Upcoming Lectures & Classes

Join me at these upcoming events and training sessions

Professional cloud security training and certification programs designed to help organizations gain the relevant knowledge and expertise for secure cloud adoption.

Certification Programs

Industry-recognized certifications from leading organizations

TAISE Logo

TAISE - Trusted AI Safety Expert

Provider: Cloud Security Alliance & Northeastern University

AI Security

The Trusted AI Safety Expert (TAISE) certificate equips professionals to lead the safe, secure, and responsible development and deployment of AI systems. The industry-leading credential covers the full AI lifecycle from generative AI fundamentals and architecture to governance, risk management, privacy, and cloud security.

  • 10-module course - from basic concepts to behind the scenes of AI engines
  • Integration with modern cloud services
  • Unique, innovative and well-defined content
  • Includes training + exam with 2 attempts
CCSK Logo

CCSK - Certificate of Cloud Security Knowledge

Provider: Cloud Security Alliance

Foundation

Certificate of Cloud Security Knowledge (CCSK) was created by the Cloud Security Alliance in 2010 to address the growing need for security knowledge around cloud computing. CCSK certification covers all major aspects in information security including risk management, provider evaluation, infrastructure and application security, identity management, and highlights the recommended approaches and tools required for secure cloud adoption.

CCSK Foundation (2 days)

Frontal teaching of 6 modules covering all topics relevant to cloud security. Contains all information needed for passing the CCSK exam. Exam voucher included.

CCSK Plus (+1 day)

Additional day devoted to practicing cloud labs. Students practice different security tools available for IaaS/PaaS environments.

Includes class kit with books, labs, and two vouchers for the CCSK exam.

CCSP Logo

CCSP - Certified Cloud Security Professional

Provider: ISC2

Advanced

The globally recognized CCSP cloud security certification demonstrates advanced technical skills and knowledge to design, manage and secure data, applications and infrastructure in the cloud using best practices established by ISC2's certified members and cybersecurity experts.

Cloud Concepts Architecture & Design Cloud Data Security Cloud Platform & Infrastructure Security Cloud Application Security Cloud Security Operations Legal Risk & Compliance

As a CCSP founding committee member and co-author, I provide unique insights into the certification.

Custom Training Programs

Tailored training for your organization's specific needs

Cloud Secure Architecture Training

Duration: 8 hours | Audience: SecOps, Security Architects, AppSec, Project Managers

Technical

Building secure cloud architecture from the ground up.

View Modules
General Concepts and Terminology

Cloud services overview, key concepts: Snapshot, CWPP, CNAPP, Flow Logs

Network Architecture Highlights (IaaS/PaaS)

VPC design, firewall services, WAF configurations, remote connectivity

Identity Management in Cloud Environments

OUs and policies, federation protocols, IdP, identity management processes

Workload Management

VMs, Containers, Kubernetes, Serverless, EDR/CWPP/Kubernetes Runtime

Data Security

Storage types, encryption, masking, tokenization

Configuration Monitoring (Posture Management)

CNAPP/CSPM/ASPM/SSPM concepts, open-source tools

SIEM & Incident Response

SIEM architecture, log collection, incident detection, response automation

Developers Security Training

Duration: 2-6 hours | Audience: Developers, Architects, AppSec Professionals

Technical

What developers need to know about cloud security.

View Modules
Why Cloud is Changing Application Security

Key architecture concepts: VPC, IAM, WAF, CDN; New workloads: Kubernetes, Serverless

Secure SDLC in Cloud Environments

Adapting SSDLC practices, threat modeling for cloud applications

CI/CD Security

Security considerations in CI/CD design, recommended architecture and gates

Security Testing & Shift-Left/Right

SAST, DAST, SCA, Secrets scanning, IaC scanning, Vulnerability scanning, Penetration testing

Application Security Operations

WAF, API Gateway, Ingress controllers, DDoS protection

AI in Application Development

Secure architecture considerations for AI services

Cloud Threats & Risks Training

Duration: 2-4 hours | Audience: All Security Professionals, Developers, Architects

All Levels

Understanding cloud attack vectors based on CSA research.

