8 Must-Have Google Cloud Products for Startups

3189
Of your peers have already read this article.
2:30 Minutes
The most insightful time you'll spend today!
Startups worldwide turn to Google Cloud tools to build fast on a strong and easy to use platform that helps them get to market and launch products faster, all while building on the cleanest cloud in the industry. Startups leverage Google Cloud and our Google for Startups Cloud Program to go from idea to IPO, and there are a variety of products on Google Cloud that can help them.
Here are the 8 top products that startups use on Google Cloud to innovate and grow:
Firebase for app development
Speed up innovation with Firebase, a mobile development platform that’s fully integrated with Google Cloud. Work in a simpler cloud environment, easily pull in products or services, and build your apps faster.
Cloud SQL for database needs
Build your startup’s foundation with Cloud SQL, a fully managed relational database solution that integrates with Google Cloud services. Create and connect to your first database in minutes and scale with a single API call.
AI and machine learning products
Solve tough problems with AI and machine learning products, built with the best of Google’s technology. Train deep learning and machine learning models cost-effectively so you can iterate and innovate faster.
BigQuery for data analytics
Drive agility with BigQuery, a serverless, cost-effective, multi-cloud data warehouse. Query streaming data in real time, predict business outcomes with built-in machine learning, and share analytics with just a few clicks.
Google Kubernetes Engine (GKE) for containers
Unlock faster, more secure app development with GKE, the most scalable Kubernetes platform. Streamline operations with release channels that fit your business needs and leave cluster monitoring to Google engineers.
Looker for data visualization
Get more from your data to keep moving ahead of the competition with Looker, a trusted business intelligence and data platform. Generate real-time reports and get insights at the right time with proactive alerts.
Cloud Run for serverless computing
Create scalable containerized apps in any programming language on Cloud Run, a fully managed compute platform. Pair it with container tools like Cloud Build and Docker, and only pay when your code is running.
Cloud Armor for security
Protect your startup from Web attacks with Cloud Armor, a leading Distributed Denial-of-Service (DDOS) defense service. Use it with an HTTP Load Balancer for Managed Instance Groups across regions to keep your workloads highly available and secure.
To learn more about products best-suited to the unique demands of startups, check out our startups solution page. Our team is looking forward to discussing how these products can help you. If you’re not already in the program, you can get started here.
If you want to learn more about how Google Cloud can help your startup, visit our page here to get more information about our program, and sign up for our communications to get a look at our community activities, digital events, special offers, and more.
Three Benefits of VPC Network Peering for SAP Managed Apps

3536
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
Over the past year, RISE with SAP has emerged as a valuable solution for SAP customers seeking a faster, simpler, and more affordable path to the cloud. RISE with SAP is a subscription-based offering that typically includes a number of fully managed cloud application options, including SAP S/4HANA Cloud and elements of the SAP Business Technology Platform. It’s a great way to migrate your business to modern cloud ERP applications, while handing off the implementation and management to SAP and freeing your own IT staff to focus on other projects.
As a strategic partner for RISE with SAP, Google Cloud works closely with SAP to ensure reliable, secure, high-performance connectivity between your SAP managed applications and your other Google Cloud applications and services. Today, we’re focusing on a Google Cloud capability that plays a big part in achieving this goal: VPC network peering. If your company uses Google Cloud to host its RISE with SAP managed applications (or any other SAP-managed offering, such as SAP Enterprise Cloud Services), it’s worth learning more about why VPC network peering is an important capability and how your network admin can implement it.
VPC network peering: The critical link for your SAP managed applications
We recently co-authored a white paper with SAP that goes into technical detail about how VPC network peering works and includes step-by-step configuration instructions. But it is useful to understand, at a higher level, why it matters for RISE with SAP subscribers.
When SAP implements your RISE with SAP managed applications on Google Cloud, it also provisions a virtual private cloud (VPC) — a virtualized network that provides the same functionality, performance, and security benefits as a dedicated physical network — for this SAP environment. In fact, a VPC actually gives you some capabilities that a physical network can’t match, such as the ability to increase IP space without downtime.
Using VPC network peering to connect your SAP managed environment with your Google Cloud applications and services gives you three key benefits:
- Network latency: Traffic that remains inside Google’s network enjoys lower latency than connectivity that uses external addresses.
- Network security: Service owners do not need to have their services exposed to the public internet and deal with its associated risks.
