, then moving to network operating systems and go to virtualization, mastering systems and after the uh, moving to the cloud. Cloud is a big area and evolving, growing and most of companies now moving to the cloud and the most important thing for them how to secure their environment on the cloud because it's out of their control. The other guys from the cloud service providers managing those environments. So the security is a big concern and now we are not talking about how to secure your PC now how to secure your apps, your code, your access, your identity, your data. This is a very big change. Uh, and the chances is being complicated. More and more wants to move now we move into the AI and machine language. That's another factor came to this world, this IT world and bring a lot of questions about how can we show this is real, not fake. How to separate, how to control the access. That's what I do.

Speaker A: Awesome. Perfect. You touched on a number of really important things. The general modal shift from owning your infrastructure to cloud. I think the AI one's really fascinating. I imagine have you had to deal already with things like people deploying LLM driven apps and having prompt escapes and this kind of thing? Is that a security concern that started to creep into your horizon?

Speaker B: Um, I'm not working deeply in the application area in the problem. I'm from infrastructure and security but I have some of those apps but usually I ah, look from the outside. You have your app that X for me, uh, my job. Okay, who should access it, what is the output area that it can work, which service that can interact with it or uh, contact with. That's what I focus and build by design and sure send it back to the customer. This environment would be secure.

Speaker A: Perfect. So you touched on a couple of ways that the technology and the industry has changed throughout you know, your time in it. What do you think are the key shifts or the key benchmarks that you know really mark how the industry has changed in your time?

Speaker B: That's very important question and it's not easy to answer. But for myself the key that moving the companies from one environment to another and the key developing is data. Data is the most important thing for user, for deferable and for companies. There are days that someone to send you a virus to uh, corrupt your system is over. Now everyone trying to reach your data, to capture them, to impersonate yourself for other things to sell it to other entities. So this is a uh key factor that companies invest more and more in ah, the IT field either on their data centers or moving to the cloud or building new apps. They were upgrading their apps and those companies have one question. I'll be sure that my data is secure. No one can access it and the only authorized peel group can see what they should see only not nor you can see. In United States we have some governance and uh compliance be applied especially for healthcare which called hipaa. Now in Europe they have their own compliance with gdpr. No one should access those data outside the region. So more to come new compliance applied new complications requesting from us to build new things to adapt with those compliance and uh, all of them around one thing, data.

Speaker A: Yeah, really. I mean I should say it's a complicated question and interesting answer like you know I asked you what's changed to technology but of course you mentioned piece of legislation there, uh, GDPR that is still relatively new. So it's not even just the technology that's changing. The legislation and compliance picture is a huge one. We spoke a little bit about your experience and how you bring that to bear for these companies and for the design. So you have just renewed your Microsoft certification in cybersecurity Architect expert. I mean at the time of recording, by the time this comes out, it will not be quite as recent, but it's pretty recent as of now. Well firstly, congratulations. And then secondly, what does it take to get that certification and to be the uh, Microsoft certified Cybersecurity Architect expert?

Speaker B: You know, for myself certificate it just, I figured that I can do this. It's not showing me like an expert, it's just I can discuss this technology with my customer. It shows my customers that uh, I'm capable to do this. That's why companies like Microsoft, Amazon, Google and others keep updating their certs and forcing us to updating our cert annually. That's because new things coming to the technology, new terms, new design, new deployments that I must be aware about. All these uh, new deployment services and going to adopt it to my certificate is just something that proves that I'm aware about what's going on in the market.

Speaker A: Interesting. If I were to take the viewpoint of someone who's new to the cybersecurity industry, someone who's getting their start in their career, you would recommend to them these certifications as a way to signal that they've got the knowledge necessary. Is that correct?

