❌

Vue lecture

Strengthen your CI/CD pipeline with new Secure Source Manager capabilities

A resilient software supply chain is the foundation of modern delivery, and securing your continuous integration and continuous delivery (CI/CD) pipeline is what keeps innovation moving safely.

Notable supply chain attacks more than doubled in the first half of 2026 compared to the second half of 2025, according to Wiz’s recent Cloud Threat Highlights report. 

It’s crucial that your source code not be the weakest link in your private cloud. To help you better address software supply chain threats, Google Cloud Secure Source Manager (SSM) lets you manage your source and CI/CD systems with unified authentication and authorization mechanisms. 

We now offer two new capabilities, both generally available, that can simplify and secure your development and CI/CD workflows:  

  1. Unauthorized access to CI/CD systems: Attackers only need to alter a single deployment script to turn your CI/CD pipeline into a vehicle for malware. To help mitigate this risk, from the version control system to the build and artifact systems, to deployment tools, SSM can now block unauthorized access to your CI/CD systems even if your corporate network has been compromised.

  2. Unauthorized changes to code by authorized users: The new Code Owners system manages pull request approver sets at a per-file and per-branch level to help provide more granular identity and access management (IAM). Code Owners helps engineers who need to write, edit, and review code. It adds additional guards to files and directories in your repository at a per-file or per-branch level.

Key capabilities

Beginning with source code changes to your CI/CD pipeline, the new code owners feature gives you granular merge guards: Check in CODEOWNERS files to your repository to specify required approvers highly granularly:

  • Per-path approver sets: Using flexible glob-style path specifiers, you can require that changes to matching files be approved by one or more of given sets of users.

  • Branch-specific governance: Manage security and deployment rules across branches without friction. You can define different owners for main or dev in the same file, eliminating the merge conflicts that occur with existing CODEOWNERS solutions. See our documentation for more details. 

  • Nestable multi-file ownership: You aren't limited to one giant, 5,000-line root file. You can nest CODEOWNERS files in sub-directories. SSM uses a "more local wins" logic, allowing sub-teams to own their folders while the root admin maintains veto power over the entire repo.

  • Independent approval sections: Using the [SectionName][count] syntax (e.g., [Security Team][2]), a single pull request (PR) can require independent sign-offs from multiple departments. A PR might be reviewed by a peer, but it won't merge until two members of the security team also approve.

With your source code ready, SSM’s new Developer Connect integration makes it easy to connect your CI/CD system and runtimes securely, even when they are in different private networks.

The private CI/CD blueprint architecture follows a secure path: Secure Source Manager connects to Private Service Connect, which connects to Cloud Build. The repository, the build pools, and the artifact storage all reside in a private network, with VPC Service Controls (VPC-SC) providing defense-in-depth to limit access to proxy endpoints.

Next steps

To secure your network, follow our new Private Network Integrations guide to connect SSM to Cloud Build with Developer Connect. 

To secure your pull request approvals, create a root CODEOWNERS file to replace blunt IAM "Approver" roles with file-specific ownership.

  •  

Changing the game: Using agentic AI to secure infrastructure code

AI is accelerating software development at an unprecedented pace. But as code generation scales, so do the challenges of securing the code, especially emerging AI-based vulnerability exploitations. To meet these challenges, the Google AI and Infrastructure team is transforming how we approach security. In this article, we discuss new AI-native agentic methods that we’ve developed that systematically embed high-precision, pervasive vulnerability scanning and patching directly into Google’s software development lifecycle. By continuously scanning every code change across hundreds of millions of lines of code that we deploy onto our infrastructure, we are preventing hundreds of vulnerabilities per month from ever reaching our code base or production, defending our global network, AI infrastructure and our users. 

Solution architecture and implementation

image1

Pervasive pre-submit agentic scanning: security as part of ongoing software development

Traditionally, the technology industry relies on large one-off security scans that are slow and lack sufficient context. As a result, they often find vulnerabilities too late. Our approach instead focuses on pre-submit scanning, where we evaluate each code check-in (across every layer of the stack) in real-time using AI agents. By integrating the pre-submit scan into the tools developers already use, security becomes a continuous routine process, similar to rule checkers, readability reviews or other software development tools. Also, from an AI perspective, scanning each individual code change requires much less context than performing a large one-off scan, significantly improving the scan’s effectiveness. 

The importance of localized threat models

For this initiative, we evolved Mantis, our open-source multi-agent review harness, to increase the precision of our security agents by matching them with a cohort of robust localized threat models. Rather than relying on static decoupled documents, the threat models use live codebase metadata. The scanning agent improves its accuracy further using a dependence call graph across packages and libraries to expand and refine its threat model context. Making threat models part of our ongoing vulnerability scanning encourages developers to continuously update threats and dependencies, keeping the models up-to-date. Using localized and precise threat model data translates to dramatic accuracy improvements, bringing our false-positive rates down to 3% in some cases.

Specialized triage agents speed up development

Vulnerability scanning as part of code check-in requires it to respond quickly to the developer or agents generating the code, so as not to impede engineering productivity. To get responses with low latency, we run a two-step validation process. First, we run a quick lightweight scan that validates its findings against a specialized triage agent. This agent programmatically checks the actual structure of the code (using abstract syntax tree parsing, call-graph traversal, and pre-indexed domain safety rules) to prove that the vulnerable path is actually reachable by an attacker. This agent gets over 92% precision and completes its work in less than a minute. Then, a post-submit scan as part of nightly integration testing serves as a second layer of defense, using off-peak cycles to test for vulnerabilities that may have been introduced across multiple changes. 

Bug fix agents close the loop

Finding vulnerabilities is only half the battle. The last component of our solution is an automated bug-fix agent that uses the scan results and generated proofs (snippet of code that demonstrates how the vulnerability is exercised) to autonomously construct precise fixes that are consistent with our internal coding standards. The agent submits the fixes for human review as part of the original change request’s review, further reducing the time between detection and resolution. 

Learnings and call to action 

Embedding continuous scanning directly into the software development lifecycle has been a game changer at Google; its suggestions are widely adopted, and it’s prevented a multitude of vulnerabilities from being introduced into the codebase. But any organization wishing to improve security can adopt a similar AI-native approach, following these principles: 

  1. Keep systems separate: To prevent bias, keep the harnesses, rules, and context for each of your development, scanning, triage agents separate. Pair lightweight AI scans with deterministic, structural validation to drive down latency and improve accuracy. 

  2. Use context wisely: Feed your agents your existing threat models. Precise context is the answer to reducing false positives, and up-to-date threat models set a high floor on a team's security posture by improving the rate of true positives in presubmit scanning.

  3. Build a good harness: While the choice of the underlying model is important, using a multi-agent harness can have substantial impact, by helping compensate for variability in model choice. 

  4. Automate the fix: Use agents to also propose human-in-the-loop fixes, to further reduce time-to-resolution. 

If you want to get started on your own AI-native security transformation, Mantis is now available as open source for you to use and benefit from. You can also learn more about the fundamentals of cybersecurity and the other platforms that power this agentic pipeline: Google Cloud, Gemini Enterprise and Gemini models running on Trillium and Ironwood TPUs. And you can get inspiration from how agentic vulnerability scanning and remediation defends Google Cloud customers as an integral part of Google Cloud’s secure software development lifecycle (SDLC) effort.


With special recognition to critical team members who made this delivery possible: Stella Voutsina (Lead Program Manager), Yulong Zhang (Senior Staff Security Engineer, Mantis), and Nick Galloway (Staff Security Engineer, Mantis).

  •  

Google named a Leader in the External Threat Intelligence Service Forrester Wave™

At Google, we see firsthand how the speed, scale, and sophistication of cyber threats continue to challenge traditional enterprise defenses. Today’s defenders can’t rely on reactive triage or fragmented data feeds; you require high-fidelity intelligence, deep underground visibility, and actionable context to anticipate adversary moves before an attack unfolds.

1-a leader

We are proud to announce that Forrester has named Google a Leader in The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026. In this evaluation, Google received the highest possible score of 5.0 across nine distinct criteria spanning both Current Offering and Strategy.

Organizations trust our decades of threat intelligence expertise to help them understand today’s attacks and to protect against tomorrow’s threats. Google Threat Intelligence operationalizes protection with specialized threat intelligence agents that autonomously conduct multi-step investigations and malware analysis at machine speed. Underpinning these capabilities is the unified visibility provided by Mandiant’s frontline incident response, VirusTotal’s crowdsourced visibility, and Google-scale infrastructure with industry-leading deep and dark web monitoring, illuminating adversary operations where they begin.

2-graph

Google is a Leader in the Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026

Key attributes of a leader

Accurate and relevant deep and dark web monitoring enables proactive security, spotting exposed credentials, threat actor reconnaissance, and illicit forum chatter before they escalate into active attacks. 

We received the highest possible score in the Deep and Dark Web Monitoring and Intelligence Collection Sources criteria. 

As Forrester wrote in the report, “Google is the only vendor in this evaluation that is also a frontier AI model developer and a significant player in quantum computing.” 

Because Google Threat Intelligence has direct access to a leading frontier model rather than an off-the-shelf wrapper, our AI agents don’t just summarize data — they can actively evolve. We fine-tune and stress-test our agents continuously using proprietary Gemini best practices, removing the usage limits and latency typical of third-party layers. 

For security teams, this translates directly to immediate threat context, faster detection updates, and drastically reduced time to resolution. The Forrester report stated, "Google's recent Gemini advancements accelerated the success of many of its Al-enabled functionalities." In addition to our finished intelligence reports, defenders can now use our agent to create custom analysis derived from frontline observations, tailored to their local threat profile and environment.

Google Threat Intelligence agents autonomously conduct campaign attribution and pioneer complex agentic malware analysis. Backed by codified Mandiant tradecraft, dynamic visual workflows, and real-time telemetry that programmatically hardens tool routing and execution, our agentic platform transforms complex threat landscapes into a decisive defender advantage.

Google received the highest scores possible in the Analyst Tradecraft and Services, Attribution and Frameworks Used, and Analyst Experience criteria in the report. This foundation is built by hundreds of dedicated researchers across the Google Threat Intelligence Group (GTIG) in over 30 countries speaking 30 languages. Our rigorous, evidence-based attribution maps directly to MITRE ATT&CK, empowering practitioners through interactive graphs and Gemini-enabled agentic threat intelligence. 

By feeding the newest threat discoveries into detection workflows, these capabilities raise alert quality and take the guesswork out of rule creation across the security stack. Security operations center (SOC) teams and threat hunters can rapidly author resilient rules against novel variants, link suspicious events directly to known actor playbooks, and triage critical alerts with certainty. 

While Google also received a 5/5 score in the partner ecosystem criterion, customers using Google Security Operations can directly leverage Google Threat Intelligence enrichments with agents: 

  • The Triage and Investigation agent autonomously investigates alerts and prioritizes threats. 

  • The Detection Engineering agent automatically finds and fills coverage gaps as they emerge. 

  • The Threat Hunting agent proactively searches your environment for novel attack patterns.

Within the strategy category, Google Threat Intelligence received the highest possible scores in the Roadmap, Partner Ecosystem, and Community criteria, as well as the Intelligence Dissemination criterion in the Current Offering category. 

The Forrester report stated, “Google maintains an open, partner-centric approach that avoids lock-in to the Google SecOps ecosystem and benefits from a strong community presence across the broader Google Cloud Security ecosystem.”

Delivering measurable value for security teams

Google Threat Intelligence delivers a measurable impact on the speed and scale of modern defense. Our customers report identifying 139% more threats proactively and make their CTI teams 46% more efficient. These gains are accelerated by AI-driven summarization and context, and can help you eliminate manual guesswork, act on validated frontline intelligence, and focus on high-value investigations.

By accelerating detection engineering and proactive exposure management, Google Threat Intelligence identifies malicious infrastructure before adversaries can use it in campaigns. This faster defense helps you anticipate their maneuvers and disrupt their attack chains earlier, reducing threat dwell time and risk to your organization.

Empowering defenders everywhere

We are very pleased that Forrester recognized us as a Leader in Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026. We continue to push the boundaries of what is possible in threat research, as an early, leading innovator enhancing malware analysis and dark web monitoring with AI. We continue to deliver the autonomous decision advantage to preemptively neutralize the right threats with the right action and the right context.

To learn more about Google’s position as a Leader, you can access the full Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026 here.


Forrester does not endorse any company, product, brand, or service included in its research publications and does not advise any person to select the products or services of any company or brand based on the ratings included in such publications. Information is based on the best available resources. Opinions reflect judgment at the time and are subject to change. This report is part of a broader collection of Forrester resources, including interactive models, frameworks, tools, data, and access to analyst guidance. For more information, read about Forrester’s objectivity here .

  •  

Cloud CISO Perspectives: How Google monitors AI threats and advances AI defenses

Welcome to the first Cloud CISO Perspectives for September 2026. Today, Sandra Joyce shares the latest details on Google’s visibility into how attackers are using AI, and how we’re using AI to stop them.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7fe6c8ab0250>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

‘Spellcheck for cybersecurity’ and beyond: How Google monitors AI threats and advances AI defenses

By Sandra Joyce, VP, Google Threat Intelligence

Sandra Joyce

Sandra Joyce, VP, Google Threat Intelligence

Anyone operating in security knows that speculation is a major liability during periods of technological disruption. While there is plenty of hype and understandable concern around how threats might use and target AI, a CISO’s AI security strategy has to be anchored in ground truth.