View Modules
Introduction to Cloud Attack Vectors

CSA research on IaaS/PaaS attack vectors, connection between risks, threats, and vectors

Real-World Attack Examples and Analysis

Characteristics and methodologies, incident examples, impact analysis

Mitigating Controls & Best Practices

Security controls, architectural defense strategies, proactive practices

Cloud Detection & Response Training

Duration: 4-8 hours | Audience: SecOps, Incident Responders, Level 3 Analysts, DevOps

Expert

Cloud incident response and forensics.

View Modules
General Concepts and Terminology

Cloud IR lifecycle, legal and compliance considerations in cloud forensics

Focus on IaaS/PaaS Forensics

Data sources (CloudTrail, VPC Flow Logs), evidence collection, attack scenario analysis

SaaS Services Forensics

Microsoft 365, Google Workspace, Salesforce incident response

Resources

Open-source tools, commercial solutions, case studies

Cyber Security for Startups

Duration: 2-4 hours | Audience: Founders, CTOs, R&D Managers, Security Teams

All Levels

Building security for SaaS startups from day one.

View Modules
Introduction & Motivation

Security as a driver for trust and go-to-market readiness

Cloud Architecture Across Growth Phases

Secure design decisions for each startup lifecycle phase

Developer-Centric Security

Building security into development workflows, DevSecOps practices

Governance, Risk & Compliance (GRC)

CSA CCM, SOC 2, ISO 27001 mapping to startup maturity

Identity & Data Protection

Scaling IAM, BYOK, encryption, data residency

Incident Response & Security Visibility

Logging and monitoring maturity, practical IR strategies

Past Lectures

A selection of recent speaking engagements and training sessions

Featured Lectures

Cloudefigo: Automated IaaS Security at Scale

Black Hat 2016 | Nir Valtman & Moshe Ferber

Watch Video →

A deep dive into automating cloud security using Cloudefigo, an open-source framework for hardening IaaS environments. The talk covers practical techniques for deploying secure, pre-configured instances with encrypted storage and automated vulnerability assessment using AWS Cloud-Init.

From 0 To Secure In 1 Min: Securing IaaS

DEFCON 23 | Nir Valtman & Moshe Ferber

Watch Video →

Introducing "Cloudefigo" - an open source tool enabling accelerated security lifecycle for cloud instances. Demonstrates launching pre-configured, patched instances into encrypted storage environments while automatically evaluating and mitigating vulnerabilities using AWS EC2 Cloud-Init scripts.

Understanding Cloud Attack Vectors

CISO Platform | Moshe Ferber

View Lecture →

This webinar covers popular IaaS/PaaS attack vectors, list them, and map to other relevant projects such as STRIDE & MITRE. Security professionals can better understand what are the common attack vectors that are utilized in attacks, examples for previous events, and where they should focus their controls and security efforts.

View Past Events (2012-2023)

