Why Siloed Security Fails in the Cloud: A New Horizontal Approach

Why Siloed Security Fails in the Cloud: A New Horizontal Approach

🎙 Cloud Security Podcast 👥 39K 📅 September 25, 2025 ⏱ 45 min 👁 7K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

cloud securitysiloedhorizontalattack pathexposure managementDevSecOpsthreat intelligencegamificationautomationCSPM

Summary

In this episode of the Cloud Security Podcast, hosts Ashish Rajan and Shilpi Bhattacharjee are joined by Micki Boland from Check Point and Eyal Golombek from Wiz to discuss the limitations of traditional siloed security approaches in cloud environments. The conversation begins with introductions and definitions of cloud security in 2025, emphasizing the accelerated pace and complexity brought by AI and multi-cloud adoption. The main thesis is that security teams often operate in vertical silos—vulnerability management, data security, identity—without understanding how these domains interconnect, creating blind spots. The guests advocate for a horizontal approach that considers the full attack path, thinking like an attacker to see how vulnerabilities, misconfigurations, and identity issues combine. They discuss practical strategies such as shifting left and right, integrating security into the development lifecycle, and using gamification to engage developers. The episode also covers the importance of connecting external threat intelligence with internal posture, the feedback loop between incident response and exposure management, and the cultural challenges of moving from on-premises to cloud mindsets. The guests highlight the psychological barriers to automation and the shift from posture management to exposure management. They conclude by discussing the partnership between Wiz and Check Point to expand the security graph and the need to democratize security across organizations.

210 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information lies in its practical insights from industry veterans who have direct experience with cloud security challenges. The guests provide concrete examples of how siloed structures fail, such as the disconnect between vulnerability management and identity teams, and offer actionable advice like using gamification to involve developers. The argumentation is coherent and persuasive, building a case for a horizontal security approach by illustrating real-world attack paths and the need for integration. However, the discussion is largely anecdotal and lacks empirical evidence or case studies with specific metrics. The arguments are based on professional experience and industry trends, which adds credibility but also introduces potential bias due to the speakers’ affiliations with security vendors. The reasoning is logical and aligns with current best practices, but it could be strengthened by referencing specific research or data.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate; the discussion is not based on formal research but on expert opinion and industry observations. The sources cited are limited to the podcast’s own website and social media, with no external references to academic papers or industry reports. The title accurately reflects the content, focusing on the failure of siloed security and the need for a horizontal approach. The episode does not present any original research or data, but it does reference concepts like exposure management and threat intelligence that are well-established in the industry. The lack of citations reduces the overall rigor, but the practical insights from experienced professionals provide some value. No user comments were provided for analysis.

268 words

Title / Content Match

The title accurately reflects the core theme of the episode: the failure of siloed security approaches in cloud environments and the need for a horizontal, integrated perspective.

Quality & Reliability

7/10

The discussion features two experienced security professionals from major vendors (Check Point and Wiz) sharing practical insights and industry observations. However, the content is largely anecdotal and promotional, lacking rigorous scientific evidence or citations. The arguments are coherent and align with current industry trends, but the reliability is moderate due to the absence of verifiable data and potential bias from vendor affiliations.

Chapters

Cited Sources

Concurring Sources

Contribution & Novelties

The episode provides a clear articulation of the ‘horizontal attack path’ concept, emphasizing the interconnectedness of vulnerabilities, identities, and data in cloud environments. It offers practical advice on integrating security into development processes and using gamification to foster developer engagement. The discussion on the psychological barriers to automation and the shift from posture to exposure management adds depth to the conversation.

Pour aller plus loin :

  • Exposure Management — Provides a general overview of the concept, relevant to the shift discussed.
  • DevSecOps — Explains the integration of security into DevOps, aligning with the episode’s emphasis on collaboration.
  • Cloud Security Posture Management (CSPM) — Related to the tools and practices mentioned for posture management.

113 words

Radar Profile

The radar profile shows balanced scores across quantity, quality, technical level, and reliability, with a slight emphasis on quantity and quality. This indicates a well-rounded discussion that provides substantial information with moderate technical depth and reliability, typical of an expert opinion podcast.

Reliability 6/10