- Network cost: Rather than pay egress bandwidth costs for networks using external IPs to communicate, peered networks can use internal IPs to communicate, saving you money on those egress costs. Regular network pricing still applies to all traffic.
Many customers also appreciate the flexibility they get from VPC network peering: It supports the ability to peer your own VPC networks with other VPC networks that reside in different projects and even in different organizations.
Using VPC network peering to strengthen your SAP security posture
Most Google Cloud customers find VPC network peering most useful to ensure seamless connectivity between their SAP managed applications and the rest of their Google Cloud environment. But some companies also rely on VPC network peering to gain greater control over the security of their cloud environments. This can include:
- Implementing additional network security capabilities, such as advanced firewalls, intrusion detection, and network package inspection, that go above and beyond standard SAP security measures.
- Leveraging Google Cloud Interconnect to link your on-premises and Google Cloud environments, including your RISE with SAP managed applications, without sending traffic across the public internet.
Once your company has configured VPC network peering, things get even more interesting. Google Cloud offers plenty of ways to complement and enhance the value of your SAP applications: using Google BigQuery to consolidate and enrich your SAP application data; relying on Google AI/ML capabilities to sharpen your predictive analytics and real-time decision-making; or leveraging Google Kubernetes Engine to jump-start your own cloud-native application development efforts, among many other examples.
Some of the world’s biggest SAP customers, including The Home Depot, and Cardinal Health, have chosen Google Cloud to migrate their business-critical SAP applications. And we’ve seen how useful VPC network peering can be for SAP customers to unlock the full value and potential of Google Cloud. Be sure to download our white paper so you can get VPC network peering configured for your RISE with SAP managed applications, and discover for yourself just what’s possible when you run SAP applications on Google Cloud.
Developers and Practitioners’ Guide for Moving On-prem Data Warehouse to BigQuery

5427
Of your peers have already read this article.
3:00 Minutes
The most insightful time you'll spend today!
Data teams across companies have continuous challenges of consolidating data, processing it and making it useful. They deal with challenges such as a mixture of multiple ETL jobs, long ETL windows capacity-bound on-premise data warehouses and ever-increasing demands from users. They also need to make sure that the downstream requirements of ML, reporting and analytics are met with the data processing. And, they need to plan for the future – how will more data be handled and how new downstream teams will be supported?
Checkout how Independence Health Group is addressing their enterprise data warehouse (EDW) migration in the video above.
Why BigQuery?
On-premises data warehouses become difficult to scale so most companies’ biggest goal is to create a forward looking system to store data that is secure, scalable and cost effective. GCP’s BigQuery is serverless, highly scalable, and cost-effective and is a great technical fit for the EDW use-case. It’s a multicloud data warehouse designed for business agility. But, migrating a large, highly-integrated data warehouse from on-premise to BigQuery is not a flip-a-switch kinda migration. You need to make sure your downstream systems dont break due to inconsistent results in migrating datasets, both during and after the migration. So..you have to plan your migration.
Data warehouse migration strategy
The following steps are typical for a successful migration:
- Assessment and planning: Find the scope in advance to plan the migration of the legacy data warehouse
- Identify data groupings, application access patterns and capacities
- Use tools and utilities to identify unknown complexities and dependencies
- Identify required application conversions and testing
- Determine initial processing and storage capacity for budget forecasting and capacity planning
- Consider growth and changes anticipated during the migration period
- Develop a future state strategy and vision to guide design
- Migration: Establish GCP foundation and begin migration
- As the cloud foundation is being set up, consider running focused POCs to validate data migration processes and timelines
- Look for automated utilities to help with any required code migration
- Plan to maintain data synchronization between legacy and target EDW during the duration of the migration. This becomes a critical business process to keep the project on schedule.
- Plan to integrate some enterprise tooling to help existing teams span both environments
- Consider current data access patterns among EDW user communities and how they will map to similar controls available in Big Query.
- Key scope includes code integration and data model conversions
- Expect to refine capacity forecasts and refine allocation design. In Big Query there are many options to balance cost and performance to maximize business value. For example, you can use either on-demand or flat-rate slot pricing or a combination of both.
- Validation and testing
- Look for tools to allow automated, intelligent data validation
- Scope must include both schema and data validation
- Ideally solutions will allow continuous validation from source to target system during migration
- Testing complexity and duration will be driven by number and complexity of applications consuming data from the EDW and rate of change of those applications
A key to successful migration is finding Google Cloud partners with experience migrating EDW workloads. For example, our Google Cloud partner Datametica offers services and specialized Migration Accelerators for each of these migration stages to make it more efficient to plan and execute migrations.