Google operates at a rare intersection as both a frontier AI lab and a security company with a frontline view of global incidents. This dual vantage point allows us to understand how AI is built, and exactly how AI is being targeted in the wild. To provide the operational realities that security and business leaders need in the AI era, Google Threat Intelligence Group (GTIG) recently released our latest AI Threat Tracker.

When we strip away the noise and look at the telemetry, the real threat landscape boils down to three structural shifts that CISOs must address:

  1. AI is reshaping how software is built. 

  2. AI is expanding the attack surface.

  3. AI is enhancing threat capabilities. 

Today, we’re sharing details on Google’s visibility into these three challenges, and our approach for solving them.

Building securely in the AI era 

AI has fundamentally altered software development velocity. Across the industry, autonomous agents and AI workflows now push code into production at unprecedented speed. This creates exciting opportunities for innovation, yet CISOs are faced with the difficult task of mitigating enterprise risk while maintaining business momentum. 

We’re seeing threat actors turn our greatest engineering shortcut against us by contaminating upstream packages that AI assistants are trained to suggest and trust. GTIG believes that malicious contamination of AI-assisted coding practices has been contributing to the significant growth in large-scale, open-source software supply chain compromises we observed in 2025 and early 2026.

The solution to a machine-speed threat landscape isn't slowing developers down — it’s building security natively into the AI pipeline. Part of this process involves in-editor guardrails for developers that create a real-time 'spellcheck for cybersecurity.'

We’re also monitoring adversaries targeting agents. The financially-motivated threat actor TeamPCP (UNC6780) has implemented more than half a dozen methods to exploit AI tools and open-source software development practices, including hijacking AI toolkits, prompt injection, and blinding AI scanners with toxic prompts to obfuscate malicious payloads.

The solution to a machine-speed threat landscape isn't slowing developers down — it’s building security natively into the AI pipeline. Part of this process involves in-editor guardrails for developers that create a real-time “spellcheck for cybersecurity.” 

Just as word processors underline typos without forcing the writer to stop, security controls must sit natively inside the developer’s editor and agentic workflows, instantly flagging poisoned packages, toxic prompts, and misconfigured toolkits. 

Crucially, this can’t stop at the editor. Traditional security suffers from context blindness: Code editors can’t see cloud configurations, delivery pipelines miss runtime exposure, and production teams can’t easily patch root-cause blueprints. 

Bridging this gap requires an integrated code-to-cloud approach — the exact design principle behind platforms like Wiz Code. The underlying approach is to ensure code is continuously verified against live cloud realities before it ships.

When organizations think about AI-driven code analysis, the default assumption is to pick one frontier model and point it at their repository. However, our research and telemetry show that single-model security creates a dangerous monoculture: No single AI model can discover every vulnerability, and threat actors are already testing inputs that can blind specific LLM safety filters and scanners.

To secure this expanding attack surface, CISOs should avoid the trap of managing AI through disconnected silos... The future of cloud and AI defense needs to be built on a unified and dynamic graph that connects your code, your models, your data lineage, and your runtime identities into a single living map.

To solve this, Google takes a deliberate multi-model approach. By orchestrating several foundation models — including Gemini, commercial, and open-source — we cross-validate findings, strip out false positives, remediate code, and identify complex logic flaws that a single model misses. We’re smarter with more than one “brain.”

Securing AI 

Securing the development lifecycle is only half the battle. We also need to prevent adversaries from exploiting AI attack surfaces and weaponizing over-privileged agents. Threat actors are targeting AI workloads with techniques that include: 

  • LLMJacking: Cybercriminals and state-sponsored groups target GPU access to support running their AI models and agentic workflows. In one notable intrusion Mandiant investigated in April, a threat actor gained initial access to a victim’s cloud environment from an exposed personal access token, and used it to deploy unauthorized AI infrastructure and scale high-performance compute resources, leaving the victim to absorb the hardware and platform costs.

  • Targeting of AI data and access: Cybercriminals now recognize that your custom prompts, agent instructions, and fine-tuned models represent high-value crown jewels. In Q2 2026, Mandiant investigated multiple data theft extortion operations where threat actors stole proprietary AI data, including models, skills, prompts, source code, and related research. Demand is also surging for AI account credentials in underground marketplace forums, with some sellers offering steep discounts for consumer accounts at up to 99% off retail prices.

To secure this expanding attack surface, CISOs should avoid the trap of managing AI through disconnected silos. Don’t treat agent access policies, model inventories (AI-BOMs) and shadow AI as separate challenges because these risks are deeply connected. The future of cloud and AI defense needs to be built on a unified and dynamic graph that connects your code, your models, your data lineage, and your runtime identities into a single living map. 

Pioneered by the Wiz Security Graph, this approach serves as the contextual engine for Google AI Threat Defense (AITD) — our broader autonomous security framework that fuses the reasoning power of Gemini and other frontier models, the contextual risk prioritization of Wiz, the code remediation capabilities of CodeMender, and the frontline expertise of Mandiant to stay ahead of AI-driven attacks. Crucially, this context is not siloed; it directly feeds Google Security Operations, ensuring that security operations teams can continuously identify, prioritize, and sever toxic attack paths at machine speed.

Defending against AI threats

Threat actors are rapidly moving beyond simple prompt generation toward fully-automated, multi-agent attack pipelines.

Security in the AI Era

Cyber Defense Summit 2026: Security in the AI era

In one notable intrusion investigated by Mandiant, a financially-motivated actor compromised an organization's cloud infrastructure and deployed an autonomous agent framework. The threat actor used an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours.

We’re also tracking adversaries using AI as an intelligent orchestrator across the entire attack lifecycle. GTIG recently observed a PRC-nexus espionage group experimenting with a tool called CC Switch to cycle across multiple accounts and swap AI models — like Claude, Codex, and Gemini — picking the best model for specific tasks, such as writing exploit scripts and drafting lures. While the underlying hacking tools aren’t new, AI turned what had been a disjointed manual process into a smooth and automated workflow.

To take advantage of your deep context, it’s imperative to shift from manual, human-scale incident response to machine-speed security operations. We can no longer rely on human analysts manually triaging endless backlogs of static alerts.

While these machine-speed attacks sound daunting, defenders actually hold an asymmetric advantage. Even when armed with autonomous AI, an attacker operates from the outside with limited context — probing in the dark, guessing connections, and hoping a compromised credential leads to a useful asset. 

Defenders, on the other hand, possess deep context that attackers don’t have. You know your code, cloud configurations, user identities, deployment realities, and internal architecture better than anyone. When you feed this rich, multi-dimensional internal observability into security models, AI defense becomes inherently faster and more accurate than AI offense.

To take advantage of your deep context, it’s imperative to shift from manual, human-scale incident response to machine-speed security operations. We can no longer rely on human analysts manually triaging endless backlogs of static alerts. 

By codifying our frontline threat intelligence directly into these AI models, these autonomous agents can continuously monitor for, investigate, prioritize, and remediate attacks.

How Google is helping defend the ecosystem 

As adversaries adopt AI, we have a unique opportunity to disrupt them at the source. As a major security and AI provider, we take this responsibility seriously, using multiple levers to stay ahead.

  • Disabling malicious infrastructure. If you use Google tools to facilitate an attack, you lose access to those tools. We proactively disable the projects, accounts, and assets of known bad actors.

  • Hardening our AI models and classifiers. We operate a continuous feedback loop for our AI models. By feeding threat intelligence directly back into product development, our models learn to recognize and refuse malicious requests before an attack can even be generated.

  • Automating vulnerability hunting and patching also disrupt adversaries. We are moving from manual patching to AI-driven hunting. Tools like CodeMender automatically fix critical vulnerabilities in the code itself.

  • Developing advanced defenses and threat models. Our teams at Google DeepMind are building specialized defenses for generative AI — deploying active monitoring across our entire ecosystem to identify misuse in real-time.

Securing the AI era can’t be achieved with the disconnected, manual tools of the past, and you can only defend against an AI-powered threat with an AI-powered defense. To tip the scales back in favor of defenders, we must transition to a continuous, machine-speed model of protection — and at Google, we are committed to building that secure future alongside you.

To learn more about our approach to securing the AI era, please check out our new Mandiant AI Risk and Resilience report.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7fe6c8642ed0>), ('btn_text', 'Watch now'), ('href', 'https://x.com/googlecloud/status/2090213589558698309?s=20'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • A manufacturing blueprint for secure agentic AI: AI and agents have arrived on the factory floor. Today’s CISOs and business leaders must balance innovation with precision, physical safety, and operational resilience. Read more.
  • Proactive cyber defense for governments and enterprises: Our new Fairwind Program is a limited access program for governments and trusted partners to use our most advanced cyber defense capabilities. Read more.
  • Getting started with the Mantis harness to find and fix bugs: Mantis is part of how Google finds and fixes vulnerabilities at machine-speed. The open-source AI harness creates a more effective repository analysis. Read more.
  • Breaking into Google's GFile for $100,000: Learn about how a vulnerability — that was not exploited and has now been patched — could have allowed attackers to chain unauthenticated, undocumented internal APIs with overly-permissive shared file libraries to achieve unrestricted data access across core infrastructure. Read more.
  • Introducing new session management tools with native, granular controls: New Google Cloud session controls are deeply integrated and a granular feature of Context-Aware Access. Here’s what you need to know. Read more.
  • How Blackline prevents data exfiltration with VPC Service Controls: We’re excited to share new policy intelligence capabilities in VPC-SC that help drive operational simplicity: Violation analyzer and violation dashboard. Read more.
  • Introducing Continuous Vulnerability Assessment: You can detect exposure to new vulnerabilities the moment they’re published with Wiz CVA. Read more.
  • How developers prevent production risk at the source: Fixing security vulnerabilities in code takes seconds, while patching in production creates high operational costs and risk. Discover how empowering developers as your first line of defense eliminates exposure across every phase of your software pipeline. Read more.
  • Wiz achieves GovRAMP High authorization: Delivering unified cloud security and accelerating secure modernization to protect citizen data and critical infrastructure. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7fe6c8640610>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • AI Threat Tracker: From prompting to autonomy: In the newest Google Threat Intelligence Group (GTIG) report on the adversarial misuse of AI, we’ve observed adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation, including threat actors compromise a cloud resource, then plan, build, and execute an agent-enabled mass credential harvesting campaign in under six hours. Read more.
  • Financially-motivated threat actor BREEZE COMET targets Brazil: Learn about BREEZE COMET’s tactics and toolkit, and our mitigation recommendations and detections to support organizations in defending against this active and developing threat. Read more.
  • JFrog Artifactory under attack: Wiz Research has identified active, in-the-wild exploitation of three critical and high-severity vulnerabilities impacting JFrog Artifactory. Attackers are chaining these vulnerabilities to bypass authentication and gain administrative control. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: Patching browsers with AI, agents, Rust, and your tabs: Jasika Bawa and Doug Turner of Chrome Security explore how Google Chrome now uses AI agents to autonomously identify and patch security vulnerabilities at an unprecedented scale, significantly accelerating the browser's update cadence. Listen here.
  • Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Nir Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

Introducing new session management tools with native, granular controls

Google Cloud session management provides flexible options for setting up session controls based on your organization’s security policy needs. To help you improve your security posture and mitigate credential theft and account takeover (ATO) risks, we have rolled out a 16-hour default session length for Google Cloud customers.

We’ve now completed extending this security standard to all customers who had not already self-configured session lengths, but today’s cloud environments require even more precision. As we conclude this global rollout, we have also evolved Google Cloud session controls from a broad administrative setting into a deeply integrated, granular feature of Context-Aware Access (CAA).

This update gives administrators more flexibility, better automation, and a more natural security workflow.

What’s new in Session Controls

1. Automation-first: Terraform, gcloud, and API support
Modern infrastructure is managed as code. To support DevSecOps workflows, the Session Controls policy configuration is no longer limited to manual UI configuration. Now generally available, you can define, deploy, and manage your session policies programmatically using:

  • Terraform: Integrates session controls directly into your infrastructure manifests.

  • gcloud CLI: Manages policies from the command line.

  • REST APIs: Automate policy enforcement across complex multi-tenant environments.

2. Granular targeting with Google Groups
One of the most requested upgrades has been the capability to target policies with precision. Previously, session lengths were tied to organizational units (OUs). Now generally available, the Session Controls policy uses Google Groups.

This shift allows you to apply distinct session policies to specific clusters of users — such as requiring a two-hour session for users with elevated privileges (such as billing administrators and project owners) while maintaining a standard 16-hour session for general developers — regardless of where those users sit in your organizational hierarchy.

3. Precision application controls
Instead of a blanket policy that affects every application requiring Google Cloud API scopes, Session Controls policy allows you to configure session controls to specific applications. These applications include:

  • The Google Cloud Console

  • The gcloud command-line tool

  • Specific OAuth applications

Now generally available, this update can help prevent all-or-nothing scenarios where a strict policy on the Cloud SDK might inadvertently disrupt legitimate business intelligence or dashboarding integrations that rely on OAuth.

4. Google Cloud-native experience
Historically, configuring session lengths for Google Cloud could only be done in the Google Workspace administrator console. 

Google Cloud customers can also sign up to use the Google Cloud Console to manage session policies alongside other access levels and security bindings in Access Context Manager (ACM). Available in preview, this update can help give Google Cloud administrators who prefer using the Google Console for policy administration tasks greater flexibility and a unified experience for configuring all their CAA policies. 

How to get started

By evolving session controls from static organizational defaults into dynamic, context-aware policies, your security teams can enforce tighter reauthentication boundaries against credential theft where risks are highest, without disrupting developer velocity.

Get started with the session controls documentation for instructions on how to use Terraform, REST API, and gCloud to configure session controls.

