

Scale to Zero - No Security Questions Left Unanswered
Scale To Zero
We know security is challenging, but a timely understanding of security is far more challenging! Scale to Zero is built for all the security professionals for helping them to be more privacy and security-sensitive. With this show, we hope to address all the security-related issues that are challenging to understand and resolve without the help of experts. We believed that a community space like Scale to Zero would make things a little bit simpler for everyone after we discovered the discomfort of constantly switching back and forth.
Episodes
Mentioned books

Apr 8, 2026 • 49min
IAM in 2026: From Anti-Patterns to Autonomous AI Agents | ft. Advait Patel | ScaleToZero Podcast | Ep. 108 | Cloudanix
Cloud infrastructure is moving faster than ever, but is your security keeping up? We sit down with a Senior Site Reliability Engineer to discuss the evolution of Infrastructure Security and Compliance in 2026. Whether you're an SRE, Security Engineer, or DevOps Lead, this episode will challenge how you think about "secure" infrastructure.Transcript: https://www.scaletozero.com/episodes/iam-in-2026-from-anti-patterns-to-autonomous-ai-agents-with-advait-patel/Advait Patel: https://www.linkedin.com/in/advaitpatel93/Powered by: https://cloudanix.comAlso Available on our YouTube Channel: https://youtu.be/1dchqWnt1hAKey Discussion Points are as Follows:00:00 Introduction07:40 Real-world Challenges of Infrastructure Security and Compliance11:20 Automating Security Checks and Avoiding Bottlenecks13:25 Security Impact of IAM Implementation17:28 Architecting an IAM Program in 202619:38 KPIs to Measure the Effectiveness of Security Implementations22:48 Measuring the Decision Quality25:12 Most Common IAM Anti-Patterns29:40 AI Agents for Automated Root Cause Analysis of IAM Failures33:27 Will AI Agents go Fully Autonomous?35:40 Using AI to Bypass IAM Security39:14 Cloud Security Trend From 2012 Should Die42:33 Future of AI Cloud Security44:14 Summary45:24 Learning Recommendations

Mar 25, 2026 • 45min
AI Security: Hype vs. Reality and the Roadmap to CISO | Ft. Niyati Daftary | Ep. 107 | ScaleToZero Podcast | Powered by Cloudanix
Is the security impact of AI being underrated, or are we worrying about the wrong risks? In this episode, we sit down with a Security Analyst to bridge the gap between high-level security consulting and the deep-trench reality of day-to-day defense.#Cybersecurity #SecurityAnalyst #CISO #AISecurity #SecurityResearch #Infosec #CareerRoadmap #SecurityLeadership #TechPodcast #ScaleToZeroPowered by Cloudanix: https://www.cloudanix.comYouTube: https://www.youtube.com/@cloudanix00:00 Introduction04:55 AI Security Risks Organizations are Worried09:00 Security Impact of AI - Underrated?11:33 Challenges of Security Leaders18:00 Cybersecurity Perspective of a Consultant vs. Analyst22:10 Beliefs vs. Reality in Security Practices23:53 Development of a Security Research Document31:40 Challenges of Leaders Implementing Security Research Notes36:22 Roadmap for Aspiring CISOs and Security Leaders42:22 Learning Recommendations

Mar 11, 2026 • 48min
Product Security at Scale: Minimizing Friction & Defending AI Integrations | ft. Sana Talwar | Ep.106 | ScaleToZero Podcast
In this episode of ScaleToZero Podcast, we sit down with a Product Security Engineer to discuss the delicate balance between robust security, user experience, and developer velocity.From identifying red flags in security reviews to using AI for point-in-time vulnerability assessments, we cover the tactical moves that early security teams need to make today.The landscape is shifting from "Security vs. Engineering" to "Security + Engineering." If you're an early security team looking to leverage AI to punch above your weight class, this episode is a must-listen.YouTube: https://youtu.be/wv_1NZkv9bsCloudanix: https://www.cloudanix.com00:00 Introduction03:40 Developer-friendly Security in Practice07:22 Minimizing Friction between Security and Engineering09:15 Navigating the Trade-offs between Security and User Experience11:32 Red Flags in Third-Party Security Reviews and Internal Security Reviews19:00 Point-in-Time Vulnerability Assessments using AI21:35 Managing Malicious Updates without Manual Reviews24:55 Communicating Third-Party Security Risks to a Product Manager28:50 Improving Product Security using AI for Early Security Teams33:20 AI Performing Critical Security Job Functions35:27 Patching AI Prompt Injection Attacks41:05 AI Integration and Reshaping Security Landscape46:04 Summary#ProductSecurity #DevSecOps #AppSec #Cybersecurity #AISecurity #ProductManagement #DeveloperVelocity #TechLeadership #ScaleToZero

