Introduction
fwd:cloudsec North America 2025 · Day 1 · Track 1 - Crystal
Overview
The opening session of fwd:cloudsec North America 2025 sets the stage for the conference under this year's theme: "Living on the Edge." Delivered by the conference organizers in Denver, Colorado (the Mile High City), the introduction frames the evolving landscape of cloud security in 2025 and establishes the community-driven ethos that has defined fwd:cloudsec since its founding in 2020. The roughly eight-minute session covers the conference theme, logistical announcements, sponsor acknowledgments, and a rallying call to the assembled community of over 300 independent cloud security practitioners.

Key moments
- 0:00 Conference theme introduced: Living on the Edge
- 0:30 Five AI talks and new resource types like GPUs highlighted
- 1:15 Sponsor acquired for over $30 billion - existential question for cloud security
- 2:00 Pressures on cloud security startups and research teams discussed
- 3:00 Thanks to organizers, volunteers, and 40 speakers
- 4:00 First-ever speaker honoraria and scholarship attendees announced
- 4:30 Acknowledgment of attendees unable to travel due to visa and global violence
- 6:00 Over 300 top independent cloud security practitioners gathered
Introduction
Speakers: fwd:cloudsec Organizers
Conference: fwd:cloudsec North America 2025
YouTube: https://www.youtube.com/watch?v=p8PZiqXoVTc
Overview
The opening session of fwd:cloudsec North America 2025 sets the stage for the conference under this year's theme: "Living on the Edge." Delivered by the conference organizers in Denver, Colorado (the Mile High City), the introduction frames the evolving landscape of cloud security in 2025 and establishes the community-driven ethos that has defined fwd:cloudsec since its founding in 2020. The roughly eight-minute session covers the conference theme, logistical announcements, sponsor acknowledgments, and a rallying call to the assembled community of over 300 independent cloud security practitioners.
Background
▶ Watch: Conference theme introduced: Living on the Edge (0:00)
fwd:cloudsec launched in 2020 when "cloud" still largely meant centralized infrastructure running in a handful of hyperscaler regions. Five years later, the organizers observe that the definition of cloud has fundamentally shifted. Cloud is no longer a monolithic concept but a distributed, heterogeneous fabric spanning GPUs, AI agent architectures, edge compute, and an ever-expanding set of managed services. The conference was born as a practitioner-led, community-first event, and this opening session reaffirms that identity even as the industry undergoes rapid consolidation, cost pressures, and geopolitical upheaval.
The organizers note that a repeat fwd:cloudsec sponsor was acquired for over $30 billion in the past year, underscoring the commercial maturity of the cloud security market. Yet this maturity brings existential questions: Is cloud security simply "security" now? Are the same M&A pressures and AI-driven efficiencies that excite practitioners also threatening early-stage engineering careers, research teams, and the startup ecosystem that feeds innovation?
Key Findings
▶ Watch: Sponsor acquired for over $30 billion - existential question for cloud security (1:15)
The introduction does not present technical research findings, but it does surface several important observations about the state of cloud security in 2025:
- The attack surface has expanded dramatically. New resource types such as GPUs, AI agent architectures, and data lakes demand new security approaches. Five of the conference talks focus on AI, reflecting the community's urgency around agent architectures, token theft, and cost control.
- Resource Control Policies (RCPs), released by AWS in November 2024, provide powerful new tools for creating data perimeters. The organizers highlight these as a significant development the community needs to understand deeply.
- The regulatory and political environment is volatile. Visa challenges and global violence prevented some speakers and participants from attending. The organizers acknowledge this is "probably the hardest year to predict" in a decade of doing cloud work.
- Community sustainability requires investment. For the first time, fwd:cloudsec offered speaker honoraria funded by 30 personal sponsors who paid premium ticket prices. This change aims to ensure the best talks are selected regardless of whether a speaker's employer covers travel costs. Eight scholarship attendees were also supported.
Technical Deep Dive
▶ Watch: Thanks to organizers, volunteers, and 40 speakers (3:00)
As an opening session, this talk does not contain a technical deep dive. However, it previews the conference's technical agenda, which spans AMI security, appliance threat hunting, workload identity (SPIFFE), GCP tenant project vulnerabilities, deepfake threats via cloud APIs, IAM Roles Anywhere with Let's Encrypt, Entra ID enumeration tooling, and OAuth/OIDC vulnerability research. The organizers specifically call out talks on RCPs and data perimeters as areas of particular importance.
The mention of Granted, described as fwd:cloudsec's first open-source project maintained by Chris Norman's team, signals the community's commitment to building shared tooling rather than relying solely on vendor solutions.
Demo / Proof of Concept
▶ Watch: First-ever speaker honoraria and scholarship attendees announced (4:00)
No demo or proof of concept was presented in this session.
Defensive Implications
▶ Watch: Over 300 top independent cloud security practitioners gathered (6:00)
While not a defensive talk per se, the opening session carries an implicit message for defenders: the definition of what needs defending has expanded, and the community must adapt. The organizers' framing of "living on the edge" is a direct acknowledgment that perimeter-based thinking is insufficient when cloud infrastructure is distributed across GPUs, agent workflows, SaaS integrations, and hybrid environments. Defenders should take note of the conference's emphasis on data perimeters, RCPs, and the intersection of AI and cloud security as areas requiring immediate attention.
The acknowledgment that early-stage cloud security careers face disruption from AI and M&A also carries a workforce implication: security teams need to invest in upskilling and retaining talent in a contracting market.
Key Takeaways
- fwd:cloudsec 2025's theme, "Living on the Edge," reflects a cloud security landscape that has moved far beyond centralized infrastructure into distributed, AI-driven, and edge-heavy environments.
- Resource Control Policies (RCPs) from AWS represent a significant new tool for data perimeter enforcement and are highlighted as a key topic.
- The conference features over 300 independent practitioners, 40 speakers, and over 1,000 reviews of submitted talks, underscoring its status as a serious practitioner community.
- Speaker honoraria and scholarship programs funded by personal sponsors represent a maturation of the community's sustainability model.
- Global regulatory uncertainty, visa challenges, and geopolitical instability are actively shaping who can participate in the cloud security community.
About the Speaker(s)
The opening session is delivered by fwd:cloudsec conference organizers. The conference was founded by Scott, who delivers a closing "state of the union" talk. The organizers describe themselves as practitioners who have been doing cloud security work for approximately a decade. The session acknowledges dozens of volunteers, fellow organizers (identified by blue shirts), and the broader community that sustains the event.
Reviews
Dr. Zero (Offensive Security Researcher) — HARD PASS
Conference opening remarks with logistical announcements and sponsor acknowledgments. Zero technical content, zero exploits, zero reason for me to be paying attention. I used the time to refill my coffee.
Heather Calloway (CISO) — WEAK
The conference opening provides useful strategic framing around the evolving cloud security landscape, workforce pressures, and geopolitical disruption, but it lacks the depth or actionable guidance that would make it valuable viewing for security leaders outside the room.