Speaker B: Yeah. How to differentiate you among the others. I know many people doesn't have a college degree and they are working on Google. Why they had the knowledge and the technology. Plus I said everyone has bachelor degree, everyone can get a master degree. All of them are academic. But going on the real field, you need to talk about something real that uh, okay, customer has a problem, your role to get a solution to solve this problem. So with the master with a be chain, it will not be enough. Your serve can show to the customers that you are capable to give them a solution to solve their problem. What is their problem? I have my data. How can I protect my data? How can I access my data, uh, from anywhere. Most of companies now moving from on site to remote. So people who are transforming remote locations either from your garage or from your bedroom or a rental office. So how can be sure the access is secure? And the guy who accessing my system is the guy who is working with me, not as a person. All of them need certified people who has the Knowledge and experience to give the solution and build the right environment for the right customer.

Speaker A: Fascinating. The important certifications aside, you know, I really liked your emphasis on the bachelor's degrees and university degrees that have their place. But fundamentally theoretical, academic and the practical vocational nature of certifications is showing real world experience is really, really useful. I really loved that point you made there about not just the shift in technology, not the shift in legislation, but the way we work. Like you know, previously everyone's machines were in a secured office. They knew where it was, the company knew how to handle it, and now they could be anywhere. Has that impacted architecture? Has ah, that impacted how you design systems for your clients?

Speaker B: The more the request is the uh, more to complicate the process in my desire. If you go back 10 years, for example, we have one SNR, some servers connected with back end storage through fibers and network switches. Done. Now we have more. You have a place to put your code. You don't need a complete server or complete laptop or computer to use it to build your code. It's just a code. Publish it on the cloud, everyone can access it. If you want to sell something, you have website, different websites that you build a complete website for you and start selling your product. You have analytical record, you can work with different hospitals, you go to their uh, portal, you check for test results, you schedule your appointment, all this data bring to you. How do you ensure that there is no one else can see those data except you? That is a big concern and this makes our design more difficult because we bought many things to consider about. Not only the infrastructure, the components, the storage, the uh, networks, the cable. No, we're looking outside. Who can access from where he can access he or she, and when he or she can access which area you can get, what reward you can retrieve. All these points we must consider in our design. Usually it's a username and password. Most of the people I'm on there to save my username and password in the browser. This is not a uh, good practice. What will happen if your laptop will be stolen or lost? Someone will find it, crack your password, log into your browser getting your password and can do whatever you want. That's it. So how can trace those activities? Sometimes when you just log into your browser from a strange place which shouldn't be there, There is a product, a software or marketing tool to monitor this activity and block it. Okay, you shouldn't be here. I need to get authorization to allow you to access all of them. Um, added to my design, which will be bigger uh, and um, bigger, uh, and bigger. Uh, that's just. If I would continue. I will not finish.

Speaker A: Yeah, yeah. Ever evolving complexities. I'm very glad to hear you say that saving passwords in the browser is not a good idea because I don't do that and all my friends think I'm really paranoid for not doing it. So I'm going to see that. I'm on the right there. I'll be showing them this recording. Throughout our conversation so far you've mentioned a lot of potential risks that businesses might face with their security setup in various levels. How do businesses start to identify these risks and potential risks in their architecture?

Speaker B: We can get an example for the airport once they start to do the check in. Ah, the security check in. When a breach happens. This is the same with the business. With the enterprises companies, when a breach happen, they look how to avoid it next time. This is the problem. It doesn't start with okay, I want my system to be very secure from up or down. When they have a problem, they start to invest.

Speaker A: Sure. It's less about identifying potential risks in their current setup and more about mitigating the risks once they happen and working out how that risk is raised and being able to move forward and have that risk corrected. Is that right?

Speaker B: Well you heard about Equifax experience and um, there's a preach happen and data installing attorneys telling, getting this razor case and to just get some compensation. Other companies, okay, how can I be out of this? How to avoid this same case for my data. I have a lot of customers. I don't lose them, I will lose my market share. So if they didn't feel there is a risk, they will not invest. Most of the companies come in to discuss their budget. Why should I invest in uh, this technology which is not my core business. Why should I hire the certified people, the experienced people. Why not to offshore this unit to other third party companies. I'll focus my core business. Most of the companies do this because okay, I spent $1 to get this $10. Why should I invest internally without not get anything from it? But once you come to the reality that there is a breaches, there is a little loss, there is something you can lose your reputation, your market share, your actual business and that time uh, they will change their strategy. Without this nothing will happen.