2023

CCAK Class – with ISACA

Tel Aviv | December 19, 2023

CCSK Plus – Public Class

Ramat Gan | October 22, 2023

Cyberweek 2023 – CSA Israel Event

Tel Aviv | June 26, 2023

CCSK Plus – Including Labs

Tel Aviv | June 4, 2023

CCSK Foundation – Special Edition Including Cloud Governance

Virtual, Singapore Time Zone | May 29, 2023

Cloud Security Session at Innotech

Tel Aviv | March 29, 2023

Cloud Attack Vectors – Research Overview

Virtual | March 28, 2023

2022

CCSK Plus Class

See Security College | November 28, 2022

Digital Solutions and Resilience of Supply Chain

Tel Aviv University | November 21, 2022

CSA Top Threats – Presenting Threats and Risks

Virtual | November 20, 2022

CCSP Workshop

AWS Offices, Tel Aviv | November 7, 2022

CCAK Certification Class

Tel Aviv | November 6, 2022

Challenges with Cloud Security

Virtual | September 20, 2022

Managing Cloud Computing Risks – ISACA Workshop

Online | September 15, 2022

CCSK Foundation – Remote Training

Online (BSI) | September 12, 2022

CSA Israel Annual Event @ Cyberweek

Tel Aviv University | June 27, 2022

CCSK Foundation @ Cyberweek

Tel Aviv University | June 26, 2022

Lawyers Bar – Cloud Security Lecture

Tel Aviv | May 31, 2022

2021

CCAK Training

Israel (ISACA) | December 12, 2021

CCAK Training – CISO Cloud Summit

Milan, Italy | December 1, 2021

CCAK Training – ISACA EU Conference

Helsinki / Virtual | October 18, 2021

CCSP Training

See-Security College | October 17, 2021

CCAK – Meet the Authors

Virtual | August 4, 2021

CSA Event at Cyberweek 2021

Tel Aviv University + Online | July 21, 2021

CCSP Formal Class (Hebrew)

See-Security, Ramat Gan | July 5, 2021

Israclouds CISO Event

Virtual | June 30, 2021

Building Secure Cloud Architecture

Virtual (AppSec Meetup) | June 24, 2021

CCAK Frontal Training (Hebrew)

Deloitte, Tel Aviv | June 20, 2021

CCAK First Formal Training

Virtual | May 24, 2021

Understanding Chain of Supply Risks (Hebrew)

Virtual | April 26, 2021

What the Auditor Needs to Know About Cloud Computing – CSA EMEA 2021

Virtual | April 13, 2021

Secure Your Cloud Data – Embedded Tech Conference

India (Virtual) | March 26, 2021

CSA Israel Meetup – Exploring Cloud Identities

Virtual | March 18, 2021

Data Security Meetup

Virtual | February 23, 2021

CSA Israel Quarterly Meetup

Virtual | February 15, 2021

2020

CCSK Foundation Training – Cyberweek 2020

Online | October 22, 2020

Cyberweek – CSA Innovation Summit

Online | October 20, 2020

ISACA College – What the Auditor Needs to Know About Cloud Security

Online | October 13, 2020

3 Days CCSK Plus – Australia

Brisbane, Australia | September 7, 2020

Economic Times – Datacon

Virtual | September 3, 2020

CCSK Plus – Australia

Perth, Australia | September 2, 2020

CCSK Plus 3 Days Online Class

Online | July 15, 2020

CCSK Plus 3 Days Online Class

Online | June 15, 2020

CCSK Plus – 3 Days Online Training

Online | May 25, 2020

CCSK Public Class

TBD | January 13, 2020

2019

Cyber Security, From Liability to a Business Advantage

Nielsen Marketing Cloud, Tel Aviv | November 12, 2019

Cloud Security Certifications Landscape

AWS, Tel Aviv | September 3, 2019

Israclouds & CSA Israel Security Architecture Meetup

AWS, Tel Aviv | June 26, 2019

CCSK Foundation – Cyberweek 2019

Tel Aviv University | June 24, 2019

Cloud Security Alliance Tel Aviv Summit

Tel Aviv University | June 24, 2019

CISO Challenges – Israclouds Event

Cisco, Netanya | April 11, 2019

Cloud Security Certifications – ISC2 & CSA IL Event

Appsflyer | February 26, 2019

2018

CSA Annual Event – Financial Sector and the Cloud

Tel Aviv University (Cyberweek) | June 18, 2018

CCSK Foundation – Cyberweek 2018

Tel Aviv University | June 17, 2018

CISO Challenges – Cyber Defense Congress

Kiev, Ukraine | June 5, 2018

CISO Challenges with Cloud Security – SECURE 2018 Congress

Mumbai, India | March 21, 2018

Cloud Security for Startups – CITI Bank Accelerator

Tel Aviv | February 27, 2018

CCSK Foundation + Plus

BDO Offices, Tel Aviv | February 5, 2018

CCSK Foundation + Plus

HP, Raanana | January 21, 2018

2017

CCSK Foundation

See Security College | December 21, 2017

Workshop: Securing Infrastructure As A Service (IaaS)