  •  

Getting started with Mantis, our open-source bug finding-and-fixing harness

AI models have clearly proven their ability to discover and exploit vulnerabilities without much, if any, human assistance. To help defenders gain the advantage with AI, we built the Mantis harness to automate the discovery, triage, reproduction, and patching of software vulnerabilities. 

Available to all as an open-source framework, Mantis is part of Google’s internal approach to find and fix vulnerabilities at machine-speed. It creates a more effective scalable, context-aware repository analysis. 

While sloppiness in AI code scanning frequently leads to hallucinated bugs and weak true-positive rates under 7%, we designed Mantis to be effective by combining industry-standard agentic techniques like critic and review agents with sandboxed reproduction of vulnerabilities for grounding. 

As we detailed in June, it examines the history of the repository to learn from past security fixes and automatically builds up architectural and threat model documentation, even if these are not provided. 

It constructs a hierarchical security summary tree, condensing individual files into directory and root-level summaries. This technique reduced token overhead by over 85%, while preserving critical structural context across massive repositories.

Mantis distills decades of cybersecurity expertise across a wide spectrum of codebases, and is available on GitHub. Here’s how you can get started using Mantis.

  • First, clone the Mantis repo locally using:

code_block
<ListValue: [StructValue([('code', 'git clone https://github.com/google/mantis.git'), ('language', ''), ('caption', <wagtail.rich_text.RichText object at 0x7fcc5fa559d0>)])]>
  • Second, open your favorite coding agent and use the prompt, “I would like to use Mantis framework in path/to/mantis to review my code in path/to/your/code, can you help me get started?” 

Internally at Google, this exact prompt has been used to find real vulnerabilities across our many code repositories. As part of the Mantis repository on GitHub, we’ve included sample sandboxing options. You can also implement your own sandbox to match your own workflow.

Mantis is intended to be an easy place to start with vulnerability discovery, true positive filtering, and patching. Once you've got a handle on AI-discovered vulnerabilities, you can use the new mantis-advise skill to make use of the accumulated knowledge and get your coding agents to write secure code the first time.

To get the most out of AI-driven vulnerability discovery and modernize your development practices, we strongly recommend two essential practices:

  1. Feed your tools the right context: While Mantis automatically analyzes commit history and code to build documentation for itself, human-curated knowledge often can dramatically improve the quality of your results. For example, if you would never waste time fixing bugs where the user can crash their own program, this is critical information for a scanning pipeline to ensure that those types of bugs are never surfaced.

  2. Build a cyber sandbox with vulnerability acceptance criteria. Safe, sandboxed environments where you can reproduce vulnerabilities with clear vulnerability-reproduction criteria will give you better results for surfacing only the things you need to know and also for ensuring that your fixes are correct.

You can learn more about Mantis here.

  •  

How BlackLine simplifies perimeter policy intelligence with VPC Service Controls

Establishing network-level perimeters with VPC Service Controls (VPC-SC) is a critical step that can help you protect your cloud environment against data exfiltration, compromised accounts, and insider threats.

Today, Google Cloud is excited to share new policy intelligence capabilities in VPC-SC that can help drive even greater operational simplicity. With our latest release of the VPC-SC violation analyzer and violation dashboard, we have simplified policy management and troubleshooting, to make managing and optimizing your security perimeter more efficient and straightforward than ever. 

How BlackLine streamlines incident response

BlackLine, a leader in financial operations management, adopted the VPC-SC policy intelligence solution to maintain strict security perimeters. Chosen by over half of Fortune 500 companies, BlackLine uses Google Cloud's full suite of managed services and built-in security capabilities to protect sensitive customer financial data.

VPC Service Controls are the foundation of BlackLine's preventative compliance and security controls in our Google Cloud environment, helping us to mitigate data exfiltration risks and ensure clear separation between our higher and lower environments by establishing strong security perimeters.

Managing these complex perimeters is a continuous process. VPC Service Controls violation analyzer helps BlackLine cloud infrastructure administrators adapt to changing API connection requirements of the business by adjusting security perimeters through approved access levels, ingress policies, and egress policies. 

With only the troubleshooting token or unique ID from any VPC-SC violation error message, we can produce a detailed report identifying the principals and target resources involved in a failed API request, and explaining why and how that API request violated BlackLine's service perimeters. We don’t need to write a Cloud Logging SQL query to extract the data.

The clear access context and actionable insights in the violation details report are an invaluable starting point as we collaborate to resolve violations, significantly reducing our mean-time-to-resolution (MTTR) for service perimeter issues, and helping BlackLine maintain our focus on our customers and continue to innovate on their behalf.

Streamlining the perimeter operations lifecycle

Our new policy intelligence tools — the VPC-SC Violation analyzer and Violation dashboard — simplify real-time monitoring and active incident response. These tools provide clear, actionable insights in the Google Cloud Console, offering greater speed and automation to help you confidently enforce least-privilege perimeters, and quickly resolve access denials.

Violation Dashboard aggregates and visualizes all service perimeter violations across your entire Google Cloud organization in a single pane of glass, helping your team identify trends, spot spikes in access denials, and shareable filters on violations by specific perimeters, projects, or identities.

Violation Analyzer streamlines investigating violations, eliminating the need to query Cloud Logging and manually piece together the details. When you click a troubleshooting token from the dashboard (or input a unique denial ID), the analyzer maps out the identity, source, target, and VPC-SC rule triggered, creating a report telling you why that specific request was blocked. This helps your team more quickly take action to determine whether to modify existing policy rules or create a new one, and resolve incidents more quickly.

Together, the new VPC Service Controls policy intelligence tools go beyond automated log analysis to provide unified visibility of violations and actionable insights to investigate them, making your perimeter deployment and management simpler and lower-risk.

1

Streamlining the VPC Service Controls lifecycle, from deployment to policy refinement.

With the new VPC-SC troubleshooting tools you can more easily:

  1. Test new perimeters (deployment): Use the violation dashboard to visualize the impact of a service perimeter during your initial dry run phase, helping to verify that enforcement is accurate and predictable before it affects production traffic. Filter violations to track and resolve with prebuilt contextual filters for principals, service perimeters, enforcement type, and more.

  2. Track perimeter denials (monitor): The violation dashboard offers a unified view of your perimeter health, allowing your security operations team to monitor status in real time, including dynamic agentic access denials.

  3. Triage an event (investigate): Violation analyzer provides the identity, source, target, and operations for any violation. It cross-references identity and access management (IAM) permissions, resource ancestry, and context evaluation to identify which rule was triggered, reducing manual effort.

  4. Fix the rule (refine policy): Instead of searching through configuration files, violation analyzer maps violations directly to the relevant line in your VPC-SC policy, allowing you to make updates more quickly and with less manual overhead.

output_hq

The VPC Service Controls violation dashboard produces detailed reports to jump-start perimeter access investigations that are simplified using the violation analyzer.

Core VPC-SC operations: Simple perimeter enforcement

Our new troubleshooting capabilities build on VPC Service Controls’ foundational simplicity for designing, enforcing, and managing strong perimeters. 

By using dry run mode, your teams can build precise, contextual ingress and egress rules based on observed traffic — without disrupting vital business workflows. Once you validate these access patterns, moving to full enforcement becomes a more confident, data-driven process. To keep perimeter maintenance more efficient and straightforward, scoped policies allow you to delegate management directly to project-level administrators, empowering the teams closest to the workload.

Getting started

Simplify data security with VPC Service Controls. With the new Violation Analyzer and Violation dashboard, you can spend less time investigating incidents and more time safely scaling your cloud initiatives. Your data is your most valuable asset — protect it with a perimeter that’s as simple to manage as it is effective in enforcing controls.

Learn more and get started with the VPC-SC violation analyzer and violation dashboard in our documentation.

  •  

Cloud CISO Perspectives: Tips on securing the water sector in the AI era

Welcome to the second Cloud CISO Perspectives for August 2026. Today, Chris Sistrunk and Stephanie Kiel detail the critical issues facing the water sector, and actionable steps that OT operators can take to secure their infrastructure.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc310>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Tips on securing the water sector in the AI era

By Chris Sistrunk, Practice Leader, OT, Mandiant Consulting, and Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud

ChrisSistrunk

Chris Sistrunk, Practice Leader, OT, Mandiant Consulting

Google Cloud’s threat intelligence teams have observed that threat actors are becoming bolder when targeting critical infrastructure amid geopolitical conflicts. Recently, we’ve seen increased targeting of water utilities' internet-connected programmable logic controllers in the U.S.

Stephanie Kiel crop

Stephanie Kiel, Head of Cloud Security Policy, Government Affairs and Public Policy, Google Cloud

Historically, cyber incidents haven’t usually disrupted operations, in part because water utility operators have long had manual override capabilities and established water-quality checks that kick in before water reaches consumers. Pumps and pipes fail routinely for reasons that have nothing to do with cyber threats.

However, they do require our urgent attention and a commitment to stronger security hygiene. Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era. 

We recommend a threat-informed, risk-managed response. The current state of water sector security is indicative that additional action should be strongly considered in light of the unique operational resilience that keeps these systems safe.

Actions water and wastewater utilities should consider

For resource-constrained utilities, the most effective defense is to focus on cybersecurity fundamentals. By prioritizing these fundamental practices, you can significantly harden your systems and transform your organization into a far more challenging and resilient target, causing even well-resourced threat actors to look elsewhere. 

  • Inventory assets and assess exposure: Identify if your control systems are insecurely exposed to the internet, which often allows for the successful exploitation of vulnerabilities.

  • Basic security hygiene: Replace default credentials with strong passwords, and rigorously harden exposed access points, including firewalls.

  • Backups: Make sure that critical systems, including control systems, are safeguarded following the proven 3-2-1 backup rule (keep three copies of your data on two types of storage, with at least one copy stored off-site). Ensure critical spare equipment is on-hand to minimize downtime from cyberattacks.

  • Segmentation: Use network segmentation and multifactor authentication to ensure that remote access, when necessary, is strictly controlled. You should use read-only access where full control isn't required.

  • Emergency planning: Integrate cyber-incident planning into your existing all-hazards incident command system, including FEMA NIMS and Incident Command System for Industrial Control Systems, the same response structures you already use for physical pipe breaks, boil water alerts, and natural disasters.

  • Secure third-party and vendor access: As many water utilities do not manage their own IT or OT and rely on third-party system integrators, you should audit the remote connections used by the system integrators and maintenance contractors. You should ensure third-party vendors are held to rigorous access controls (such as MFA standards) and logging requirements.

These recommendations echo guidance from the American Water Works Association, the National Rural Water Association, the Water-ISAC, the Environmental Protection Agency, the Cybersecurity and Infrastructure Security Agency, and the FBI.

Recommendations for IT and OT leaders: Bridging the governance gap

IT and OT leaders must work together to build a unified governance framework and should focus on making cyber-physical systems more resilient over the long term, a collective effort that spans government agencies, private sector organizations, and individuals. The goal is to build a future where these systems are secure, adaptable, and capable of recovering quickly from disruptions.

Although PLCs almost always sit outside standard software development practices, a robust approach to the software your organization uses can significantly enhance your overall security posture, such as those outlined in NIST’s Secure Software Development Framework (SSDF). They’re also good examples of leading indicators that can help you gauge your resilience, and to help you get started we’ve published a guide to evaluate leading indicators.

Manual overrides provide a reliable safety net, but preventing cyber threats still requires a commitment to fundamental digital security — especially in the AI era.

As technology evolves, it is critical to modernize security, transitioning from a reactive, manual model to an AI-augmented approach that keeps human expertise central to decision-making. This approach offers an unique opportunity to be a force multiplier for lean security teams. 

To stay ahead of today’s threats, organizations must move beyond simple compliance checklists and adopt a more agile, threat-informed strategy that makes compliance a natural outcome of good security, rather than the primary goal.

The Mandiant Operational Technology (OT) Theory of 99 has become more relevant in the AI era. Although the funnel of opportunity has been significantly compressed, in intrusions that go deep enough to impact OT:

  • 99% of compromised systems will be computer workstations and servers

  • 99% of malware will be designed for computer workstations and servers

  • 99% of forensics will be performed on computer workstations and servers

  • 99% of detection opportunities will be for activity connected to computer workstations and servers

  • 99% of intrusion dwell time happens in commercial, off-the-shelf computer equipment before any Purdue level 0-1 devices are impacted

As a result, there is often a significant overlap across tactics, techniques, and procedures used by threat actors who target IT and OT networks. However, the Theory of 99 underscores a significant defender's advantage in the AI era. By using advanced AI capabilities to secure the 99% of intermediary infrastructure, organizations can proactively neutralize threats and ensure robust protection for the critical 1% of physical operational processes.

AI for cyber defense

As we have shared before, AI capabilities offer the opportunity to shift the balance in network security in the favor of defenders. The defender’s advantage becomes even more important as malicious actors increasingly use AI capabilities across the attack lifecycle. 

In the current threat environment, automating defenses can serve as a force multiplier for human security teams, enhancing decision-making and productivity to ensure critical exposures are addressed before they can be exploited. With careful planning, critical infrastructure providers can protect their physical assets while building a more resilient, threat-informed defense.

To effectively realize AI advantages for defense, you should integrate AI tools into systems in a structured, intentional way. It’s crucial that operators understand the unique vulnerabilities that AI introduces to physical processes, evaluate specific business uses that can benefit from security automation, and establish clear frameworks to continuously test and monitor. As part of our approach, we’ve developed the Secure AI Framework to help you achieve secure integration and deployment of AI capabilities, regardless of sector. 