Speaker A: It's a sad picture but I think you're right. I think that's definitely a pattern I've observed. You know a common piece of I guess wisdom that I hear a lot about security breaches is you know, if a vendor that you use or a company you use has a security breach, you shouldn't take that as a sign to change off of them immediately and to drop their business because the fact they've had one means that they will remedy it and it's now not a problem. And I guess that is kind of speaking to what you're saying here. Right. Would you agree with that statement that you shouldn't initially jump ship?

Speaker B: Any problem is a new business opportunity for us is a lesson. Okay, we have a problem, let's learn from it. How can I avoid it? How it happened, how, uh, we can fix it.

Speaker A: Yeah. So to change gears a little bit, we've been talking a lot about the current industry, how it's evolved, and how people can avoid risks. One of the phrases that I see a lot nowadays as someone who's outside the cybersecurity field is this phrase, zero Trust networking. Can you tell me a little bit about this, what it's about, and for folks who haven't heard that phrase before, what is it?

Speaker B: Zero Trust networking. In a brief for non IT person, I will give you an example. You are working on a company. You have a username and password. You just logged in and you have access to everything. Applying, uh, zero trust environment means yes, you log in, but to access anything, you still need to also request for authentication and authorization. Nothing being inherited by your login. So if you want to log into your hr, you need another credential or another way to log it in, not to use your previous login. So every step, uh, need to be checked to be known that you are who you are and this is your credential. We need to check that you really have access to this.

Speaker A: Interesting. Okay, so that I imagine has various influences on um, how staff are working with the network, how they're working with the resources. From a technical standpoint, how do you as a cloud architect, structure a business's network to provide for that facility?

Speaker B: There are different tools added to the system to apply the Zero Trust environment. Okay, we have multiple environment. You have an elderly store, your identity access. Plus you have third party, um, multi factor authentication and multifactor authentication based on um, what you have, who you are, what do you know. So you maybe have a token. So once the login, I ask you what number you have in your token. If you give them this number, that means you are the guy who has this access, not other, stole this answer from the real one. Or you have a biometric, like your fingerprint, your biometric eyes or Just something related to you. Where did you born, when did you marry, who's your best name? Something that no one else know except you. You enter those information with your credential. That means you are the guy who should access it. But you already entered. There is another layer called shape. This guy locked in and uh, this time from this location is this is a secure location or that's a public location like in a cafe or in the airport. So no, I can plug it. This is one of the layers we use in the Zero trust. Okay, you're trying to access your email. Everyone has its email on the cloud, that's not a problem. But there is a payroll, there is an other business application that ah, need another layer of security. So I couldn't inherit your access and just jump there. No, we need another layer to apply to be sure that you still the guy who want to access and have the right access here and what level of access you have just to watch, to review or, or to add it or to have everything maybe you have a permission to delete. This is a big problem. This is the layers we added to deploy the concept of zero trust.

Speaker A: Okay, amazing. So the next question I had specifically related to zero trust, but I imagine it comes up a lot is as you're setting up these security precautions with a uh, company there is a certain level of juggling and advocacy and trying to balance the friction to the workers with the needed precaut. How do you make the need for this and soften the blow of the friction that it will introduce for the workers and uh, make it clear this is something that needs to be put in place and get through any, you know, concerns about oh, I have to log in extra times and that's annoying to me as an employee. Like how do you manage that balancing act?

