
Hosted by TechRiot.io
Learn Cloud Security in Public Cloud and for AI systems, the unbiased way from CyberSecurity Experts solving challenges at Cloud Scale. We are honest because we are not owned by Cloud Service Provider like AWS, Azure or Google Cloud.
352 episodes · publishes weekly · latest 2026-06-23 · ~43 min/episode
Rank
#335
Substance
78.0
/ 100
Breakdown
Scored 2026-07
Updated monthly
Across the index
#335 of 6182
Substance
Top 5%
outscores 95% of the index
Cloud Security Podcast ranks #335 on The B2B Podcast Index with a substance score of 78.0 out of 100, scored across 1 recent episode. It scores highest on guest caliber and insight density. Simon Biggs is a genuine hands-on practitioner with 15 years in forensics and IR, a law enforcement background as a detective sergeant on an organized crime team, and time at NCC Group - he has clearly worked hundreds of real breaches. The episode is sponsored by his current employer Varonis, which introduces some vendor framing, but his operational knowledge is evident throughout.
Averaged across 1 recently scored episode, with cited evidence.
The episode contains a solid cluster of practitioner insights - the shift from encryption-first to data-first ransomware, automated Microsoft Graph queries seconds after token theft, and AI enabling bedroom researchers to get proof-of-concept exploits - but is padded with well-worn points about logging maturity, data classification importance, and AI lowering barriers that circulate widely in security circles.
“We're seeing queries coming in seconds after that token's been stolen. There's more people doing attacks and achieving outcomes without the requisite skill set that they needed”
“Five years ago, attacks predominantly used to be encryption first. Now is data first. Practically no encryption”
The framing of AI as an accelerant rather than a revolution is a measured and honest take, and the shift to data-first ransomware is a useful reframe, but most of the episode confirms conventional wisdom rather than challenging it - the Metasploit analogy is apt but well-worn, and recommendations (log everything, classify data, run tabletops) are standard IR doctrine.
“I don't think it's so much a revolution in terms of it's doing things that were just impossible. I think it's accelerating that process”
“somebody could get that in their bedroom if they can afford the tokens that's on the table. I think that's a bit of a sea change”
Simon Biggs is a genuine hands-on practitioner with 15 years in forensics and IR, a law enforcement background as a detective sergeant on an organized crime team, and time at NCC Group - he has clearly worked hundreds of real breaches. The episode is sponsored by his current employer Varonis, which introduces some vendor framing, but his operational knowledge is evident throughout.
“I've been in that space for about 15 years and started off doing cyber law enforcement. I was in the police. I, uh, finished as a detective sergeant on the regional organized crime team dealing with cybercrime”
“dealt with hundreds of breaches all the way up from business email to nation state and government agencies”
There are genuinely specific practitioner details - SQL schema queries materialising in minutes, Graph API calls arriving seconds post-token-theft, S3 access logs being off by default, 72-hour contractual notification windows - but the episode is light on named breaches, precise statistics, or published research citations beyond a vague Copilot prompt-injection mention.
“we're seeing pretty much all the groups. They will go after maybe your SQL databases, they'll be taking a schema, they'll be coming back and they'll be doing a really crafted query within minutes”
“S3 storage access logs on, um, on by default... the amount of people that are shocked when we say that there, there is nothing that will tell you what access that data”
The host asks some genuinely useful follow-ups - pressing for a concrete speed example, introducing the Metasploit analogy to sharpen the point, and synthesising a summary checklist at the end - but also asks long compound questions, lets vendor claims go unchallenged, and relies on affirmations like 'awesome' and 'wow' rather than productive pushback.
“when you say they're getting faster, what's an example of something that was, I guess probably a similar attack before, but now seems a lot more different with AI?”
“Is there a huge volume of security? AI attacks.”
First period on the Index - history builds from here.
1 scored on substance · 60 tracked in total.
Add this badge to your site - it links back here and updates automatically as you rank.
<a href="https://index.fame.so/show/cloud-security-podcast" target="_blank" rel="noopener">
<img src="https://index.fame.so/badge/cloud-security-podcast/badge.svg" alt="Ranked #44 on The B2B Podcast Index" width="360" height="136" />
</a>Track Cloud Security Podcast's rank
Get an email whenever this show moves up or down the Index. Monthly at most, no spam.
The themes that come up most across this show's episodes.
Podcasts that dig into the same topics.