Most importantly, human oversight must remain central — meaning that AI should support decision-making, and safety practices need to be embedded directly into incident response plans. 

What’s next for water security

Protecting water systems from malicious cyber threats is not just a technical challenge; it is a fundamental public safety imperative. Given that access to clean, reliable water is an essential service, we anticipate that federal, state, and local governments will increasingly shift from policy debate to decisive action to ensure the continuity of this critical public infrastructure in the face of cyber threats. 

For example, the Office of the National Cyber Director in partnership with the State of Texas has just launched a pilot program to help protect water infrastructure providers from cyberattacks, and U.S. senators have already introduced a new bill in response to recent events.

Google is committed to helping you protect your cloud and hybrid cloud OT environments. To learn more about Google guidance on securing critical infrastructure, please visit our CISO Insights Hub.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc370>), ('btn_text', 'Watch now'), ('href', 'https://x.com/googlecloud/status/2090213589558698309?s=20'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Empowering autonomous agents with advanced security governance: To be useful and secure, AI agents need access — and also guardrails. In our new State of AI infrastructure report, 79% of tech leaders cite security, governance, or operations as their most significant challenge to scaling inference. Read more.
  • The state of cloud risk 2026: Most security findings aren’t real attacker opportunities: Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise. Read more.
  • Introducing Google Cloud Fault Injection Testing in preview: When databases fail and network paths falter, you still need your mission-critical cloud services to stay online. Fault Injection Testing (FIT) can help you automate failure testing to ensure predictable behavior during disruptions. Read more.
  • How Wiz built AI-powered data discovery: Inside the multi-agent pipeline and feedback loops that turned a bucket scanner into a context engine. Read more.
  • Democratizing FinOps with Wiz: How the Wiz Cloud Cost automates cost allocation to power developer-led cost optimization and connect cost to business value. Read more.
  • Defend against agent risks with layered protections in Google Workspace Studio: Studio incorporates layered defenses to mitigate risks from threat actors and robust observability tools to help organizations adopt agents safely. Built on Google’s secure-by-design architecture, Studio combines native threat defenses with deep ecosystem visibility to secure multi-step agentic workflows. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7f06802cc3d0>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • Distinct clusters target individuals of interest to Russia: Google Threat Intelligence Group (GTIG) is tracking three suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace, governments, and think tanks across Europe and in the U.S. Read more.
  • Inside 90 days of attacks on AI infrastructure: Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft. Read more.
  • Version Control DFIR: A cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps: A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services. Read more.
  • Rust supply chain attack on arrayref: Significant overlap with DPRK campaigns: Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: Patching browsers with AI, agents, Rust, and your tabs: Jasika Bawa and Doug Turner of Chrome Security explore how Google Chrome now uses AI agents to autonomously identify and patch security vulnerabilities at an unprecedented scale, significantly accelerating the browser's update cadence. Listen here.
  • Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Near Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

Simplify your resilience testing strategy with Fault Injection Testing

When databases fail and network paths falter, you still need your mission-critical cloud services to stay online. Yet guaranteeing high availability has become increasingly difficult because of the complexity of modern distributed systems. 

To help you maintain availability and reliability during adverse events, we’re announcing Fault Injection Testing in preview. Fault Injection Testing is designed to help developers and architects automate failure testing to ensure predictable behavior during disruptions. 

By deliberately introducing faults into your environment, you can verify your safety mechanisms before an actual outage impacts your customers.

Why native resilience testing matters

Unlike in self-hosted data centers, cloud applications offer less direct access to underlying infrastructure to facilitate failover testing.

Without native tools to prove your application can survive a failure, you risk a critical gap in your reliability strategy that exposes you to several risks:

  • Damaged trust and reputation: Frequent failures or poor performance lead to customer dissatisfaction and long-term damage to your brand's image.

  • Compliance and regulatory penalties: For many industries, particularly financial institutions, failing to prove disaster recovery capabilities can lead to non-compliance, audits, and fines.

  • Migration delays: Large-scale migrations often stop when teams cannot verify that critical applications will remain stable during a zone failure.

How Fault Injection Testing works

Fault Injection Testing allows you to run experiments by creating experiment templates. These templates act as blueprints, defining the specific fault to be injected and the resources that will be targeted for the experiment.

In this public preview, you can test two primary failure scenarios:

  • Failover Cloud SQL: This fault triggers a failover of a high availability Cloud SQL instance from the primary zone to a standby zone.

  • Degrade application traffic: This allows you to selectively add latency and HTTP error codes through an Application Load Balancer. 

Before any fault is injected, Fault Injection Testing performs an automated dry run. This read-only simulation checks your permissions and provides an up-to-date list of every resource that will be affected. 

Once you verify the scope, you can manually start the injection. The duration you defined in the template will run its course, and the faults will be reverted at the expiration of the timer.  

During the experiment, you can verify that your application is behaving as you planned.  If things do not go as planned, you can use the stop and revert capability to immediately halt the experiment and begin restoring resources to their normal state.

During preview, we recommend as a best practice to use Fault Injection Testing (FIT) in a non-production environment. Preview is an opportunity to get early access to learn how the service fits and complements your existing testing practices, and to provide us with your feedback to improve the product as well!

Built for the enterprise

Partners like KeyBank and Servier are already using Fault Injection Testing to validate their deployments. By using native fault injection, these organizations can approximate demanding failure scenarios — such as zonal outages — to help ensure their services remain stable.

Get started with Fault Injection Testing

Fault Injection Testing is available through the Google Cloud console, the gcloud CLI, and REST APIs.

  1. Request preview access: Talk to your Google Cloud Account Team to add your project to the preview.

  2. Enable the API: Search for "Fault Testing API" in your Google Cloud console and select enable.

  3. Assign roles: Ensure your team has the roles/faulttesting.operator role to configure and run experiments.

  4. Run your first dry run: Create a template for a Cloud SQL or load balancer resource in a non-production environment and execute a dry run to see the potential impact.

For more details on implementation, talk to your account team, or view the User Guide for Fault Injection Testing.

  •  

Empowering autonomous agents with advanced security governance

AI agents are the ultimate insiders. We grant them permission to read emails, query databases, and trigger API calls. They don’t just retrieve information, they take action. 

Agents offer incredible potential for increased productivity and better customer experiences, but they also come with new security concerns. In our new State of AI infrastructure report, 79% of tech leaders cite security, governance, or operations as their most significant challenge to scaling inference.

While there’s still a crucial role for traditional security tools, the threat model has fundamentally changed. Autonomous workflows have redefined enterprise risk, so it's crucial that we give agents the access they need without compromising security.

Blog 4_Infographic 1
Blog 4_Infographic 2

The agentic paradox

The path to success starts with viewing governance as a driver for innovation. To be useful and secure, an agent needs access — and also guardrails. Yet 35% of senior IT decision makers cite insufficient security for multi-system access as a primary issue preventing agentic deployment.

Agents expand the surface area that defenders need to protect, and can introduce new threats, including tool poisoning and indirect prompt injection, where an attacker can hijack an agent’s logic through the data it processes. Managing the dynamic permissions that agents need to succeed at their tasks can also be a significant challenge, particularly as legacy security wasn’t designed for today’s automated threats.

Blog 4_Infographic 3

Securing the chain of thought

Along with securing more identity and access issues, it’s important for defenders to secure both the network layer and the model.

Security leaders are increasingly shifting their focus from preventing breaches to verifying provenance to guard against misuse, including indirect prompt injection.

From an infrastructure perspective, what are your top security concerns related to AI?

From blocking to managing

We’ve looked at the new security challenges posed by agentic AI. You can’t solve them by simply locking down the system, as that defeats the purpose of autonomous agents.

Many organizations are turning to integrated, full-stack cloud platforms to give them greater oversight. 69% of surveyed executives now rate a full-stack platform as a critical requirement, and 80% say data compliance is the primary factor dictating that choice.

By adopting frameworks like the Secure AI Framework (SAIF) and moving to a central control plane, purpose-built platforms such as Gemini Enterprise Agent Platform, organizations can manage risk in three main areas:

  • Secure-by-default design: Embedding security directly into the AI development process to proactively guard against threats including prompt injection.

  • Agent governance and oversight: Adopting purpose-built permission and identity management for agents — giving greater control over agent interactions, exposing blind spots and limiting risks tools.

  • Human-in-the-loop control: Enforcing clear rules that automatically flag when an agent requires human approval before moving forward with a critical action.

Governance will guide you to success

The true value of a modern security foundation is its ability to encourage innovation. By embedding robust governance directly into a unified foundation, organizations can deploy agents with confidence across their most sensitive, business-critical workloads. 

The leaders of the agentic era are re-architecting their stack to use security as a launchpad — empowering them to innovate securely and scale faster than their competition.

Find out more about how enterprise leaders are rethinking security for the agentic era in the State of AI infrastructure report.

  •  

Cloud CISO Perspectives: Sticking to security fundamentals in the AI era

Welcome to the first Cloud CISO Perspectives for August 2026. Today, Chris Betz explains why the AI era makes it more important than ever to lean into security fundamentals.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7f1828ef1880>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

How to stay strong with security fundamentals in the AI era

By Chris Betz, CISO, Google Cloud

Chris Betz Google-9779

Chris Betz, CISO, Google Cloud

As AI accelerates the capabilities of adversaries, foundational strength becomes the primary differentiator between resilience and vulnerability. It’s a dangerous and unfortunately common misconception that traditional security fundamentals are becoming obsolete. For CISOs, the challenge is to adopt new AI technology securely while scaling essential, effective defensive practices to move at the speed of the adversary.

For both attackers and defenders, AI has been a catalyst for optimization and innovation. While traditional automation has allowed us to perform repetitive tasks at scale, AI enables both sides to execute highly-specific, customized actions at massive scale and unprecedented speed.

Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.

We can see the threat developing almost in real-time. Adversaries are deploying new malware with just-in-time AI that dynamically generates malicious scripts and obfuscates code mid-execution to evade detection. They use sophisticated vishing and deepfakes for identity theft and business email compromise. We even see unauthorized AI tools lead to the rise of shadow agents. 

Defending against AI powered security threats requires more than accelerating current security practices; it means stepping back and beginning with the security foundation and layered defenses. It’s critically important to build and use a layered defense with the right guardrails — foundational cybersecurity building blocks that we’ve been investing in for years.

Doubling down on this foundation: technologies like multi-factor authentication (MFA), Zero Trust frameworks, consistent system patching, and comprehensive detection and response. Collectively, these technologies reduce the attack surface and contribute to the deep context that defensive AI needs to be a business enabler — and create the necessary conditions for successful AI-powered defenses.

Revolutionizing vulnerability management

In just a few short years, identifying and fixing vulnerabilities has evolved from a mostly laborious, manual process to one driven by AI tools discovering vulnerabilities at volumes never seen before. Further, the time to exploit window has essentially been eliminated.

However, it’s not enough to merely discover vulnerabilities, especially at today’s volumes. You still need to prioritize fixing those that have the most critical impact on your systems and networks first, and that necessitates an equally-rapid response in smart mitigation. 

Organizations use multiple models to scan for flaws and then suggest high-quality code fixes that engineers can quickly move into production, leveraging capabilities like AI Threat Defense. AI allows us to automate the entire software development lifecycle, from discovery to testing and deployment, ensuring that our defensive posture evolves faster than the threats targeting us.

Enhancing threat modeling

We’re also seeing the fundamental concept of threat modeling have an outsized impact. Doing threat modeling well requires bringing context together from your code, your cloud architecture, system design, and network pathways. 

While it isn’t easy, using AI can scale our ability to bring that data together into a coherent picture. Teams have been experimenting with multi-AI models to collect system information and enumerate threats. 

As I noted in June, engineering teams at Google Cloud now route product launches through an agent-based security review pipeline. High-risk indicators automatically get flagged for human review, while we’ve replaced static threat models with dynamic product dossiers that update in real-time.

The CISO as a strategic business leader

The most effective security leaders that I know today are more than just technologists: They are strategic business leaders. The intense global focus on AI vulnerabilities has brought cybersecurity to the forefront of boardroom and executive attention like never before.

This visibility is an opportunity to lead. We CISOs are expected to communicate with clarity, from the board to the C-suite to the security teams who look to them on a daily basis, demonstrating their ability as capable strategists who can navigate the complexities of AI while safeguarding the organization's growth. 

By aligning security fundamentals with business objectives and using AI to enhance defense, we can lead our organizations securely into the future.