Data warehouse migration: Things to consider
- Financial benefits of open source: Target moving to ‘Open Source’ where none of the services have license fees. For example BigQuery uses Standard SQL; Cloud Composer is managed Apache Airflow, Dataflow is based on Apache Beam. Taking these as managed services provides the financial benefits of open source, but avoids the burden of maintaining open source platforms internally.
- Serverless: Move to “serverless” big data services. The majority of the services used in a recommended GCP data architecture scale on demand allowing more cost effective alignment with needs. Using fully managed services lets you focus engineering time on business roadmap priorities, not building and maintaining infrastructure.
- Efficiencies of a Unified platform: Any data warehouse migration involves integration with services that surround the EDW for data ingest and pre-processing and advanced analytics on the data stored in the EDW to maximize business value. A cloud provider like GCP offers a full breadth of integrated and managed ‘big data’ services with built-in machine learning. This can yield significantly reduced long-term TCO by increasing both operational and cost efficiency when compared to EDW-specific point solutions.
- Establishing a solid cloud foundation: From the beginning, take the time to design a secure foundation that will serve the business and technical needs for workloads to follow. Key features include: Scalable Resource Hierarchy, Multi-layer security, multi-tiered network and data center strategy and automation using Infrastructure-as-Code. Also allow time to integrate cloud-based services into existing enterprise systems such as CI/CD pipelines, monitoring, alerting, logging, process scheduling, and service request management.
- Unlimited expansion capacity: Moving to cloud sounds like a major step, but really look at this as adding more data centers accessible to your teams. Of course, these data centers offer many new services that are very difficult to develop in-house and provide nearly unlimited expansion capacity with minimal up-front financial commitment. .
- Patience and interim platforms: Migrating an EDW is typically a long running project. Be ready to design and operate interim platforms for data synchronization, validation and application testing. Consider the impact on up-stream and down-stream systems. It might make sense to migrate and modernize these systems concurrent with the EDW migration since they are probably data sources and sinks and may be facing similar growth challenges. Also be ready to accommodate new business requirements that develop during the migration. Take advantage of the long duration to have existing your operational teams learn new services from the partner leading the deployment so your teams are ready to take over post-migration.
- Experienced partner: An EDW migration can be a major undertaking with challenges and risks during migration, but offers tremendous opportunities to reduce costs, simplify operations and offer dramatically improved capacities to internal and external EDW users. Selecting the right partner reduces the technical and financial risks, and allows you to plan for and possibly start leveraging these long-term benefits early in the migration process.

Example Data Warehouse Migration Architecture
- Setup foundational elements. In GCP these include, IAM for authorization and access, cloud resource hierarchy, billing, networking, code pipelines, Infrastructure as Code using Cloud Build with Terraform ( GCP Foundation Toolkit), Cloud DNS and a dedicated/partner Interconnect to connect to the current data centers.
- Activate monitoring and security scanning services before real user data is loaded using Cloud Operations for monitoring and logging and Security Command Center for security monitoring.
- Extract files from on-premise legacy EDW and move to Cloud Storage and establish on-going synchronization using Big Query Transfer services.
- From Cloud Storage, process the data in Dataflow and Load/Export data to BigQuery.
- Validate the export using Datametica’s validation utilities running in a GKE cluster and Cloud SQL for auditing and historical data synchronization as needed. Application teams test against the validated data sets throughout the migration process.
- Orchestrate the entire pipeline using Cloud Composer, integrated with on-prem scheduling services as needed to leverage established processes and keep legacy and new systems in sync.
- Maintain close coordination with teams/services ingesting new data into the EDW and down-streams analytics teams relying on the EDW data for on-going advanced analytics.
- Establish fine-grained access controls to data sets and start making the data in Big Query available to existing reporting, visualization and application consumption tools using BigQuery data connectors for ‘down-stream’ user access and testing.
- Incrementally increase Big Query flat-rate processing capacity to provide the most cost-effective utilization of resources during migration.
To learn more about migrating from on-premises Enterprise Data Warehouses (EDW) to Bigquery and GCP here.
Casper on Google Cloud: Revolutionizing Web3 Development with Flexibility & Security

1441
Of your peers have already read this article.