Bangalore, India | November 10, 2017

CISO Challenges with Cloud Computing – Internet & Mobile World

Bucharest, Romania | October 4, 2017

Building Government Clouds – RSA Singapore

Singapore | July 27, 2017

CCSK Foundation

See Security College | July 12, 2017

Clouday – CSA Israel Annual Event

Tel Aviv University (Cyberweek) | June 29, 2017

CCSK Foundation – Cyberweek

Tel Aviv University | June 28, 2017

Cloud Security for Startups – Infosec Israel

Tel Aviv | May 23, 2017

CCSK Foundation & Plus

HP Education, Raanana | April 26, 2017

Cloud Security for Startups – From A to E(xit)

Google Campus, Tel Aviv | March 19, 2017

How the Cyber Industry Contributing to a More Resilient Society

The Royal Society, London | February 28, 2017

CCSK Foundation

See-Security College | February 16, 2017

CCSK Foundation + Plus

HP Education, Raanana | January 11, 2017

2016

CISO Challenges with Cloud Computing – Citrix Israel User Group

Rishon LeZion | December 15, 2016

CISO Challenges with Cloud Computing – Oracle Week

Herzliya | December 8, 2016

CCSK Foundation + Plus

HP Education, Raanana | November 23, 2016

CCSK Foundation Training

Madrid, Spain (CSA EMEA Congress) | November 14, 2016

Cloud and Web-based Application Security Foundation

SKILIT, Rehovot | September 25, 2016

CCSK Foundation + Plus

HP Education, Raanana | September 14, 2016

CCSK Foundation & Plus

HP Education, Raanana | June 27, 2016

The CISO Challenge – Cyberweek TLV

Tel Aviv University | June 22, 2016

Building Government Clouds

Infosec Israel | May 31, 2016

Building Government Clouds – Lessons Learned from Israeli Gov Cloud Program

SecureCloud-2016, Dublin, Ireland | May 25, 2016

CCSK Foundation – SecureCloud 2016 Congress

Dublin, Ireland | May 23, 2016

CCSK Plus + Foundation (Including TTT)

Milan, Italy | May 18, 2016

CISO Challenges with Cloud Security

Crown Plaza, Tel Aviv | April 3, 2016

Cloud Security for Startups – CSA Central Europe Congress

Ljubljana, Slovenia | March 8, 2016

Cloud Computing Security Foundation (CCSK)