To learn more about building and maintaining strong security foundations in the AI era, read our newest Defender’s Advantage: Cyber Snapshot Report.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7f1828ef18e0>), ('btn_text', 'Watch now'), ('href', 'https://www.youtube.com/watch?v=CmGWIwgHR60'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Driving AI threat readiness with Wiz: Announcing new Wiz capabilities that can help organizations prepare for the AI era by expanding visibility and accelerating response, so your security teams can defend at machine speed. Read more.
  • PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap: We’ve long been actively working on and rolling out post-quantum cryptography in our infrastructure. Here’s our updated Google Cloud roadmap to migrate to PQC by 2029. Read more.
  • How Google Cloud detects, contains, and protects against emerging threats: Learn more about how Google Cloud empowers you with the tools, governance, and infrastructure you need to securely deploy workloads and maintain long-term trust. Read more.
  • Privacy-first medical AI with MedPerf and Google Cloud: Discover how Google Cloud and MedPerf use Confidential Computing to enable secure, privacy-first collaborative medical AI evaluation. Read more.
  • More cryptanalysis makes us all safer: Recent advances in frontier AI models do not signal the downfall of cryptography. Here’s why they’re best viewed as additional cryptanalysts. Read more.
  • How layered defenses harden Chrome against abusive notifications: Learn how Chrome Security has collaborated with Firebase Cloud Messaging (FCM) and Safe Browsing to significantly reduce notification abuse, and improve the security and quality of the web ecosystem for everyone. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7f1828ef1940>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • Staying ahead of adversarial AI through agentic source code review: To help defenders implement agentic approaches similar to our approach at Google Cloud, we are sharing the details of our Agentic Vulnerability Discovery Harness architecture for the first time. AVDH can also be used alongside CodeMender’s ongoing scanning to create a two-layered defense strategy. Read more.
  • Cloud threat highlights from the first half of 2026: In the first half of 2026, Wiz's Research and CIRT teams tracked threats affecting thousands of cloud environments. We saw a notable increase in the volume of activity, with supply-chain attacks running at a previously unseen scale and developer toolchains and AI infrastructure drawing serious attention. Read more.
  • Batten down your packages: Mitigation guidance for supply chain compromise: GTIG and Mandiant have tracked ongoing and increasing open source software supply chain compromise campaigns over the past several years. Here are our mitigation and hardening recommendations to secure software supply chains, including insights we have developed as a result of supporting customers. Read more.
  • Multi-brand vishing extortion targets financial services and enterprise cloud environments: Telemetry and infrastructure analysis reveal that UNC6671 has not disbanded. Instead, the threat group has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon and continues to rely on voice phishing to target enterprise employees. Read more.
  • Keyv and cacheable npm package hijacked in supply chain attack: Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages. Read more.
  • Inside the Metabase SQLi: Exploited in the wild: Wiz has reverse engineered Metabase CVE-2026-72898 with AI to accelerate defense. Here’s what we learned. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: All about Project Atlas, Wiz's AI vulnerability research: Near Orfeld, head of vulnerability research, Wiz, discusses how his team uses multi-agent AI systems for discovering high-impact zero-day vulnerabilities in cloud infrastructure. Listen here.
  • Cloud Security Podcast: How Google eliminates classes of vulnerabilities at scale: How do you build the foundations for a secure Google-scale enterprise that stays secure even if an AI is writing the code and nobody has time to review it? Christoph Kern, principal security engineer, Google, explores what secure-by-design really means in the AI era. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

Announcing quantum-safe key import in Cloud KMS

As enterprises increasingly adopt multicloud architectures, bring your own key (BYOK) has become a fundamental pillar for maintaining data sovereignty and helping protect critical cloud workloads. At the same time, quantum computing has rapidly advanced, and security teams need to re-evaluate how they securely transfer encryption keys across networks.

Following our previous announcements of quantum-safe digital signatures and quantum-safe key encapsulation mechanisms (KEMs) in Cloud Key Management Service (Cloud KMS), we are excited to announce the preview of quantum-safe key import in Cloud KMS for software-based cryptographic keys.

Our updated quantum-safe BYOK capability, the first step of the next phase of our post-quantum cryptography (PQC) migration timeline, can help you protect your sensitive keys before a cryptographically-relevant quantum computer (CRQC) emerges.

As you adopt quantum-safe key import to help protect your keys in transit, you can also monitor your overall post-quantum posture with Cloud KMS PQC insights, now generally available. This high-level visual illustrates your asymmetric keys based on the categorization of the algorithms they use, and can help you plan for future modernization and support long-term resilience.

The threat: Store Now, Decrypt Later attacks

Traditional key import methods rely on classical asymmetric encryption standards to wrap keys during transit. While these algorithms successfully defend against today’s threats, they will become fundamentally insecure when a viable quantum computer emerges that can potentially decrypt keys that adversaries have intercepted and stored. 

Quantum-safe key import helps mitigate these store now, decrypt later (SNDL) attacks by wrapping your keys in a quantum-resistant envelope from day one.

Building a quantum-resistant envelope for keys

The post-quantum transit mechanism now available in Cloud KMS uses hybrid public key encryption (HPKE). Our new import method wraps your sensitive software key material in a quantum-resistant transit envelope. The process integrates into the existing Cloud KMS API workflow to minimize your work:

  • Initiating the job: The client creates a new import job through the Cloud KMS API, requesting a post-quantum HPKE import method.

  • Key generation: The Cloud KMS server generates a post-quantum KEM private key and exposes the corresponding public key to the client.

  • Client-side wrapping: Using a supported cryptographic library (such as Tink or OpenSSL), the client executes an HPKE Seal() operation. This encapsulates the public key to establish a shared secret, derives an ephemeral AES key using HKDF-SHA256, and encrypts the target key material.

  • Submission: The client transmits the encapsulated ciphertext concatenated directly with the encrypted key material back to the Cloud KMS endpoint, which already has quantum-safe data-in-transit protection built-in.

  • Unwrapping: The Cloud KMS server executes an HPKE Open() operation using its private portion of the wrapping key to safely decrypt and help protect the key material within the Cloud KMS boundary.

For the KEM layer, you can choose between X-Wing, ML-KEM-768, or ML-KEM-1024. The key derivation layer utilizes HKDF-SHA-256, and the final symmetric wrapper employs AES-256-GCM with standard 12-byte nonces.

To learn more about setting up your import jobs, preparing your local key material using external cryptographic libraries, and managing quantum-safe solutions, check out our Cloud KMS quantum safe key import documentation.

A critical milestone in Google Cloud's PQC journey

The global migration to post-quantum cryptography is a marathon that you take one milestone at a time. Today, you can create your first quantum safe key import job and begin the process of helping make your applications quantum-safe. 

We welcome your feedback and invite you to reach out to explore how we can support your organization's post-quantum strategy.

  •  

PQC in Plaintext: Google Cloud’s post-quantum cryptography roadmap

Securing infrastructure and services against a future cryptographically-relevant quantum computer has been a goal for Google for a decade, and we’ve dedicated ourselves to help developers by advancing open standards that can benefit everyone. As post-quantum cryptography (PQC) has matured, we’ve been rolling it out in our infrastructure for internal and customer-facing services. 

Today, we're sharing our updated Google Cloud roadmap to migrate to PQC by 2029.

Our strategy: Secure by design

We’ve based our PQC migration strategy on the Google Quantum Threat Model, prioritizing protection across three key domains:

  • Mitigating Store Now, Decrypt Later (SNDL) risks: Protecting today's encrypted data from being harvested and decrypted by a future quantum computer.

  • Ensuring integrity against forgery: Strengthening digital signatures to prevent attackers from falsifying data and identity.

  • Enhancing foundational capabilities for cryptographic agility: Building flexible systems that can easily adopt new cryptographic standards with minimal engineering effort as cryptographic standards evolve.

We’re actively transitioning internal infrastructure and customer-facing services to PQC algorithms far ahead of regulatory deadlines.

We are also deploying PQC solutions across our Sovereign Cloud initiatives, such as Google Cloud Dedicated (GCD) and Google Distributed Cloud (GDC), in collaboration with our partners. Similarly, our strategy allows us to progress on integrating post-quantum protections across our AI services to secure the next generation of cloud workloads. 

These efforts are fundamental pillars of our overarching strategy to achieve full post-quantum readiness across Google Cloud. As this landscape evolves, we will continue to refine and update our deployment schedules.

1

Visualization of our Google Cloud PQC roadmap. Our efforts converge in 2029, and extend beyond it.

We plan to achieve full PQC readiness by 2029, when our efforts converge. We anticipate continuing those efforts into the 2030s to support broader industry guidance and evolving global standards. These standards include CNSA 2.0 and the transition paths defined in NIST IR 8547, which anticipate the final deprecation of legacy, quantum-vulnerable algorithms between 2030 and 2035.

Immediate progress: 2026 milestones

Leadership in the quantum era requires deployment at global scale. We have achieved foundational milestones that provide immediate protection for our customers:

  • API endpoint readiness: Google Cloud API endpoints now offer quantum-safe key exchange, protecting incoming traffic from future decryption. These endpoints include google.com and *.googleapis.com, and both have implemented NIST-standardized ML-KEM (FIPS 203) in hybrid mode.

  • Load balancers PQC support: Application and proxy load balancers now support quantum-safe hybrid key exchange (X25519MLKEM768) for TLS 1.3. Initially available on an opt-in basis, this allows our customers to perform validation, while minimizing impacts to their existing applications.  

  • Quantum-safe certificate experimentation at scale: We’re collaborating with the IETF PLANTS Working Group to produce a public key infrastructure (PKI) standard that minimizes impact to your operations teams. Chrome and Cloudflare have started experimenting with Merkle Tree Certificates to address challenges using PQC signatures for WebPKI, and we have been sharing insights with the standards working group.

  • Cloud KMS PQC algorithms: NIST standardized PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) for your encryption and signing keys are now generally available. 

The roadmap to 2029

We’ve established specific customer-centered journeys for Google Cloud to achieve quantum readiness that allow us to prioritize our quantum-safety initiatives. By adopting this risk-based approach, we focus on the core journeys our security experts have identified as most vulnerable to the potential impacts of quantum computing.

2

Risk-based prioritization for core quantum readiness user journeys.

These scenarios offer diverse platform perspectives to ensure global enablement across our services to meet you where you are.

For each risk domain, we provide a roadmap for key products and services organized by domain, although the services highlighted are not exhaustive lists. We project most services will meet their respective domain's target completion date, though specific product timelines may be adjusted if necessary to account for evolving engineering requirements and any third-party dependencies.

Domain 1: Store Now Decrypt Later (SNDL) mitigation

This domain focuses on addressing vulnerabilities in asymmetric encryption where a future cryptographically-relevant quantum computer (CRQC) could decrypt data captured today.

We’re enabling incremental progress for our customers based on their typical journeys.

  • Securing your customer workloads: Offer quantum-confidential TLS 1.3 handshakes for your Google Cloud services and configured load balancers to protect user sessions.

  • Securing administrator and developer flows: Protect the admin pathways used to manage your cloud environment against SNDL. This includes services such as Cloud VPN and Interconnect. For developers, these include client libraries, SDKs, and Tink, our open-source cryptographic library.

  • Securing data pipelines: Safeguard the confidentiality of data transfers for our analytics and storage platforms. PQC is essential to ensure that sensitive intellectual property and customer data flowing through these systems cannot be captured today and decrypted by a future quantum-capable adversary.

Roadmap
We are targeting these changes for 2027. 

Journey

Benefits

Representative services

Store now decrypt later mitigation (End of 2027)

Securing your customer workloads

Quantum-safe ingress: Protects your cloud perimeter using standardized post-quantum algorithms.

Application and proxy load balancing
[2026 (Completed)]

Securing admin and developer flows

Secure operations: Validates that your management and deployment stack meets emerging cryptographic standards.

Quantum-confidential ALTS
[2025 (Completed)]

API endpoints
[2026 (Completed)]

Cloud VPN, Cloud Interconnect, GCE OS Login, Cloud SDK, gCloud CLI, GKE service mesh, and client libraries
[2026/2027]

Securing data pipelines

Confidential data transfers: Protect sensitive intellectual property and customer data against quantum attackers.

Cloud Storage SDK, Storage Transfer Service, BigQuery CLI, Data Transfer Service
[2026/2027]

Domain 2: Integrity and non-repudiation

This domain addresses quantum-proofing of digital signatures and attestations to safeguard against forgery that could compromise data integrity and authenticity.

  • Securing the software supply chain: Ensure that only trusted, untampered images with quantum-resistant attestations run in production to help prevent a quantum attacker from altering builds. This includes services like Binary Authorization, Cloud Build, and Assured Open Source Software.

  • Issuing quantum-safe certificates: Transition the public key infrastructure (PKI) including our internal and external certificate authorities (CAs) to support ML-DSA certificates and where meaningful, SLH-DSA certificates. This transition will follow Internet Engineering Task Force (IETF) standardization efforts that are currently in development. We’re actively contributing to these efforts, and we’re also conducting several large-scale experiments:

    • Address large PQC signature sizes that can impact the performance of certificate chain validations through novel approaches like Merkle Tree Certificates for Web PKI. 

    • Support ML-DSA/SLH-DSA (pure PQC)-based certificates in private CA solutions such as Certificate Authority Service (CAS). 

    • Add quantum-authentication in addition to our internal traffic protocol ALTS that already supports PQC for confidentiality. You can learn more technical details on our approach to digital signatures and Public Key Infrastructure here.

  • Protecting identity and access: Ensure authentication mechanisms like service account keys and tokens (JWT/OAuth) are resistant to quantum forgery.

Roadmap
We are targeting completion of these milestones by 2028. We also are mindful of ongoing standardization efforts particularly in the field of certificates. Google is actively contributing to quantum-safe certificate standards, and we are committed to help the industry overall meet those deadlines.

Domain / Journey

Benefit

Representative services

Integrity and non-repudiation (End of 2028)

Securing the software supply chain and signature services

Quantum-safe software attestations: Prevents unauthorized build tampering by ensuring only trusted images run in production.

Binary Authorization, Access Approval (AXA)
[2026]

Assured OSS
[2027]

Issuing quantum-safe certificates

Quantum-safe standardized trust: Safeguards the authenticity of your internal and external communications against quantum-calculated certificate forgery.

Quantum-authentic ALTS
[2026/2027]

Private CA (Certificate Authority Service)
[2027]

Google Trust Service: Merkle Tree Certificates
[2028]

Roll out of PQC certificates across Google Cloud products and infrastructure
[2027/2028]

Protecting identity and access

Governed identity: Eliminates the risk of adversarial credential fabrication with NIST-standardized signatures for auditable integrity.