Feb 25, 2026 • 49min
eBPF, MCP Servers, and the Kernel-Level Future of AI Security | ft. Ammar Ekbote | Ep. 105 | ScaleToZero Podcast
In this episode, we sit down with a veteran Security and Cloud Infra Leader to deconstruct the architecture of modern workload monitoring and the emerging risks of AI-driven connectivity. We dive deep into eBPF—the technology providing "invisible" observability—and the security implications of MCP (Model Context Protocol) servers in the enterprise.Whether you're an infra lead or a security engineer, this episode provides the technical depth to help you stay ahead of the curve.Also available on YouTube: https://youtu.be/iCfEJlgXFBU00:00 Teaser and Introduction04:12 Architectural differences between Agentless and Agent-based scanning07:50 Losing security signals in case of Agentless scanning09:23 Challenges of Agent-based scanning10:45 Vendor checklist for production release11:45 Noisy neighbour challenge and customer application14:52 Securing large agent-based vendor machines16:40 Use of eBPF for invisible workload monitoring19:17 Securing the eBPF21:00 Does eBPF solve the stability and performance risks?23:25 Security risks when LLMs use MCP servers27:16 Detect and Avoid MCP in an organizational environment32:32 Why use eBPF for security MCP?35:10 Using eBPF to run local servers in a secure way37:00 Can eBPF secure data leaks to AI models?41:19 Justifying stakeholders for using kernel-level security43:25 Evangelizing a security-first mindset44:50 Starting point for developer-led security using eBPF46:30 Learning recommendations47:10 Summary#eBPF #CloudSecurity #AISecurity #MCPServer #DevSecOps #AgentlessScanning #CloudInfrastructure #InfoSec #CybersecurityPodcast #LLMSecurity #KernelSecurity

Feb 4, 2026 • 1h 9min
The Last9 Story: Scaling Engineering, GTM Strategy, and the Reality of "Overnight Success | Ep.104 | ScaleToZero Podcast | Ft. Nishant Modak | Cloudanix
What does it take to build a company that redefines how we look at engineering reliability? In this episode, we sit down with the Founder of Last9 to peel back the curtain on the journey from a single "Aha!" moment to a scaling enterprise.We move beyond the pitch deck to discuss the raw reality of building a startup, the mental models for engineering leadership, and what Vision 2026 looks like in the age of GenAI.Transcript: https://www.scaletozero.com/episodes/the-last9-story-scaling-engineering-gtm-strategy-and-the-reality-of-overnight-success/Cloudanix: https://cloudanix.com/YouTube: https://youtu.be/a955CYXLRdg00:00 Introduction of Nishant Modak03:00 Birth of Last906:40 The "Aha" moment13:00 How is Last9 different?19:10 Building blocks of Last924:20 The Moments of Overnight Success33:05 Go To Market Strategy41:40 Mental Model to Separate Administration and Engineering46:00 Engineering vs Selling49:40 Hard things of hard things, which gave results over time55:00 Vision 2026 with GenAI58:04 KPIs that helped in scaling01:01:25 Personal learnings and life#StartupStory #FounderJourney #EngineeringLeadership #Last9 #GTMStrategy #Entrepreneurship #SRE #Reliability #GenAI2026 #ScalingStartups #techpodcast

Jan 14, 2026 • 49min
AWS vs. GCP IAM Architecture & The Future of Security in 2026 | ft. Senior Security Engineer (CISSP) - Sneha Malshetti
This episode is a masterclass in modern cloud architecture and the fast-evolving world of AI security. In episode 103, we sat down with a Senior Security Engineer (CISSP) to break down the architectural nuances of AWS vs. GCP IAM and how security roles are evolving in 2026. From mastering cross-account access to defining data perimeters for AI training models, this episode is a deep dive into the technical and strategic layers of cloud-native security.YouTube: https://youtu.be/Y_OCpI8LJb4Transcript: https://www.scaletozero.com/episodes/aws-vs-gcp-iam-architecture-the-future-of-security-in-2026-with-sneha-malshetti-cissp/Sneha Malshetti: https://www.linkedin.com/in/sneha-malshetti/Fearless Organization: https://www.amazon.in/Fearless-Organization-Psychological-Workplace-Innovation/dp/1119477247TLSHandshake Deep Dive and decryption with Wireshark: https://www.youtube.com/watch?v=25_ftpJ-2MECloudanix: https://cloudanix.com/00:00 Introduction04:30 Architectural differences between AWS and GCP IAM08:40 Best practices to approach IAM in AWS and GCP11:00 Achieving centralized identity federation for a consistent user experience13:45 Manage cross-account access securely in AWS vs GCP14:40 Balancing RBAC for large organizations18:00 Automation and Auditing recommendations for IAM21:42 Managing access for large organizations23:55 Monitoring Privileged Access27:20 Balancing Security and Speed30:19 Data Perimeter boundaries and their importance34:20 How have security functions transformed in the AI world?36:55 Will AI replace Humans?38:15 Managing sensitive data used to train AI models42:42 Security Trends in 202645:48 Summary46:48 Learning Recommendation