1:30 Minutes
The most insightful time you'll spend today!
Casper Labs announced a collaboration with Google Cloud that will allow developers to launch public and/or private Casper nodes directly from Google Cloud. This enables a much more seamless and highly secure process for the millions of developers who want to build in blockchain environments without having to learn new, highly specialized programming languages. Additionally, Google Cloud will provide its scalable and reliable infrastructure to developers building on the Casper Protocol.
Blockchain technology is maturing
As blockchain technology matures, a growing number of businesses are embracing it as a key way to drive new efficiencies and realize cost savings.
According to a recent Casper Labs study, 87% of executives polled in the United States, United Kingdom and China reported plans to invest in a blockchain solution in 2023. This is due in no small part due to recent innovations that help organizations overcome the so-called Blockchain Adoption Trilemma, which previously held that it was impossible for any blockchain to be simultaneously a) decentralized, b) scalable, and c) secure.
Thanks to the rise of proof-of-stake blockchains like Casper, new models have emerged that enable a more scalable and secure architecture that no longer forces a compromise on decentralization.
Another trend facilitating these growing adoption rates is the rise of WebAssembly (WASM) as a baseline technology for newer blockchains, including Casper. WASM (created by W3C) makes application development in blockchain environments far more accessible and interoperable to the millions of developers worldwide who specialize in languages like Java, Javascript, C++ and Rust. Previously, any blockchain-based build required a high degree of specialized developer knowledge, which made it a much more challenging option for most organizations.
Meet Casper
Casper is a permissionless, decentralized public blockchain based on WASM that was built explicitly to foster enterprise adoption of blockchain technology. Beyond its more accessible model, Casper is the first and only blockchain to offer native upgradable smart contracts. This means that organizations can have the option to securely and consistently update software code even after it is running on Casper. This gives organizations the control and flexibility to use industry best practices, such as continuous deployment and continuous integration, which are already in use in their IT departments. Casper is also highly configurable and allows organizations to support public, private, and/or hybrid deployments.
Casper is also noteworthy for the presence of Casper Labs, a software development and professional services firm that supports organizations building on the Casper network. Unlike most blockchains that follow a more traditional open-source project, Casper Labs provides around-the-clock support and bespoke software development for enterprise organizations. Recently, Casper Labs helped patent management company IPwe execute the largest-ever blockchain deployment, featuring more than 25 million patents being added as custom NFTs to the Casper Blockchain.
How to get started with Casper on Google Cloud
Developers who want to start building on Casper can find a comprehensive series of tutorials here.
The Casper Association also recently announced a $25 million grant program to support projects and developers building on Casper. Interested participants can apply here.
withVR Uses the Power of VR to Prep People with Speech Disorders for Real-life Speaking Situations

3280
Of your peers have already read this article.
1:30 Minutes
The most insightful time you'll spend today!
Editor’s note: Meet Gareth Walkom, an entrepreneur dedicated to helping others with speech disorders.
Turning life experience into innovation
Did you know that 3% of Americans have a speech disorder, while 1% of the world’s population have a stutter? Just getting what they need in everyday interactions can be stressful, which intensifies when the stakes are raised during job interviews, presentations, public speaking, and other activities. As a result, some people with speech disorders may avoid conversations and relationships, and risk being denied jobs because of a difference in how they speak.
As a person who stutters, I know firsthand the ableism that people with a speech disorder can encounter in wanting to use their voice in a judgemental world: the frustration of sometimes not being able to say exactly what you want to say and therefore speaking less in speaking situations. And the educational and career opportunities are lost when doors remain closed to us, especially when employers advertise their jobs as requiring someone who speaks the language ‘fluently’.
While researchers still don’t definitively know what causes stuttering, emerging technologies are giving us new and promising pathways for improving the quality of life of people with speech disorders.
That’s why after years of researching and testing potential therapeutic uses of virtual reality, and with the support of the Google for Startups Cloud Program, I founded withVR on International Stuttering Awareness Day (October 22) in 2020. The mission of withVR is to prepare people with speech disorders for real-life speaking situations by utilizing the power of virtual reality.
Working through it
One of the difficulties in adapting to any disability is the opportunity to work through it in a safe and nonjudgmental environment. withVR provides a virtual space for individuals, in collaboration with their speech therapists, to practice real-world speaking scenarios in safe, controlled environments.
