VOOZH about

URL: https://thenewstack.io/a-look-at-the-palo-alto-networks-upcoming-code-to-cloud-summit/

⇱ A Look at the Palo Alto Networks' Upcoming Code to Cloud Summit - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2022-03-15 13:12:05
A Look at the Palo Alto Networks' Upcoming Code to Cloud Summit
podcast,sponsor-palo-alto-networks,sponsored,sponsored-podcast-video,the-new-stack-makers,
Security

A Look at the Palo Alto Networks’ Upcoming Code to Cloud Summit

A preview of what’s to come at Palo Alto Network’s Code to Cloud Summit including the role of security and trust as it relates to DevOps, cloud service providers, software supply chain, SBOM and IBOM.
Mar 15th, 2022 1:12pm by Celeste Malia
👁 Featued image for: A Look at the Palo Alto Networks’ Upcoming Code to Cloud Summit
Palo Alto Networks sponsored this post.

From cloud security providers to open source, trust has become the foundation from which an organization’s security is built. But with the rise of cloud native technologies such as containers and infrastructure as code (IaC), it has ushered in new ways to build applications and requirements that are challenging the traditional approaches to security. The changing nature of the cloud native landscape is requiring broader security coverage across the technology stack and more contextual awareness of the environment. But how should teams like Infosec, DevOps rethink their approach to security?

In this episode of The New Stack Makers podcast, Guy Eisenkot, co-founder and vice president of product at Bridgecrew, Barak Schoster Goihman, senior director, chief architect at Palo Alto Networks and Ashish Rajan, head of security and compliance at PageUp and producer and host for Cloud Security Podcast preview what’s to come at Palo Alto Network’s Code to Cloud Summit on March 23-24, including the role of security and trust as it relates to DevOps, cloud service providers, software supply chain, SBOM (Software Bill of materials) and IBOM (Infrastructure Bill of Material).

Alex Williams, founder and publisher of The New Stack, hosted this podcast.

Securing the Modern Enterprise with Trust: A Look at the Upcoming Code to Cloud Summit

According to Gartner, companies will deploy 95% of new digital workloads on cloud native platforms by 2025. As this trend continues to be embraced, it introduces more complexity that makes it hard to secure and evades questions around trust. “If you want to really sleep well at night and have trust with your engineering teams, you should find the best way to have a lot of answers to questions like what open source packages am I using? What kind of infrastructure is in my provisioning? What third-party cloud providers am I using very early on and every step of the way,” said Goihman.

With serious vulnerabilities like Log4j that posed a severe risk to many enterprises, the shared responsibility model between cloud service providers and organizations has also tested the trust line. “Companies like Amazon as well as Google Cloud had to come up with services to counter account for what they are exposing us to. They have a script now that consistently checks for Log4j. So now the question of trust comes in: are you okay to have that script running? And having outages is something that tests the trust boundary,” said Rajan.

Prisma Cloud delivers the industry’s broadest security and compliance coverage—for applications, data, and the entire cloud native technology stack—throughout the development lifecycle and across multi- and hybrid-cloud environments.
Learn More
The latest from Prisma by Palo Alto Networks

While security practices are being sharpened to new threats, there’s still a lot of work ahead to create a world-class culture, spread awareness and increase strong cyber-hygiene. “I think we must be much more thoughtful on how we treat our corporate code repositories. I think we need to do a much better job of knowing what’s in there; what those corporate party repositories are connected to; where are they streaming data from; what environment and environment variables they’re using across the board,” said Eisenkot.

Modern applications built from many components can be developed in-house and off-the-shelf, but it has left many to rethink cloud security. “Having all those different kinds of assets: infrastructure, code, container images, open source packages, and the workflow of delivery pipelines in the code repository, can give us the full picture of the supply chain. And we can build a Software Bill of Materials off open source packages for infrastructures code, which is like a runtime bill of material that helps us to prioritize the bad code,” said Goihman.

As security shifts leave developers accountable for securing code, many teams are overwhelmed and struggling to keep up with the pace of modern software development. But having a complete view of where potential vulnerabilities or misconfigurations exist can also help prioritize and offer the context of where a vulnerability fits into the layers of a cloud architecture. “Developers want to produce code, but simply giving them a vulnerability is simply not good enough because they don’t have a context on what they’re trying to solve and why they need to solve it,“ said Rajan.

Prisma Cloud delivers the industry’s broadest security and compliance coverage — for applications, data, and the entire cloud native technology stack — throughout the development lifecycle and across multi- and hybrid-cloud environments.
Learn More
The latest from Palo Alto Networks
TRENDING STORIES
Palo Alto Networks sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Pragma.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.