Cloud IAM
[2028]

Infra-wide rollout of quantum-safe authentication and access
[2027/2028]

Domain 3: Foundations and key management

Cryptographic agility is the foundation of our PQC migration. Our ongoing investment in this area drives our end-to-end strategy for key management, libraries, and infrastructure changes.

  • Foundational key management and libraries: Enable NIST-approved algorithms through Cloud KMS and libraries like BoringSSL and Tink. 
      • Note that Cloud KMS achieved general availability for the NIST standardized PQC algorithms (ML-KEM, ML-DSA, SLH-DSA), and is in the process of enabling quantum-safe key import.

  • Hardware-backed cryptographic services: Secure physical foundations using quantum-resistant roots of trust. This includes PQC as part of our Confidential Computing offerings and Cloud Hardware Security Module (HSM).
  • Key sovereignty and partner solutions: Enable PQC orchestration for Google Workspace Client-side Encryption (CSE) and External Key Managers (EKM). Collaborate with partners to support PQC on-premises key providers.

Roadmap
We are targeting completion of these milestones by 2028. 

Domain / Journey

Benefit

Representative services

Foundations and key management (End of 2028)

Foundational key management and libraries

Standardized quantum-safe keys: Provides the NIST-approved building blocks to help migrate your applications.

ML-DSA and SLH-DSA in KMS, ML-KEM and Hybrids in KMS
[2025 (completed)]

Quantum-safe Key Import (BYOK)
[2026]

Hardware-backed cryptographic services

Silicon rooted hardware: Anchors your security in quantum-safe hardware roots of trust.

Confidential Compute (including attestation and vTPM)
[2028]

Quantum-Safe Cloud HSM (FIPS 140-3 L3)
[2028]

Key sovereignty and partner solutions

Cryptographic provenance: Provides control and provenance of your keys where you need them.

External Key Management
[2028]

Partner enablement (key providers and sovereignty solutions)
[2028]

 

A shared responsibility for quantum safety

Security has long been a collaborative partnership with our customers. 

Google’s responsibility — Security of the cloud: We manage the transition to a quantum-safe infrastructure, including our network and encryption in-transit, global front-ends, and the ALTS protocol. 

This responsibility encompasses the end-to-end PQC transition of our servers, ensuring that the underlying hardware and operating systems are secured against quantum threats. We maintain hardware integrity through quantum-safe, open-source silicon foundations such as Caliptra v2.1, TPM 2.0 v185, and OpenTitan. The latter is the first open-source silicon root of trust and already supports quantum-secure boot. 

While we are working toward our 2029 target, hardware transition to PQC involves both active replacement, where feasible, and natural equipment replacement cycles. Our phased approach ensures stability, though the timeline for some physical components may extend beyond 2029.

Customer’s responsibility — Security in the cloud: Organizations must manage their own applications, including updating client-side software to negotiate PQC handshakes and managing the lifecycle of your asymmetric keys.  

In addition, you should update your Google Cloud service configurations with quantum-safe settings and policies.

Our path forward, together

Building momentum toward quantum readiness requires immediate, practical action. We recommend starting with these three steps:

  1. Inventory: Identify your cryptographic resources (such as keys and certificates) using Cloud Asset Inventory and solutions such as Wiz’s cryptography and PQC readiness. When you map cryptographic resource usage across your organization, you can more accurately define and prioritize your migration backlog.

  2. Update: Ensure your development and Site Reliability Engineering teams are using software that supports PQC algorithms such as BoringSSL, Chrome, and SDKs. This update ensures your internal workflows are prepared to negotiate quantum-safe connections by default as we enable them at the edge.

  3. Validate: Test the behaviors of your existing application using our quantum-safe APIs and load balancers. Validating your workflows today will identify architectural bottlenecks before they impact your primary production environments.

Google Cloud is committed to managing the complexity of this transition so you can achieve your regulatory and compliance commitments, while focusing on innovation. We are just beginning to share our progress as we work to empower our customers to lead in the post-quantum landscape.

To learn more about our PQC approach, please visit our post-quantum cryptography (PQC) hub.

  •  

How Google Cloud detects, contains, and protects against emerging threats

At Google Cloud, securing your data and business systems is our foundational commitment. We empower our customers with the tools, governance, and infrastructure needed to securely deploy workloads and maintain long-term trust.

We approach security from a shared fate model, and we continuously work to proactively identify and mitigate potential threats before they can compromise your data and misuse your infrastructure.

Understanding the risk: How bad actors attempt to exploit cloud workloads

Hyperscale cloud platforms like Google Cloud offer massive compute capacity, high-speed networking, and cutting-edge AI engines, but these same core strengths also make us high-value targets for malicious actors seeking service disruption, financial gain, or exploit cloud resources.

By tracking active adversary techniques, Google’s specialist security teams actively monitor and defend across several areas.

  • AI workload exploitation: As organizations rapidly adopt AI tools and systems, including Gemini Enterprise Agent Platform, threat actors target unsecured API keys and leaked access tokens. Common attack patterns include using stolen credentials for unauthorized distillation attacks and reselling access tokens on third-party marketplaces. We track consumption rates, account standing, and access context to catch these anomalies early.

  • Cryptocurrency mining: Malicious actors often use stolen credentials to spin up virtual machines (VM) for illicit cryptomining. While Google Cloud respects customer privacy and does not inspect internal VM processes, we can accurately infer mining activity by analyzing infrastructure telemetry — such as distinctive CPU and memory utilization spikes and rapid VM creation rates.

  • Exfiltrated credentials and supply chain attacks: Developers occasionally commit secrets and API keys to public source repositories where automated scrapers harvest them in seconds. Exposed credentials also stem from supply chain attacks against local development environments or managed cloud workloads.

  • Account takeover (ATO): Adversary-in-the-middle (AITM) techniques — such as sophisticated phishing and session cookie theft — can grant unauthorized users administrative control. Once inside, adversaries establish persistence, move laterally, and execute downstream abuse like resource hijacking or data exfiltration.

Without proper containment, these attacks can lead to operational disruptions, compromised system integrity, and unchecked resource misuse — such as runaway costs — creating substantial friction for impacted users.

Mitigating risks: Tailored containment in action

Detecting a threat is only half the battle; maintaining business continuity by containing it without interrupting your legitimate operations is critical. Google Cloud deploys tailored mitigation strategies based on the nature of the threat.

  1. Granular containment and throttling: When anomalous traffic indicates AI abuse or cryptomining, we apply targeted throttling measures. This isolates malicious activity while preserving legitimate corporate traffic.

  2. Collaborative triage for complex workloads: In AI environments, malicious API calls are often interlaced with critical business operations. In these scenarios, our Cloud Abuse and Cloud Support teams collaborate directly to isolate and inspect specific traffic vectors.

  3. Localized identity isolation: To prevent lateral movement, localized containment protocols can be systematically applied across compromised user identities and Google Workspace domains.

  4. Targeted suspensions as a last resort: Our primary objective is to enforce containment at the most granular resource level possible. However, if platform integrity or customer financial exposure is severely threatened, we may temporarily suspend specific projects, backed by a clear appeal process.

Additionally, to stop attacks at the root, Google actively partners with public repository hosters through initiatives like GitHub Secret Scanning to catch exposed credentials immediately and trigger proactive warnings before exploitation occurs.

Communicating risk: Proactive transparency and log visibility

During a security event, time-to-awareness is everything. We provide a robust suite of tools and channels to ensure your key security stakeholders receives actionable visibility:

  • Cloud Abuse Event Logging: Provides a 30-day window into security and abuse notifications with resource-level granularity. These logs can be ingested directly into your SIEM product for automated orchestration and response.

  • Proactive support cases and abuse notifications: When critical abuse is detected, automated email notifications and high-touch support cases are generated to open an immediate channel for resolution and best-practice sharing.

  • Cloud Audit Logging and anomaly spending alerts: Audit logs monitor unexpected resource changes that point to an ATO, while automated billing alerts notify key stakeholders of sudden spend spikes driven by compromised workloads.

  • Essential Contacts: To ensure notifications reach the right people instantly, Google Cloud allows you to maintain a dedicated directory of designated contacts across security, billing, and operations.

Customer action plan: Hardening your environment

We handle the security of the underlying infrastructure, yet your organization remains resilient only through proactive hygiene on your side of our shared fate partnership.

To minimize risk exposure across your user accounts, service accounts, and API keys, we recommend implementing these foundational defenses.

  1. Mandatory identity protection: Enforce multi-factor authentication (MFA) and 2-Step Verification (2SV) across all user accounts and Google Workspace domains without exception to prevent AITM cookie theft and phishing attacks. Ensure that you use Device Bound Session Credentials (DBSC) for your Google Workspace accounts to bind a user's session to their specific device.

  2. Secure service accounts and API keys: Treat keys and tokens as top-tier secrets. Never embed API keys in source code or public repositories. Use keyless authentication where possible, rotate keys regularly, and follow strict governance for service account management.

  3. Enforce least privilege and perimeter defense: Use Identity and Access Management (IAM), VPC Service Controls (VPC-SC), and Context-Aware Access (CAA) to restrict access so identities only have the exact permissions required for their specific function.

  4. Configure Essential Contacts and billing alerts: Set up detailed billing alerts to identify unauthorized spending before costs rise, and conduct quarterly reviews to keep your Essential Contacts directory current.

  5. Regular resource hygiene: Conduct periodic audits of your organization to identify and decommission unused resources, legacy billing accounts, and dormant user accounts. Pay special attention to groups or service accounts with elevated permissions to ensure your attack surface remains as small as possible.

Continuous vigilance together

Google continuously monitors platform health to detect anomalous usage patterns before they impact your workloads. 

Ultimately, maintaining a secure environment is a partnership built on shared fate. While we take every precaution to prevent bad actors from gaining a foothold, protecting your organization requires equal dedication on your end. By applying robust access controls, staying vigilant, and adopting security best practices, together we can keep your workloads secure and resilient.

Explore key resources to harden your environment:

  •  

Advancing brain tumor research with privacy-first AI

The intersection of medicine and AI has led to remarkable innovations. However, developers now face the thorny challenge of building robust medical AI tools that have been tested and evaluated on diverse, real-world patient data while also protecting patient privacy. At Google Cloud, our approach combines strategic collaboration with Confidential Computing.

To help protect both patient privacy and AI models during validation, we’re collaborating with MLCommons through the MedPerf initiative. First announced at Google Cloud Next earlier this year, this partnership uses Confidential Computing to establish a secure clean room for benchmarking AI models in real-world settings.

The challenge: Evaluating AI without seeing the data

MLCommons, a global community with over 125 members across tech and academia, launched MedPerf in 2023 to standardize the evaluation of medical AI. MedPerf, an open-source platform for benchmarking AI models, has advanced clinical research using federated evaluation to test models.

By using Google Cloud Confidential Space, proprietary AI models can be evaluated inside hardware-isolated Trusted Execution Environments (TEEs). This special virtual machine encrypts memory in-use and hardens the operating system, so none of the parties — the hospital or research institution, other participants, or Google — can see model code or patient data while it's evaluated.

Medical AI benchmarking is compute-heavy, so the Confidential VM extends beyond the CPU to the GPU. To protect model weights and patient data even during GPU-accelerated inference, MedPerf runs on Google Cloud's A3 machine series with NVIDIA H100 GPUs, which pairs Intel TDX technology on the CPU with NVIDIA Confidential Computing on the GPU. 

Before any patient data is released into the workload, the system provides cryptographic proof that only the approved code is running on genuine Confidential Computing hardware and that the environment has been properly hardened.

Real-World Medical AI Evaluation: MedPerf & GCP Confidential Computing Demo

Learn how ML Commons MedPerf integrates with Google Cloud Confidential Compute to enable secure, real-world evaluation of medical AI models.

From theory to critical impact: Advancing brain tumor research

This technology is already driving critical research through the Federated Tumor Segmentation (FeTS) initiative. Brain tumors, such as glioblastomas, are rare, making it difficult for any single hospital to collect enough data for high-accuracy AI training.

Compounding the problem, a model that performs perfectly in one hospital can struggle in another due to differences in patient demographics, data acquisition techniques, and even in equipment. 

Working with visionary researchers like Indiana University’s Dr. Spyridon Bakas, Northwestern University’s Dr. Yury Velichko, and the University of Alberta, Canada’s Dr. Amber Simpson, MedPerf on Google Cloud is validating AI models on private brain MRI data from around the world, and identifying potential performance gaps. 

For example, a model might be 95% accurate at one site but only 63% accurate at another. Our collaborative approach demonstrates that when an AI tool reaches a clinician, it has been proven to work across a truly representative patient population.

Achieving clinical trust and validation

The impact of this collaboration is best summarized by those on the front lines of clinical research. 

"My experience testing federated learning on Google Cloud has shown that the future of medical AI lies in secure, scalable, and collaborative cloud environments," said Dr. Yury Velichko, associate professor, Radiology, Northwestern University. "Moving beyond the controlled lab setting to test these workflows in a production-ready infrastructure provided a unique opportunity to evaluate the performance and security of federated learning in real-world clinical applications.”

"Medical AI holds enormous promise for patients around the world, but that promise can only be realized if clinicians, researchers, and regulators can trust the benchmarks we use to evaluate it,” said Alexandros Karargyris, MedPerf lead, MLCommons. By bringing MedPerf onto Google Cloud's Confidential Computing infrastructure, we have taken a major step toward a future where AI models can be rigorously tested on real patient data — without compromising privacy, intellectual property, or benchmark integrity.”