Nov 26, 2025 • 53min
Zero Trust AI & Human Risk | Senior Director of Security | Ft. James Cash | Ep. 102 | ScaleToZero Podcast | Cloudanix
What are the security weaknesses that everyone overlooks, and how is the rise of AI changing the risk calculus? We sat down with a Senior Director of Security and Compliance to discuss strategic defense, from securing human capital to implementing Zero Trust for AI systems.This episode is essential for CISOs, security leaders, and compliance officers navigating the volatile landscape of modern risk.How does AI work: https://blog.hubspot.com/marketing/how-does-ai-workYouTube: https://youtu.be/feudnGhDZ78Transcript:https://www.scaletozero.com/episodes/zero-trust-ai-human-risk-a-guide-to-future-proofing-security-with-james-cash/00:00 Introduction05:08 Significant security weaknesses often overlooked10:25 AI SBOMs and Security14:10 Biggest risks in security from AI systems16:31 Ensuring AI systems are secure and responsible20:55 Zero Trust AI Systems for Internal and Third-Party Teams24:20 Evolution of Risks with Rise in AI27:15 Evaluating between Traditional vs. AI SaaS provider33:50 Keeping Stakeholders' interests in Security39:21 Responding to Insider Threats45:45 KPIs for Human Risk Management49:41 Summary50:51 Learning recommendations

Nov 12, 2025 • 52min
Beyond Tech: Culture and Mindset of Security Engineering | Ft. Dakota Riley | Ep.101 | Cloudanix
In modern, fast-moving organizations, security is a shared responsibility, not a silo. We sat down with a Staff Security Engineer who operates at the intersection of development speed and security integrity to explore what truly defines a strong security program.This episode offers essential advice for leadership, engineers, and recruiters, covering everything from core culture to the risks of new AI models.Also available on YouTube: https://youtu.be/2ut2GQPWA4I00:00 Introduction05:41 CyberArk Acquisition07:40 Top 3 Elements of Building a Strong Security Culture10:50 Good Engineering is Security Engineering13:20 Why do organizations face challenges in achieving a security culture?16:54 Moving Fast - Startups vs. Large Enterprises19:08 Addressing challenges - Startups vs. Large Scale Companies23:00 KPIs to Show Security Progress26:16 Security Teams as Enablers32:57 Right Mindset for Security Engineering36:36 Hiring the Right Security Talent38:31 Addressing Non-Deterministic Nature of LLMs43:13 Trade-Offs of Implementing Bias in Alert Triaging Systems46:11 Training an Agent for Catching Malicious Attacks48:35 Summary49:35 Learning Recommendations

11 snips
Oct 29, 2025 • 55min
Kubernetes Security Mastery: Shifting Mindsets for Ephemeral Environments | Ep.100 | Ft. Dinis Cruz
Dinis Cruz, a seasoned security leader and founder of Cyber Boardroom, dives into the transformative world of Kubernetes security. He discusses the essential shift from static data centers to ephemeral environments and emphasizes the need for engineering mindsets in security teams. Dinis highlights the challenges of balancing security with business priorities, effective logging for containers, and managing identity in this dynamic landscape. He also explores the impact of generative AI on security roles and the necessity of anticipating AI-driven attacks. A must-listen for cloud-native practitioners!

Oct 15, 2025 • 1h 42min
A PSA's Journey - Bridge Between Business and Technology at AWS | Ft. Lalit Khatter | ScaleToZero Business
Have you ever wondered what it takes to drive successful partnerships in the AWS ecosystem? In this episode, we sit down with Lalit Khatter, a Senior AWS Partner Solution Architect, who gives us a deep dive into his dynamic role and the strategies that help AWS Partners thrive.Lalit shares his journey from Software Engineer to PSA and reveals the essential traits of a successful AWS Partner.Whether you're an aspiring PSA, a business leader at an AWS Partner, or simply curious about the engine that drives cloud adoption, this podcast offers unparalleled insights!00:00 Teaser and Introduction03:57 Role of a Partner Solution Architect and their day-to-day08:15 Why Partner Solution Architect as a job role?19:52 Transition from software engineer to AWS PSA23:22 How would a SI company work with Lalit for partnering with AWS?31:04 Trait of a successful partner38:40 AWS programs that help partners get visibility to prospective customers41:58 Aha moment after getting started with the AWS partner environment48:08 Scaling with AWS Marketplace01:03:05 Amazon Pace and Ambassador Program: Hand-in-Hand01:06:23 AWS Ambassador Program and how to invest in it01:10:20 Business Outcome Accelerator (AWS BOX)01:22:53 Weekends of Lalit Khatter01:28:40 Next 5 years of AWS Partner programs01:33:01 Stuff about Lalit