Speaker B: We can't have everything. You can't have just one button to click and get access to everything. That is not the right way. So I know adding different layers, a firewall, something called data loss provision, idb, ids, all of them add a latency. Latency means I'm um, login. I'm still waiting a second, 2 seconds, 10 seconds to access, thus frustrating users. You know I'm talking about 1 to 10 to 1000. The latency will increase. But at the end of the day what is important, the security or the fast access? Now uh, you must decide which factor you want to use as uh, a main thing to fix it. So everything comes with a price. So this is a problem. Okay, you have access to everything. Assume this is your last day. What you will do. So this is a big concern for big companies and if you can look for the reports 80% from data breaches or hadn't come from internal data network from the internal company network, not from outside. Someone came to his ah girlfriend or boyfriend and put some device connected to the uh network or the WI fi and keep tracking access and capture this packet so they can uh use it to access it and someone to impersonate another one calling the IT team. Okay, I forgot my password to be resetted. I'm the new CFO uh guide here and be sure okay the username is like this okay Giving them the information he needs. This is the way he can access something couldn't access it. So to apply uh the zero trust it will complicate the process but you be sure data is secure and safe. Like you go to the hospital every time you wait until the nurse can see you check for your blood. It's just like a general which take almost 10 minutes and okay, what should I do every time you check for my temperature, blood pressure, my height, you have any problem, my eyes, uh, I want to go to the doctor immediately to talk about my case getting the m right prescription and go back to work. But following this process can eliminate a lot of things.

Speaker A: That's a great metaphor. I like that a lot. So we've spoken a lot about you know the shift to the cloud and everyone's applications are in the cloud and you've got a million different cloud services going on. For companies that have multiple cloud providers or they might be using a SaaS service that uh, integrates with certain security things and certain ones that don't. Do you have any recommendations for businesses in that situation to make their cloud security consistent or to be able to have uniform guarantees across all their different services?

Speaker B: Actually every cloud service provider has to manage their environment as a public cloud environment, give it to the customer. We know that most of the enterprise customer has more than one public cloud. Some of them has uh a cost saving in storage, has a fast access to the apps hosted on the cloud, has a strong security. So you can have one management tool to manage all these environment plus your on premise data centers. It's one pane of glass that is available every public cloud. The competition is very high. If one cloud provider surface the uh asset must who have it immediately otherwise you will lose the market. So what do you prefer? What is the right approach? Do you use one public cloud or multiple cloud? There is no right or wrong answer because okay, you stuck with one cloud, later on you find you pay a lot of money, you want to get out of this public cloud, you will pay a lot of money to retrieve your data. This is a concern and this is a problem because this is a business at the end of the day. So it's better to have multiple clouds. If there is a failure habit in one of them, you still have access to the others. So you can use one of them as a backup for the other. This is an approach we suggested to our customers. You have one public cloud using for your email for identity, another public cloud to your web apps hosting those apps. Ah, and another one as a backup. This is the right approach.

Speaker A: Perfect.

Speaker B: Cool.

Speaker A: It's great to hear. So on the complete other end of that, for smaller companies who haven't yet got to that level of sophistication, for whom may just be starting their journey into properly budgeting for cybersecurity, what are your tips for them? Getting started the small scrappy startup or just otherwise a small business that hasn't invested in this area yet, how should they get started?

Speaker B: First, define your goals. What do you actually need? What do you need for your business? And you can pick up one of those services on the cloud and start with every small and medium business need to ads for apparel or an application to sell and to buy like uh, coffee shops or just or hosting ads that you can allow, uh, for order online. So hosting apps of the cloud define which user can access it, who can retrieve it, defining your supply chains, your store. So define your goals. What I want from the cloud, should I put everything in the cloud? No, you don't need to do this. But start small and you can expand gradually. The beauty of using the cloud that it gives you this option to expand as you need, not like, okay, I pay for two servers putting in my back end, uh, any store in a room, a very small room to put my servers with my nerd. And I found later, oh, I need another server. Oh, I need another storage to order it. It will take up to six to eight weeks. Now in the cloud it's just in seconds you can expand. So start small, the fund, what do you need exactly? And go from there.