Imagine being able to raise your hand in class and give your opinion without hesitation, ordering the meal you want rather than something that’s easier to say, or sit across the table from an avatar of an employer and explain why you are the right person for your dream job. Then further customize the speaking situation and its surroundings to challenge yourself and be ready for anything. That’s what withVR offers individuals and their speech therapists.
Making VR come to life
To bring the withVR vision to life, we are developing applications using the Unity game engine on Google Cloud with integrated Firebase services including authentication, web hosting, storage, and database. It’s a powerful combination that’s enabled us to build industrial-strength applications that we’ve rapidly deployed on a global basis. Today we are already collaborating with 80+ labs, clinics, and hospitals in more than 20 different countries worldwide.
These organizations help us to test and refine a virtual reality application to support people in achieving their speech goals and build comfort through immersive VR experiences using easily available viewers like Google Cardboard.
The application works in conjunction with a web app through which speech therapists configure customized VR scenarios for their patients to use. As no real-life speaking situation is ever exactly the same, customization of VR scenarios is vital. They can construct different scenes, create and script avatars, and through the Google Text-to-Speech API can even choose from hundreds of different voices in a variety of languages. This gives them the flexibility to create many unique speaking situations for their clients no matter where they are in the world.
Progress from the practice sessions is presented through a dashboard that provides therapists with a tool to monitor their clients’ progress and provide feedback and encouragement.
No shortage of support
My founder’s journey has been supported by many passionate people. The Google for Startups Cloud Program has been instrumental in helping us come so far in the first year, and we’ve only scratched the surface of what’s possible. There are many capabilities in Firebase and Google Cloud that we have yet to explore, and through the startup program I now have a Google Mentor who can help guide that exploration.
We also joined the 2Gether-International (2GI) Tech Cohort, which is supported by Google for Startups and is built for and run by entrepreneurs with disabilities. At the end of the 10-week cohort, we finished with a pitch competition, where I was one of six selected founders to pitch in just three minutes. I was very fortunate to win the Best Overall Pitch Award, gaining 10,000 USD in seed funding. This award not only highlights the potential of withVR, but also showcases that anyone can pitch their idea in a short amount of time no matter their difference.
Working with 2GI also gave me the opportunity to collaborate and learn from other founders who have disabilities. It’s a safe space where I don’t have to explain my everyday challenges and can focus on the all-important task of advancing the vision of withVR, while seeing how others use technology in their domain.
Building on a strong foundation
I’m amazed to look back and see what we’ve accomplished in just one year and humbled by the thousands of lives we’ve touched. Every day we receive valuable real-life feedback from people in the field—both clinicians and those with speech differences who benefit from VR therapy. That knowledge tells us that we are heading in the right direction and opening our eyes to new possibilities for where to take withVR. And inspiring us to keep moving ahead.
If you’d like to participate in testing or if you are speech therapist or researcher, please feel free to reach out to us. We’d love to show you how you can contribute to a world where anyone with a speech disorder can truly use their voice in any situation. If you’d like to take part, contact us at hello@withvr.app.
If you want to learn more about how Google Cloud can help your startup, visit our page here to get more information about our program, and sign up for our communications to get a look at our community activities, digital events, special offers, and more.
What to Look for from Cloud CISO Perspective

6646
Of your peers have already read this article.
2:30 Minutes
The most insightful time you'll spend today!
May is a big month for the security industry. It’s been over a year since we gathered for RSA in San Francisco for one of 2020’s last major in-person events. While we likely won’t be together in person this year, it’s an important time for the security community to come together and reflect on many accomplishments, and to consider the challenges still ahead of us. As the world focuses on security incidents and all the risks that still need resolving, it is important to stand back, on occasion, and also note that immense progress has been made by large numbers of small, medium and large enterprises to protect themselves and their customers against increased threats. What is also amazing is to see organizations do this while accelerating their digital transformations, supporting and protecting customers and managing ongoing remote working challenges. We are privileged to play our part in supporting those great teams.
It’s also been a busy month for us here at Google Cloud since our inaugural CISO perspectives blog post in April. Today, I’ll recap our cloud security and industry highlights, a sneak peak of what’s ahead from Google at RSA and more.
