Defense in Depth Cloud Native Day 2019 - Illustration of a layered security approach for cloud native applications, emphasizing multiple security controls at different levels to protect against various threats. Layers include network security, workload security, data security, and identity and access management.

DEFENSE IN DEPTH: CLOUD NATIVE DAY 2019 TALK


Defense in Depth. As a philosophy it means “Don’t put all your eggs in one basket”. Assume that each layer of your system can be (or has been) breached, keep slowing the attacker. Be less attractive than others who might be attacked.

I presented on this topic with respect to Cloud Native (and various CNCF tools) at Cloud Native Day Montreal. See the presentation online below (or linked here). In it I go through some common myths, things to watch out for, and things that we are doing that are lazy and dangerous.