Security News

Cybersecurity news aggregator

INFO News SC Media

Attack Surface Management - Matt Lea - CSP #227

  • What: Discussion on attack surface management and cloud security risks
  • Impact: Organizations need to address cloud misconfigurations and security gaps
Read Full Article →

Subscribe Share Full episode and show notes Attack surface management Attack Surface Management – Matt Lea – CSP #227 In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk. Matt shares lessons from his experience auditing cloud environments, including common AWS security gaps around identity and access management, exposed resources, security groups, and overly permissive access. The conversation also covers emerging challenges around AI agents, protecting production data, and balancing speed of innovation with security controls. From preventing cloud breaches to building stronger security practices, Matt breaks down what organizations should understand about reducing risk... August 10, 2026 This episode is sponsored by Full Segment Notes In this episode of CISO Stories, Jessica Hoffman sits down with Matt Lee to explore attack surface management, AWS security, and the cloud misconfigurations that can put organizations at risk. Matt shares lessons from his experience auditing cloud environments, including common AWS security gaps around identity and access management, exposed resources, security groups, and overly permissive access. The conversation also covers emerging challenges around AI agents, protecting production data, and balancing speed of innovation with security controls. From preventing cloud breaches to building stronger security practices, Matt breaks down what organizations should understand about reducing risk in today’s evolving threat landscape. Segment Resources: https://schematical.com/techdebt https://www.oreilly.com/videos/zero-to-hero/0642572107789/ https://schematical.com/posts https://schematical.com/free https://schematical.com/speaking This segment is sponsored by Horizon3. Visit https://cisostoriespodcast.com/horizon3 to learn more about them! Guest Matt Lea Founder at Schematical Matt Lea is the founder and driving force behind Schematical, a consultancy dedicated to helping CTOs and engineering teams build scalable, secure, and cost-efficient cloud infrastructure on Amazon Web Services (AWS). With over 15 years of experience in cloud architecture and DevOps, Matt specializes in transforming complex cloud challenges into robust, manageable systems. By taking ownership of long-term reliability, architecture, and cost optimization, he allows development teams to step away from infrastructure management and stay laser-focused on product innovation. Beyond his consulting work, Matt is a passionate educator and creator. He is the founder of Cloud War Game, a live incident response simulation platform and the creator of the Zero to Hero on AWS Security animated course. His current passion project is Tech Debt, a rogue-lite base-builder strategy game where players must research tech, level up their engineering team, and keep servers running while fending off real-world cyberattacks like XSS, SQL injections, and DDoS. Whether through consulting, speaking engagements, or game design, Matt empowers technical leaders to ensure their systems are fast, secure, and ready to scale. Host Jessica Hoffman Show More Stay in the Know, No Smoke and Mirrors – Join Our Newsletter Get expert insights and technical breakdowns straight to your inbox. Join Now Related Segments Vulnerability Management Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting – Braden Russell – BH26 #2 Application security Model, harness, gym: why Novee owns the full AI pentesting stack – Ido Geffen – BH26 #1 Vulnerability Management AI Pentesting and the Future of Cybersecurity – Chris Wallis – BH26 #1 Related Content Penetration Testing Bugcrowd brings continuous agentic pentesting to web apps and APIs with Savant Pathseeker Attack surface management What Attack Surface Management Actually Controls Attack surface management How to Build an Attack Surface Management Operating Model You can skip this ad in 5 seconds

Share this article