
Automating Kubernetes IR (When Your CNAPP Fails)
Source: YouTube · Cloud Security Podcast · published Oct 10, 2025 · 52:24
BLUF: Automation drastically reduces the time required to contain security incidents in complex Kubernetes environments, achieving containment in minutes versus hours 0:00-0:08.
Key Takeaways:
• Traditional manual containment in regulated EKS environments is slow, often taking hours, whereas automation enables containment within approximately 10 minutes 0:00-0:08.
• Responding to incidents in containerized or Kubernetes workloads requires navigating complex networking configurations, such as ensuring the response tool is in the same network as the private cluster 0:14-0:22.
• There is currently a lack of sophisticated, widespread approaches for automating incident response and containment within these complex infrastructure types 0:25-0:33.
• While some security tooling can be overly noisy, generating more alerts is preferable to having insufficient visibility during an incident 0:36-0:43.
Closing Statement:
The transcript highlights the critical need for automated, sophisticated incident response tools that can navigate the complexities of private Kubernetes clusters to ensure rapid security containment.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Without the automation, it was within a regulated environment. It's going to take you hours. I was able to contain an EKS node within about 10 minutes time. >> What does it look like when we are doing a instant response for a containerized workload, a Kubernetes workload? >> Let's say for instance, you have a private cluster in EKS. >> Okay, already complicated. >> You have to be in the same networking configuration in order for you to be able to interact with the Kubernetes cluster. The majority of what I see is there isn't a sophisticated approach to automating incident response or containment inside of those type of complex environments. >> Do we have too much visibility? Now >> I would say that because sometimes the tooling that is being used can be a bit too noisy. More noise is bette…