Ljubljana, Slovenia | March 7, 2016

CCSK Plus

HP Education, Raanana | February 17, 2016

CCSP Live Online Training

Online (Singapore Time Zone) | January 19, 2016

2015

CCSK Foundation and Plus

HP Education, Raanana | December 6, 2015

Check Point Innovation Event

Check Point (Closed Event) | December 3, 2015

CCSK Training – CSA EMEA

Berlin, Germany | November 16, 2015

CCSK+ Training

HP Israel, Herzliya | October 14, 2015

OWASP Israel – Automating Security at Cloud Environments

Tel Aviv | October 13, 2015

From Zero to Secure in One Minute – Introducing Cloudefigo

DEF CON 23, Las Vegas | August 7, 2015

CCSK Foundation

Athens, Greece | May 25, 2015

The Role of the CISO in the Cloud World

Yes Planet, Rishon LeZion (CISO VIP Forum) | May 5, 2015

Passing Through the Lion's Den – Selling Cloud Services to Security Guys

Microsoft ILDC, Herzliya | April 14, 2015

From Zero to Secure in One Minute – Introducing Cloudefigo

Black Hat Asia, Singapore | March 26, 2015

Cloud Security Foundation and Advance

HP Education, Raanana | March 18, 2015

Cloud Security Foundation and Advance

CSA CEE Congress, Slovenia | March 12, 2015

Automating IaaS Security

CSA CEE Congress, Slovenia | March 11, 2015

The Cloud & HIPAA

Tel Aviv (AWS User Group Meetup) | February 23, 2015

Hardening IaaS Server

Tel Aviv (CSA Israel Meetup) | February 4, 2015

2014

Cloud Security Foundation and Advance

HP Education, Raanana | December 28, 2014

Information Security Basics

IBM, Haifa (Internal Class) | December 7, 2014

Cloud Security Foundation

Athens, Greece (ISACA Conference) | November 26, 2014

The Notorious 9 Cloud Computing Threats

ISACA Athens Chapter | November 25, 2014

The Notorious 9 Cloud Computing Threats

CISO Platform Conference, Mumbai | November 20, 2014

Cloud Security Foundation and Advance

HP Education, Raanana | September 29, 2014

Panel: Securing the Digital Future of America

Salt Lake City, Utah | September 22, 2014

The Notorious 9 – About Cloud Computing Threats

CSA Summit, San Jose | September 17, 2014

Panel: Startup Security Tips & Tricks (ILTechTalks Week)

Netanya | September 8, 2014

Securing Your IaaS Infrastructure

Tel Aviv | September 4, 2014

Cloud Security Foundation and Advance

VMware (In-house), Herzliya | June 9, 2014

Cloud Security Foundation and Advance

Amdocs (In-house), Kfar Saba | May 19, 2014

About Cloud Computing – Risks and Attack Vectors

Infosec Israel | May 15, 2014

Cloud Security Foundation and Advance

HP Education, Raanana | May 12, 2014

Cloud Security Foundation

Secure Cloud Congress, Amsterdam | March 31, 2014

Cloud Security Alliance, Israel Chapter Meeting

LivePerson Offices | March 18, 2014

Cloud Security Foundation

Tel Aviv | February 4, 2014

Cloud Computing: The Good, the Bad and the Unknown

Infrastructure and Cyber Con 2014 | January 29, 2014

The Notorious Nine: Cloud Computing Threats for 2014

Microsoft Offices, Herzliya | January 28, 2014

CCSK+

Avnet Security Consulting, Rishon LeZion | January 22, 2014

CCSK+

Raanana | January 7, 2014

2013

HaaS – Hacking as a Service

Bank Hapoalim, Shfayim | November 29, 2013

Enterprise Security in the Era of Cloud and BigData

Daniel Hotel, Herzliya (Oracle Week) | November 20, 2013

Cloud Security – What to Expect

DEFCON 9723 Group Meeting | November 19, 2013

CCSK

CSA CEE, Slovenia | October 24, 2013

Cloud Security Innovation – Lecture

CSA CEE, Slovenia | October 23, 2013

Panel: The Challenges of Today's Clouds

Tel Aviv | October 15, 2013

CCSK+

Tel Aviv | October 9, 2013

Cloud Security Innovation – Lecture

Herzliya | October 3, 2013

CCSK+

HP Software (In-house), Yehud | August 7, 2013

CCSK+

Tel Aviv | July 1, 2013

Cloud Sec Lecture

Herzliya | June 17, 2013

CCSK+

Tel Aviv | June 5, 2013

CISO

Ramat Gan | March 20, 2013

CCSK+

Samsung R&D (In-house), Yakum | March 20, 2013

CCSK+

Tel Aviv | February 18, 2013

CCSK+

Ramat Gan | January 8, 2013

2012

CISO

Ramat Gan | December 23, 2012

CCSK+

Tel Aviv | December 3, 2012

Interested in Training?

Contact me to discuss your training needs and schedule a session.

Request Training