Speaker A: Okay, that makes a lot of sense. So we've spoken earlier in the show about almost the inevitability of something happening and how companies wait until it happens to invest and something is going to happen. That's an accepted fact. You should be ready for it. So on that topic, if the worst does happen and um, you have a security Breach in some way. What should companies do about it? What should they think about as they're investigating that breach and making it known to customers?

Speaker B: First, you must have a backup plan. What I will do if a breach happens, I should have a backup, um, data stored in tapes or another public cloud that I can start my business on that service provider a different place to run my business. A ah, process, you document it and um, follow it. In this case in the cybersecurity you learn about business continuity, disaster recovery. Those are two difference business continuity. What should I do during the failure? Disaster recovery to recover in a different place once a uh, failure happened. So it's two concepts, two different zones. So if a breach happened, I should have this backup plan, plan B, plan C. Without it no one can help you.

Speaker A: Sure, absolutely. Yeah, that makes a lot of sense. And you spoke about the risk earlier uh, on of you know, the incident this happened. What about my market share, et cetera. My perception again being outside the industry, is that a lot of how your clients and your customers take that is down to public response. You know, how fast do they communicate the breach, how do they communicate their resolution, etc. Do you have any tips for that communication part? You know, here's the formal post mortem

Speaker B: I guess really simple. First you must have a backup plan. Second you must to test it, don't wait for a breach. Then you start to check your backup plan. And third, you should have more than one backup plan. Most customers have one production and another area for a doctor. You must test the failover in any time like at weekend whatever and check access to the doctor from bunch of users to be sure the business will be continuous, not to just start uh, oh, we are missed this. We don't have access to this. We didn't pay for that. You should have a backend and you test that your backup um, is working. Not just, I remember 20 years ago there is a government in the Middle east has a big problem. He has a very expensive system that host the data of all people looking for a job. And suddenly the system stopped working and they found later they don't have the right administrator to manage this environment. Second, the last backup they had is six months before it's not reliable. Now we need access to our database. Okay, you don't have the right people, you don't have a backup plan. Uh, the last backup you have six months ago you asked three, four companies to jump in and uh, try to start your database server. That is one not work, your data is lost. That's Dark. Nothing. We can help you. You should have a plan. It's not a uh, good idea of me. I have very expensive server with a big expensive storage and a big expensive network swatches and later on I don't have the right people. I don't have a backup plan to process. The last backup is six or one year and I didn't test it yet. So there is no solution that makes total sense.

Speaker A: Yeah, I can think of a couple of key incidents in the last year with you know, certain Internet sasses which eventually turned out to come down to not testing their backups. I think that's really great advice.

Speaker B: Amazon company in the Middle East. I have a friend that suddenly wake up and uh, get a lot of calls. We have a problem, we couldn't access our server and he found this has been affected with by ransomware. Ransomware, very similar. It's a virus that had attack your set up and encrypt all your data and the guy will come to you, pay to me this amount to give you the key to decrypt it. So if you don't have a backup, you will have to pay him the money that he requested he or she to decrypt your data and allow your business to continue. So this case is very simple. Able to have a firewall, you don't have a right process for people to access, you don't have a vpn. You try to save money, but at the end of the day, once a ransomware attack, you, you lose everything.

Speaker A: Right? That's very concrete advice and actionable advice. So as we're getting towards the end of time here, I want to round out with a couple of questions about how you see the industry changing and how folks can get started. So to start with, what innovations do you think are coming up in the short to midterm, um, that say over the next five years that you're looking forward to in cloud security.

Speaker B: My concern, uh, and one also I consider as an innovator. For me, the AI. AI will be dominant in the upcoming five years. Maybe the downside for it, people will lose their jobs especially which is considered routine jobs like supply chains, hr, uh, people who just do the process of filling papers. All of them will be replaced by AI. The concern I have, it can change the whole world. It can create war because they can fake data, someone can manipulate with it. This is a big concern. I hope companies not to go for the election to rely completely on AI. They must use the human being because with the AI a small error can change the whole Setup and plot you as a right resource to do your business.

