May 28, 2026 · 25 min · 14 segments
In this episode of InfoSec Insider, Alastair Stewart and Tibor Laczko, both Senior Consultants and Qualified Security Assessors (QSAs) with URM, explore the use of severless architecture and Payment…
Alistair StewartGuest
Tibor LaczkoGuestAnnieHost
Uh, so it's usually pitched as platform as a service these days, whereby you use one of the big cloud providers, like Amazon, Google, or whatever, et cetera, but you don't, uh, have any input into the infrastructure.

The infrastructure, the servers, the traditional stuff that sits underneath it, you don't see any of it.

You simply put your code in, put your applications in, and, and, and you run it.

And a lot of, certainly some more of my clients these days, are now using those environments to put their PCI applications in, either their, either their web pages, their payment e-commerce environments, or, or whatever other systems they've got that are handling card data.

Normally it would be in a cloud environment where they have to build servers and set up virtual networks and stuff.

They simply put their application up, uh, and they run it in this, this essentially serverless environment.

But I think where when it comes to serverless, um, at least what I see, is sometimes they think no servers, no responsibility.

So anything sits on top of the physical layer, uh, the client is responsible for generating logs, access control, all of that part.

It's just that you're offloading more of the environment to the provider than you were previously, I guess, would be the simplest way of thinking about it.

Uh, so it's usually pitched as platform as a service these days, whereby you use one of the big cloud providers, like Amazon, Google, or whatever, et cetera, but you don't, uh, have any input into the infrastructure.

The infrastructure, the servers, the traditional stuff that sits underneath it, you don't see any of it.

You simply put your code in, put your applications in, and, and, and you run it.

And a lot of, certainly some more of my clients these days, are now using those environments to put their PCI applications in, either their, either their web pages, their payment e-commerce environments, or, or whatever other systems they've got that are handling card data.

Normally it would be in a cloud environment where they have to build servers and set up virtual networks and stuff.

They simply put their application up, uh, and they run it in this, this essentially serverless environment.

But I think where when it comes to serverless, um, at least what I see, is sometimes they think no servers, no responsibility.

So anything sits on top of the physical layer, uh, the client is responsible for generating logs, access control, all of that part.

It's just that you're offloading more of the environment to the provider than you were previously, I guess, would be the simplest way of thinking about it.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.