The future: Scaling secure medical breakthroughs

The collaboration between MLCommons and Google Cloud represents a fundamental shift toward privacy by design in healthcare AI. By making it easier to securely share and evaluate data and models, we are clearing the path for faster, safer, and more equitable medical breakthroughs. 

Research institutions and healthcare model developers interested in using the MedPerf platform on Google Cloud should contact medical@mlcommons.org or your Google Cloud account team.

  •  

Cloud CISO Perspectives: Why AI Threat Defense is the new boardroom baseline

Welcome to the second Cloud CISO Perspectives for July 2026. Today, Chris Betz, CISO, Google Cloud, and Alicja Cade, Senior Director, Office of the CISO, Google Cloud, explain what boards of directors need to know about AI security and how to prepare their organizations for security governance and business agility in the AI era.

As with all Cloud CISO Perspectives, the contents of this newsletter are posted to the Google Cloud blog. If you’re reading this on the website and you’d like to receive the email version, you can subscribe here.

aside_block
<ListValue: [StructValue([('title', 'Get vital board insights with Google Cloud'), ('body', <wagtail.rich_text.RichText object at 0x7fe794699190>), ('btn_text', 'Visit the hub'), ('href', 'https://cloud.google.com/solutions/security/board-of-directors?utm_source=cgc-site&utm_medium=et&utm_campaign=FY26-Q2-GLOBAL-GCP39634-email-dl-dgcsm-CISOP-NL-177159&utm_content=-&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Why AI Threat Defense is the new boardroom baseline

By Chris Betz, CISO, and Alicja Cade, Senior Director, Office of the CISO, Google Cloud

Chris Betz Google-9779

Chris Betz, CISO, Google Cloud

Modern security governance has become a critical part of the foundation for business agility. Often treated as an operational cost center, security is increasingly recognized as a primary business enabler, a runway that empowers your organization to move fast, adopt cutting-edge generative AI, and capture new markets securely.

In today’s environment, every major business initiative is an AI initiative, and every AI initiative requires a secure foundation. Ensuring your company is investing in the right technologies and using the right tools will be crucial in leading through the rapid AI transformation.

Alicja Cade headshot 2

Alicja Cade, Senior Director, Office of the CISO, Google Cloud

To operate against AI speed threats, boards of directors should encourage their CISOs and business leaders to transform their strategic approach for speed, scope, and scale. We need to emphasize risk and vulnerability management with a defensive strategy that’s AI native, agentic, and open.

By aligning defensive speeds with automated attack cycles, using deep internal business context, and integrating tools into unified platforms, AI-powered defense can help you confidently manage today’s threats at machine speed, and simultaneously greenlight aggressive innovation. Based on our learnings defending ourselves and our customers, Google developed AI Threat Defense (AITD) to help transition security from manual, reactive firefighting to an automated, continuous capability.

While directors don’t need to manage the execution of these technologies, they have to provide the governance frameworks that encourage operational modernization. To help guide your organization’s leadership team in this transition, we recommend focusing on these five strategic, constructive areas of inquiry.

For boards of directors, investing in these capabilities helps build the resilience required to drive business velocity.

Key questions for CISOs, business, and tech leadership

While directors don’t need to manage the execution of these technologies, they have to provide the governance frameworks that encourage operational modernization. To help guide your organization’s leadership team in this transition, we recommend focusing on these five strategic, constructive areas of inquiry.

1. Business enablement: When an enterprise transitions to automated threat defense, it is not just closing a security gap — it’s reclaiming engineering productivity and protecting operational continuity.

  • Ask your team: How will modernization investments speed up our business to deliver value to our customers? What additional resources do we need (if any) to create this business value more quickly, and create a competitive advantage? 

  • Governance objective: Ensure that any decisions about investments align with business strategy. Speed up time to market on new features. Create competitive agility advantage for security and shareholders.  

  • Expected operational standard: Consolidate business process, speed up execution and time to market.

2. Remediation cycle: By integrating business logic and context into defensive platforms, AI can help filter out the background noise that has historically overwhelmed security operations, and also keep you on top of the complex threat landscape.

  • Ask your team: How are we managing the organization’s risk in the era of fighting AI with AI? 

  • Governance objective: Expect a management plan with CISO input for balancing business operations, risk, and profitability with speed and reliability in an AI threat-driven world.

  • Expected operational standard: Your organizational mean time to remediate (MTTR) exposures and other desired changes into production goes down and to the right.

3. System consolidation: Boards should look beyond standalone AI features and point products to address systemic risk and truly enable business speed.

  • Ask your team: Are we moving toward a unified security platform, or maintaining a patchwork of point tools? 

  • Governance objective: Reduce visibility gaps and operational friction created by fragmented vendor environments.

  • Expected operational standard: Consolidate scanning, risk prioritization, and code remediation into an integrated workflow.

4. Contextual prioritization: Your organization knows exactly how applications are interconnected, where critical data assets reside, who has access privileges, and which workflows drive actual business logic. That deep context becomes the defender’s advantage when you are using AI powered defenses, including those in AI Threat Defense.

  • Ask your team: How are we using our deep business context to reduce security alert fatigue? 

  • Governance objective: Optimize engineering resources by ensuring teams are not consumed by false-positive alerts.

  • Expected operational standard: Direct AI systems to prioritize vulnerabilities based on actual reachability and business context.

5. AI safety and policy: Every AI conversation is a security conversation. Securing AI infrastructure starts with directing teams toward approved architectures with proper governance.

  • Ask your team: What frameworks do we have in place to secure our internal AI pipelines and monitor shadow AI? 

  • Governance objective: Protect intellectual property and maintain compliance as the enterprise adopts generative tools.

  • Expected operational standard: Implement clear runtime visibility, data egress controls, and secure development standards for AI.

Innovate with confidence

In a highly automated digital environment, passive oversight is no longer practical. Your teams should be looking at how they are using AI to accelerate security and respond to AI-driven threats at AI speed.

By steering the enterprise toward a platform-centered, context-driven security posture, boards can support long-term business resilience, protect asset value, and give the organization the confidence to innovate, scale, and lead in its next phase of growth safely.  Consider technologies like AI Threat Defense as part of your defenses in this new world.

For more insight, check out our Board of Directors hub here.

aside_block
<ListValue: [StructValue([('title', 'Learn something new'), ('body', <wagtail.rich_text.RichText object at 0x7fe794699220>), ('btn_text', 'Watch now'), ('href', 'https://www.youtube.com/watch?v=CmGWIwgHR60'), ('image', <GAEImage: Cloud-CISO-Perspectives-logo-A>)])]>

In case you missed it

Here are the latest updates, products, services, and resources from our security teams so far this month:

  • Now in preview: Find and fix software vulnerabilities with CodeMender: Our AI code security agent CodeMender can scan and fix software vulnerabilities, and is now available in preview through Agent Platform and AI Threat Defense. Read more.
  • Cyber Snapshot Report: Enterprise resilience key to toolchain success: Check out curated frontline insights and blueprints to turn potential crises into manageable events in the newest Cyber Snapshot Report. Read more.
  • Future-proofing data integrity: Quantum-safe digital signatures in Cloud KMS: TWe are extending the PQC digital signature algorithms suite available in Google Cloud Key Management System to include ML-DSA and SLH-DSA. Here’s why. Read more.
  • Atlas, Wiz's autonomous vulnerability-research agent, has been ranked #1 on CyberGym: See how Wiz built Atlas, an autonomous AI system for vulnerability research that validates every finding with a real, working exploit. Read more.
  • Best Buy scales AI workloads and secures access with Workforce Identity Federation: As Best Buy expanded its use of Google Cloud for advanced analytics and AI, its technology teams faced two significant scaling challenges: Mitigating risk and managing administrative friction when syncing thousands of backend users from Microsoft Entra ID. Here’s how Workforce Identity Federation helped them solve both problems. Read more.
  • The risk hiding behind exposed MCP servers: Learn how unauthenticated model context protocol (MCP) servers are opening doors to sensitive cloud data, IAM, and command execution. Read more.
  • Agentless threat detection: Illuminating cloud blind spots: Learn how Agentless Workload Detection exposes hidden threats in virtual appliances and modern cloud networks. Read more.
  • AlloyDB adds group authentication to secure enterprise scale and AI agents: We’re bringing identity-driven access control to your enterprise workloads through IAM group authentication for AlloyDB, now available in preview. Read more.

Please visit the Google Cloud blog for more security stories published this month.

aside_block
<ListValue: [StructValue([('title', 'Join the Google Cloud CISO Community'), ('body', <wagtail.rich_text.RichText object at 0x7fe794699040>), ('btn_text', 'Learn more'), ('href', 'https://rsvp.withgoogle.com/events/google-cloud-ciso-community-interest-form-2026?utm_source=cgc-blog&utm_medium=blog&utm_campaign=FY25-Q1-global-GCP30328-physicalevent-er-dgcsm-parent-CISO-community-2025&utm_content=cisop_&utm_term=-'), ('image', <GAEImage: GCAT-replacement-logo-A>)])]>

Threat Intelligence news

  • Updated cyber threat actor naming system: Google Threat Intelligence Group (GTIG) has begun rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Read more.
  • Demystifying AI exploits: A blueprint for AI-assisted vulnerability management: Concerned about how to safely integrate AI capabilities into vulnerability management workflows? Here’s actionable guidance from Mandiant Consulting on establishing operational guardrails for AI assisted vulnerability management, including detailed scenarios. Read more.
  • GhostApproval: A trust boundary gap in AI coding assistants: Learn how Wiz uncovered a category-level blind spot in modern AI coding assistants, and why the human-in-the-loop safety model fails against this classic threat. Read more.
  • The risk of exposed cloud functions and how to harden: Mandiant uses recent lessons from customer engagements to describe attack scenarios and provide actionable guidance on how to secure serverless environments. While this analysis focuses on hardening strategies for Google Cloud Run services and functions that must remain publicly accessible, these principles apply universally to any public serverless deployment. Read more.

Please visit the Google Cloud blog for more threat intelligence stories published this month.

Now hear this: Podcasts from Google Cloud

  • Cloud Security Podcast: CISO tested, board approved: Noah Korba, vice-president, Digital Core, Cybersecurity, and Enterprise Architecture, General Mills, goes under the hood of Mills Collaborative Recovery, the company’s intensive, annual two-week drill that recovers 90% of their Google Cloud estate to test real-world cyber resilience. Listen here.
  • Cloud Security Podcast: Creating trust at global scale with local AI: Shuman Ghosemajumder, CEO, Reken, traces the evolution of automated fraud, from Gmail's early invite days to the origin of credential stuffing. Listen here.
  • Defender’s Advantage: Shadow LLMs, agentic identities, and securely integrating AI: Join Muhammad Muneer, technical manager, Incident Response, Mandiant, as he unpacks the stark realities of enterprise AI adoption. Listen here.
  • Behind the Binary: The challenges of reversing modern languages: Jae Young Kim from the Mandiant FLARE team discusses navigating how software has evolved, and what it actually takes to reverse engineer modern compiled languages like Go and Rust. Listen here.

To have our Cloud CISO Perspectives post delivered twice a month to your inbox, sign up for our newsletter. We’ll be back in a few weeks with more security-related updates from Google Cloud.

  •  

AlloyDB adds group authentication to secure enterprise scale and AI agents

Database security traditionally relies on a fragile balance between the granular control developers need and the administrative overhead of managing thousands of individual database passwords. Between managing AI agent access, rotating static credentials, handling employee on-boarding and off-boarding, and auditing access logs, passwords remain an operational tax — and a potential security vulnerability. 

At Google Cloud, our goal is to help make database access transparent, secure, and passwordless. 

Today, we are taking an important step forward in that journey. We’re announcing Identity and Access Management (IAM) group authentication for AlloyDB, available in preview. This capability brings identity-driven access control to your enterprise workloads. 

Cloud SQL customers have already adopted this authentication pattern with great success, and this launch unifies our security stance across both services.

The problem with individual scale

For years, both Cloud SQL and AlloyDB have mapped individual Google Cloud identities directly to database users using native IAM authentication. However, at enterprise scale, managing access on an individual basis can introduce significant complexity. 

Without group-based management, scaling to hundreds of instances and thousands of users creates distinct challenges:

  • On-boarding bottlenecks: Every new team member requires individual database user provisioning.

  • Off-boarding risks: Ensuring an employee’s access is entirely removed across a distributed database environment can complicate auditing.

  • Policy drift: Maintaining identical permissions across development, staging, and production systems becomes highly error-prone.

Faced with these challenges, it is tempting to use a single, powerful user or service account to serve a whole application. However, oversimplifying access for such powerful application accounts comes at the cost of risk exposure and loss of granular auditing capabilities.

Securing the future of agentic AI

The scale challenge isn't just about human users anymore. As organizations deploy an increasing number of AI agents, managing database identity and access controls will become more complex.

If an AI agent connects to a database using a generic, shared account, or a broad service account, it risks acting as a confused deputy. When using credentials with overly-powerful permissions instead of carrying through the user’s identity, an agent could access or modify data beyond what the end user requesting the action is authorized to see. Crucially, it can hide individual accountability from audit logs because actions map to a generic service account.

Granular authentication can help mitigate this risk. Agents can pass the end user’s specific identity and authentication scope through to the database layer so that queries are run on behalf of the user, limiting data access to objects that an end user is allowed to.

image1

Passing user group identity through an AI agent to AlloyDB allows the database to authorize access and record precise audit trails.