Speaker A: Yeah, that is a common answer to that question we're getting at the moment. I think it's top of everyone's mind. Everyone's thinking about the various effects that the current AI moment will have on our industry and on our jobs. And so yeah, from a security perspective, that's very interesting to hear. And on the other hand, so we spoke earlier on about certifications and about the value of showing that you're up to date. How do you stay up to date with everything that's happening in security? Do you have any books, websites, podcasts, people that you find really valuable to stay up to date on the latest developments in your industry?

Speaker B: That's a very good question, very hard to answer. First of all, because I work in a certain area I'm um, subscribed to, my vendors are uh, giving me updates as a podcast for the new services and new technology and new subject in this it. Second, look for the materials to read and uh, practice to keep my search up to date. Third, the projects customer came to us requesting something new. Now we are talking about data center. How can I protect the data center? That's what we talk about the 25 years ago now. Oh, the concept of virtualization, very good. I can utilize more servers on one physical. We need to virtualize our data center. How to do this virtualization? How to keep the virtual environment secure and expanded. Now we move to the cloud. The cloud is a big project. People go out of the local uh, data center, paying for renting electricity, calling now, moving everything to the cloud, getting Apple this hardware. I focus on my core business and my ads. Third. Oh, every country and every continent has a different compliance. How can I be compliant with that? Otherwise I will lose my market. After that we get new terms. Government cloud, sovereign cloud, data encryption, data masking, data tokenization, Everything coming to, to the market as a request from customer, as a broadcast, as a uh, post in the LinkedIn and other bloggers. You blog, you read, you just get for the right resource, you learn. It's not an easy way, it's a very tough way. But this is the process I use day to day.

Speaker A: Yeah, I think it's a great process, especially the trying and finding projects around what you want to keep up to date with. I think that's a great recommendation. Well, thank you so much Mohammed. This has been super illuminating for me and I hope for our listeners. Thank you for joining us today.

Speaker B: Thank you.

Speaker A: Beyond the Screen, an Ionis podcast to find out more about Ionis and how we're the go to source for cutting edge solutions in web development. Visit ionus.com and then make sure to search for Ionos in Apple Podcasts, Spotify and Google Podcasts or anywhere else podcasts are found. Don't forget to click subscribe so you don't miss any future episode episodes. On behalf of the team here at Ionis, thanks for listening.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 115: Rethinking AI Governance for Enterprise Adoption with Dr. Markus SchmidbergerUsing AI at Work · on AWS92 / 100
  • He quit Stripe and hit $10M ARR in 4 years - with $0 marketing spend. | Anurag Goel, Founder of RenderA Product Market Fit Show · on AWS89 / 100
  • 323 - David Yanacek on 20 Years of Innovation at AWSCode with Jason · on AWS80 / 100
  • Enterprise Software Buyers Now Demand a Vendor AI Training Data Provenance AuditB2B SaaS Talks with Fexingo · on GDPR80 / 100
  • Why AI Agents Are a Security Wild West with David from Arcjet and Johannes from CakewalkThis Much I Know · on identity and access management (IAM)77 / 100
  • When AI Starts Writing the Pull Requests with Madelyn OlsonScreaming in the Cloud · on AWS77 / 100

More from Beyond the Screen

All episodes →
  • The Uncanny Valley Phenomenon: The Impact of AI on Human Behavior47 / 100
  • Preventing Security Breaches: Strategies for Effective Threat Detection and Prevention60 / 100
  • Revolutionizing Talent Acquisition with Seamless Workflows and User Experience53 / 100
  • The Evolution and Impact of AI and Machine Learning Across Industries79 / 100
  • Exploring the Role of Cloud-Based Systems in Climate Change
All Beyond the Screen episodes →