Thoughts from around the industry
- Risk Governance of Digital Transformation in the Cloud – In our latest Office of the CISO whitepaper, we shared guidance on both the challenges and opportunities of cloud transformation for Chief Risk Officers, Chief Compliance Officers, Heads of Internal Audit and their teams. A misconception we sometimes see among these executives is that moving to the cloud creates more risk to manage. Having held these leadership positions in previous roles, I believe that the cloud is as much a means of managing security, resilience and other risks as it is a risk in its own right. The whitepaper dives deep into considerations for each of these leadership functions as their organization embarks on a digital transformation journey.
- The importance of meeting global compliance requirements – Compliance is critical for building trust with customers in regulated industries, especially the public sector. It is worth remembering that in any critical industry, where there can be material impact from incidents, strong industry practices and standards to protect customers are vital (I wrote about this last summer). At Google Cloud, we’re regularly adding new compliance and security certifications to meet our customers’ needs globally. Recently, we expanded our list of FedRAMP High-certified products to include Cloud DNS, and helped our customers in the Asia-Pacific region address various compliance requirements to meet new government regulations for security and data protections. Google Cloud was also the only cloud service provider to complete an annual pooled audit with the Collaborative Cloud Audit Group (CCAG), which is a syndicate of 39 leading European financial institutions and insurance companies who depend on cloud infrastructure and technologies to deliver innovative solutions and experiences for their customers. Having spent most of my career in the financial services industry, I know firsthand the importance of managing risk assessments for outsourced vendors to provide the necessary assurances customers need from their cloud providers.
RSA 2021
We have a great lineup of speaking sessions and keynotes from Googlers at RSA this year. Below are the highlights you don’t want to miss:
- I’ll be doing a session on May 20 about supply chain resilience, where a panel of experts will dive into how we can adjust risk and security initiatives to handle the next “punch to the supply chain.” Additionally, on May 18 I’ll join many of my esteemed CISO leaders from various industries and governments for a keynote discussion on our top security insights, lessons learned and best practices for how we move forward as an industry to address the next wave of challenges.
- Google’s Senior Director of Information Security Heather Adkins will deliver a session on how to build secure and reliable systems at scale, which will cover principles from Google’s Site Reliability Engineering book with the same title (available for free download here). I’m most looking forward to Heather’s advice for how we as an industry can reshape our security thinking, based on modern architectures and technologies that can help organizations design scalable and reliable systems that are fundamentally secure.
- Nelly Porter, Senior Product Manager at Google Cloud Security, will participate in a panel discussion with security experts on the importance of Confidential Computing technology, how it’s changing the security landscape and where it’s headed. Google Cloud has made great progress in delivering a Confidential Computing portfolio for our customers in regulated industries over the past year, and we’re excited for new milestones in 2021.
Google cloud security highlights
- Infrastructure and SRE spotlight – Before I joined Google Cloud, I always admired the infrastructure and benefits this organization delivers that are uniquely Google – from the subsea cable innovations to SRE inventions and principles. Security and resiliency are baked into every layer of our infrastructure. Many of the Googlers who build and support our platform have sat in the same seat as our customers, so they understand those needs intimately. Over the last few months it’s been amazing to watch our technical infrastructure team grow, and the direct reliability, operational resilience and security benefits that team brings to our customers. For example, we’ve opened a new region in Poland, announced the first subsea cable that will directly connect the U.S. to Singapore with fiber pairs over an express route, and released an SRE book focused on how organizations can complete a successful cloud migration.
- New security foundations blueprint guide – As part of our mission to deliver the industry’s most trusted cloud, we strive to operate in a shared-fate model for risk management in conjunction with our customers. This includes sharing opinionated step-by-step guidance with key decision points and focus areas for how our customers deploy workloads in Google Cloud. This is why we’ve updated our Google Cloud security foundations guide and corresponding Terraform blueprint scripts. These blueprints are tremendously helpful to many stakeholders within an enterprise, like a CISO that needs to understand our key principles for cloud security, or a C-Suite business leader that needs to quickly identify the skills their teams need to meet an organization’s security, risk, and compliance needs on Google Cloud.
When we think about the types of features to build into products, we have many principles we follow. But the two that I keep coming back to as crucial are:
- The need for secure products not just security products. All products should have security built in and while we do build great security products our security and other teams remain focused on constantly enhancing the base levels of security and the security features in all our products.
- Defense in Depth. We don’t just focus on defense in depth from attacks – for ourselves and our customers. We also prioritize defense in depth from configuration errors or other hazards.
As you see below in some of the highlights of new features and products, these represent our commitment to secure products and all forms of defense in depth.