IAM group authentication simplifies this architecture. Instead of managing micro-permissions for every combination of agent and user, security teams can define up to 200 functional Google Groups (such as financial-agents@company.com or regional-analysts@company.com). Google Cloud’s managed database infrastructure validates the user's group context, helping ensure the database authorizes data access at the database or table level while audit logs capture exactly what data was accessed, modified, and on whose behalf.

Proven value for digital leaders

Enterprises are already improving their operational velocity by adopting centralized identity principles. Bilt, a leading platform rewards program, uses our unified approach to help enhance the security of its high-scale database environments:

"By combining AlloyDB’s group-based IAM with our automated group management and Privileged Access Manager (PAM) entitlements, we've eliminated the risk of shared credentials entirely. Database and role provisioning are now fully templated from day one, allowing our engineers to securely access only the data they need and exactly when they need it," said Kosta Krauth, CTO, Bilt.

A unified blueprint for passwordless access

With this launch, Google Cloud provides a unified approach for access control across both Cloud SQL and AlloyDB. Organizations can now enforce a standardized, defense-in-depth access strategy across their relational database portfolio.

By pairing IAM group authentication with features like VPC Service Controls, Organization Policies, IAM conditions, and Private Service Connect, security teams can help ensure that database access — whether by a human engineer or an autonomous AI agent — is bound to verified corporate identities and secure network perimeters.

Moving toward a Zero Trust database future

Security shouldn't force a trade-off between engineering velocity and compliance. By integrating AlloyDB with Cloud Identity and Workforce Identity Federation, we are removing the friction of database administration while helping you implement a more secure architecture.

You can explore how to set up group-based database roles by trying out the feature today. You can find more recommendations and best practices for security and compliance in our documentation.

  •  

Future-proofing data integrity: Quantum-safe digital signatures in Cloud KMS

With cryptographically relevant quantum computers (CRQC) on the horizon, transitioning to quantum-safe digital signatures is critical to safeguarding long-term data integrity and authenticity. Organizations are steadily recognizing this urgency. 

For example, the U.S. government announced an update to the timelines by which departments and agencies must transition to quantum safe digital signatures. To help with the transition, we are announcing the general availability of our quantum-safe digital signatures (ML-DSA, SLH-DSA) and post-quantum key encapsulation (ML-KEM) in Google Cloud Key Management Service (Cloud KMS).

The immediate challenge for your organization is functional: You need to sign massive data payloads without encountering the bandwidth and processing issues inherent with post-quantum cryptography (PQC). To proactively address these emerging threats and help you support compliance with regulatory obligations, you can use the suite of PQC digital signature algorithms available in Cloud KMS, which includes ML-DSA (FIPS 204) and SLH-DSA (FIPS 205), featuring dedicated support for the efficient external-µ variants. 

PQC digital signature algorithms in Cloud KMS

As standards and regulatory institutions are setting requirements and timelines for adopting quantum-safe algorithms, such as the National Security Agency’s CNSA 2.0, they’re underscoring the need for organizations to start their migration planning. To help you choose the specific security strength and signing method necessary for your applications, Cloud KMS gives you a broad selection of ML-DSA and SLH-DSA algorithms that are publicly available.

Cloud KMS now supports the following PQC algorithms and variants:

Algorithm Name

NIST Security Category

Variant Type

Description

SLH-DSA-SHA2-128s

Level 1

Pure, Pre-hash

Stateless Hash-Based Digital Signature for defense-in-depth

ML-DSA-44

Level 2

Pure, External-µ

High performance, Level 2 quantum security (equivalent to a collision search on SHA-256)

ML-DSA-65

Level 3

Pure, External-µ

Balance of security and performance, Level 3 quantum security (equivalent to an exhaustive key search on AES-192)

ML-DSA-87

Level 5

Pure, External-µ

Highest security for long-term data protection, Level 5 quantum security (equivalent to an exhaustive key search on AES-256)

The need for pre-hash and external-µ variants

The cryptographic elements used for digital signatures have a fixed or predictable size in memory. In contrast, the message being signed can range from a few bytes to massive files. This size disparity creates a major challenge when you use a separate, secure device, such as an HSM or a dedicated key management service. 

These systems are often optimized for security and key operations, but they have limited bandwidth and processing power, making it impractical or impossible to securely transmit and process extremely large messages in the security boundary for signing. Therefore, the application first processes the large message locally using a cryptographic hash function (such as SHA2 or SHAKE) to create a fixed-size, small digest that is around 32 bytes. The application then sends this small digest to the hardware security module (HSM) or key management service for the actual signing operation using the private key. 

NIST’s ML-DSA standard, FIPS 204 (Algorithm 7), uses an external-µ variant for its prehash functionality, which helps with this workflow. RFC 9881 Appendix D describes the details of external-µ. This method allows the application to calculate the digest (also called the message representative) externally and feed it into the pure ML-DSA signing algorithm. This offers the best of both worlds: The bandwidth efficiency of a pre-hash workflow, and full compatibility with pure ML-DSA verifiers.

These external-µ variants also bind the public key mathematically to the message representative to achieve non-resignability, an important security property that prevents an attacker from manipulating the message representative in a way that verifies under a different, possibly attacker-controlled key. You can learn more details here, and explore the BoringSSL implementation for a practical example of handling external-µ.

Google Cloud KMS now supports the pre-hash and external-µ variants. This enables high-performance, low-latency signing workflows that securely handles large payloads via external hashing, while integrating with pure verifiers.

Getting started with PQC signatures in Cloud KMS

Your applications can integrate these algorithms through the Cloud KMS API. Developers can use existing Cloud KMS capabilities to create, manage, and use PQC keys for signing operations. Detailed instructions and code samples are available in our KMS documentation to guide you through the process.

The PQC road ahead

The transition to a post-quantum cryptographic landscape is a collaborative journey. Adding PQC digital signatures in Google Cloud KMS is a significant milestone, helping you with your quantum-safe migration strategies.

We will continue to update our services to incorporate future NIST standards and guidance, helping you maintain the security of your critical systems. We look forward to collaborating with you on your specific cryptographic needs, and we welcome your feedback.

  •  

Best Buy scales AI workloads and secures access with Workforce Identity Federation

As Best Buy expanded its use of Google Cloud for advanced analytics and AI, its technology teams faced two significant scaling challenges: Mitigating risk and managing administrative friction when syncing thousands of backend users from Microsoft Entra ID. 

The retailer solved both problems and paved the way for a massive cloud expansion by implementing Google Cloud's Workforce Identity Federation. This direct approach allowed developers to access cloud resources securely using their existing Microsoft credentials without a separate identity store, giving technical leadership confidence that access remains strictly controlled, auditable, and manageable at scale.

Replacing service accounts with direct federation

Best Buy historically maintained complex synchronization pipelines to copy backend users from Entra ID to Google Cloud. Because the organization used Cloud Identity without a Google Workspace deployment, it needed a more direct approach. Previously, Best Buy's Power BI integration with BigQuery relied on service account credentials. 

This pattern can work at a small scale, but quietly becomes a liability as your team grows.

Manually rotating keys for service accounts meant tracking the credentials each team held, and accepting that every key was a potential security vulnerability. Service account keys created daily friction for the Best Buy security and platform teams, and the technical debt compounded as data access requirements grew more complex.

To support tens of thousands of users, Best Buy modernized its identity architecture. The team adopted Workforce Identity Federation to federate existing Entra ID identities directly into Google Cloud. 

Now, when developers access BigQuery through Power BI, they authenticate as themselves using their existing Entra ID identity. They no longer need to rotate keys, worry about credentials exposed in chat messages, or guess who performed an action in the audit log.

The architecture relies on two components working together: Entra ID handles authentication, Workforce Identity Federation brokers the trust relationship between Entra ID and Google Cloud. This federation is stateless on Google's side. It validates tokens at the moment of access instead of syncing user records. Removing the service account key layer greatly reduces the credential management burden.

Architecture

The diagram below shows how identity flows from Entra ID through the Workforce Identity Federation to the services teams use at Best Buy. The key change from the previous approach is the removal of the service account key layer entirely; there is no credential to manage between Entra ID and Google Cloud.

Best Buy architecture diagram no MSFT logo

Identity flows from Entra ID through the Workforce Identity Federation to the services teams use at Best Buy

Key implementation decisions

When implementing this architecture, Best Buy made several important technical choices:

  • Separate provisioning and SSO apps in Entra ID: The configuration follows the Entra ID provisioning and single sign-on (SSO) setup guide. You should separate the provisioning application from the SSO application in Entra ID. Running them as two distinct enterprise apps provides a cleaner separation of concerns; provisioning changes do not affect SSO configuration, and vice versa.

  • Place the automation OU carefully: You need to place the Entra ID provisioning service account in a separate organizational unit (OU) and explicitly disable SSO for that OU. This prevents a bootstrapping problem: If you enforce SSO globally, the provisioning account cannot authenticate to set up the provisioning in the first place.

  • Understand that syncless means stateless on Google's side: Workforce Identity Federation does not create or maintain user records in Cloud Identity. It validates tokens at the moment of access. This makes the architecture viable for Best Buy's target scale, because it eliminates synchronization lag, stale record cleanup, and separate provisioning pipelines.

Secure authentication for developers

For developers, the change was practically invisible. They authenticate once through their corporate Entra ID credentials, and access to BigQuery works automatically, whether through Power BI or direct API calls. The SSO experience matches everything else they access through their Microsoft identity.

For the security and platform teams, the benefits are significant. The attack surface from credential management disappears. Audit logs now show individual users instead of shared service account identities, and you can revoke access quickly based on the enterprise identity lifecycle rather than waiting for manual key rotation.

If you currently manage service account keys for developer access to Google Cloud, moving to Workforce Identity Federation is worth the effort. You gain significant security benefits, and the operational simplicity grows as your team expands. Best Buy is currently scaling this secure access to a broader workforce to power its future retail operations.

Expanding Workforce Identity Federation support

Google Cloud continues to make it easier for all organizations to bring their own identity providers. Recent updates simplify the setup for Ping Identity users and extend access to online billing accounts.

  • Ping Identity integration: If you use Ping Identity, you can follow a new, dedicated setup guide to configure federation. This guide provides step-by-step instructions so you can securely connect your workforce to Google Cloud resources.

  • Online billing support: Google Cloud now supports customers with online billing accounts. You can use Workforce Identity Federation for secure, syncless access without needing an enterprise billing agreement.

Get started

Google Cloud is committed to removing friction from cloud adoption and making it simpler for organizations to secure their environments. To explore these new capabilities and connect your organization's identity provider, read more about how Workforce Identity Federation allows you to federate identities directly, and explore our supported Google Cloud services.

  •  

Cyber Snapshot Report: Go beyond the toolchain and build enterprise resilience

Even as machine-speed attacks dominate the headlines, Mandiant’s view from the frontline reveals that the vast majority of successful intrusions still stem from fundamental human and systemic failures.

This operational break-down shows up pointedly in research from the M-Trends 2026 report. Exploits remain the most common initial infection vector for the sixth consecutive year at 32%, voice phishing surged to second place at 11%, and prior compromise was the number one confirmed vector for ransomware-related incidents, according to the report.

To stay ahead, leaders should shift from prevention-focused strategies to an operating model where compromise is anticipated, exploitation is recognized as inevitable, and a continuous, intelligence-led feedback cycle leads their defense. Business and security leaders should rethink how they architect and implement resilience strategies and train cross-functional teams. At the same time, they should also systematically address technical debt and organizational security culture. 

To help your team navigate this reality, we have curated the frontline insights and blueprints you need to turn potential organizational crises into manageable events in the newest Defender’s Advantage: Cyber Snapshot Report.

Hardening architecture to contain blast radius

When we accept that intrusions will happen, the goal of security shifts from keeping attackers out to containing their impact. 

Ransomware operators now aggressively target recovery paths — virtualization hypervisors, backup environments, and privileged access management (PAM) vaults — to deny organizations the ability to restore operations and maximize the pressure to negotiate. Hardening the architecture means implementing strict credential separation and air-gapped isolated recovery environments (IRE) to help verify that a compromise in the production network can not destroy backups.

However, containing the blast radius also requires securing soft entry points beyond traditional data centers — starting with your executives and high-value personnel. Threat actors increasingly target personal digital footprints, including personal devices, home networks, and family members, as entry points into critical corporate infrastructure. 

A resilient posture should expand to protect this extended ecosystem, integrating digital footprint management with traditional executive protection programs. 

Forging readiness for the inevitable crisis

While architectural guardrails can limit the physical reach of an attacker, human readiness and decision-making often determines how quickly your organization can respond and recover.

This capacity can only be forged from first-hand experience. While policy can encourage its growth, enabling a culture of "safe failure" supported by immersive learning and mentoring can help teams to build the collective muscle memory needed to manage high-stress incidents.

This human readiness is tested even further as adversaries embrace automation. Recent research by the Google Threat Intelligence Group (GTIG) identified the first known zero-day exploit developed with AI. This finding, combined with the intense industry focus on AI-driven vulnerability discovery, has driven many organizations to search for a quick technological countermeasure.

While AI-assisted discovery provides advanced technical capabilities for defenders, it requires integrating these automated tools into a mature, structured program that aligns people and processes. By transforming raw discovery into a continuous, risk-based readiness capability, teams can overcome alert fatigue and achieve both machine-speed execution and strategic control.

Activate your Defender's Advantage today

Technology alone will not define your cyber defense outcomes. True resilience lies in preparing your team, hardening your architectures, and practicing under pressure. 

To help arm your organization with the frontline insights needed to navigate evolving threats confidently, you can download your copy of The Defender’s Advantage: Cyber Snapshot Report, Issue 8, today.

  •