- Workload identity federation – Service account keys are powerful credentials, and can represent a security risk if they are not managed correctly. A safer approach is to use workload identity federation, using IAM to grant external identities IAM roles, including the ability to impersonate service accounts. This lets you access resources directly and eliminates the maintenance and security burden associated with service account keys. We also offered related overall guidance on the best way to use and authenticate service accounts on Google Cloud.
- VPC-SC Directional Policies – With VPC Service Controls (VPC-SC), admins can define a security perimeter around Google-managed services to control communication to and between those services. Using VPC-SC, you can isolate your production GCP resources from unauthorized VPC networks or the internet. But what if you need to transfer data between isolated environments that you’ve set up? VPC-SC directional policies is a new secure data exchange feature that allows you to configure efficient, private, and secure data exchange between isolated environments.
- Anthos service mesh supports VMs as well as clusters – Most enterprise compute resources are still in VMs and many will remain there for a long time to come. In Anthos 1.7, your VM-based workloads can now take advantage of the same mesh functionality as your container-based workloads.
- Cloud Spanner CMEK and Access Approvals – Cloud Spanner is Google Cloud’s fully managed relational database that offers unlimited scale, high performance, strong consistency across regions and high availability. Spanner now supports customer-managed encryption keys (CMEK) and Access Approval, Google Cloud’s industry-leading controls to require approval before access to your content by Google support and engineering teams.
- External Key Manager enhancements – In early 2020 we launched Cloud External Key Manager (Cloud EKM), the industry’s leading Hold-Your-Own-Key (HYOK) product. Using Cloud EKM, the keys used to protect your data stored and processed in Google Cloud are completely hosted and managed outside of Google Cloud infrastructure. Cloud EKM initially launched with support for BigQuery and GCE/PD; we expanded support for Cloud SQL, GKE, Dataflow Shuffle, and Secret Manager, with CMEK support currently in beta. We also provided in-depth documentation on the functionality, architecture and use cases for Cloud EKM in a new whitepaper.
- Web App and API Protection solution – Web applications and public APIs are increasingly important to how organizations interface with their customers and partners, and we’ve seen increased investment in tools to protect these resources from fraud and abuse. Google Cloud’s new Web App and API protection solution is based on the same technology Google uses to protect its public-facing services against web application exploits, DDoS attacks, fraudulent bot activity, and API targeted threats. It provides protection across clouds and on-premises environments.
- Threat Intel for Chronicle – Most threat intelligence feeds require security teams to do the implementation and legwork. With our new Threat Intel for Chronicle offering, however, our intelligence insights are applied automatically across your security telemetry to present unique observations within your environment. Threat Intel for Chronicle is exclusively curated for enterprise customers by Uppercase, Google Cloud’s intelligence research and applications team to provide our perspective on threats across the internet and surface them as relevant alerts.
That wraps up another month of thoughts and highlights. If you’d like to have this Cloud CISO Perspectives post delivered every month to your inbox, click here to sign-up, and we’ll see you in June!
More Relevant Stories for Your Company

Create and Protect Admin Accounts
Setting up your new cloud infrastructure is scary. Extra scary when you realize that someone (is it gonna be you?) gets to have phenomenal cosmic power over the whole thing. Yes, I'm talking about the admin account, and today we'll dig into why they are important, dangerous and different. When

What You Need to Know About Compute Engines
Compute Engine is a customizable compute service that lets you create and run virtual machines on Google’s infrastructure. You can create a Virtual Machine (VM) that fits your needs. Predefined machine types are pre-built and ready-to-go configurations of VMs with specific amounts of vCPU and memory to start running apps

Dassana: Choosing Google Workspace and Google Cloud to accelerate growth and reach goals
When Dassana co-founders Gaurav Kumar and Parth Shah, formerly founder and founding engineer at RedLock (now Prisma Cloud by Palo Alto Networks), set out on a new startup journey in 2020, they knew exactly where to start: sign up for Google Workspace. “Every startup I’ve been at, we used Google

What’s Google Cloud Firestore Database and What are it’s Benefits for Business and Developers?
Cloud Firestore is a NoSQL document database that simplifies storing, syncing, and querying data for your mobile and web apps at global scale. Cloud Firestore is a fast, fully managed, serverless, cloud-native NoSQL document database that simplifies storing, syncing, and querying data for your mobile, web, and IoT apps at






