Loading…
Thursday November 5, 2026 1:15pm - 2:00pm PST
Cloud applications are increasingly used to process highly sensitive artifacts such as adversary simulation reports, threat intelligence, and vulnerability assessments. While encryption in transit and at rest is now standard, it does not answer a harder question: when and under what conditions should an application be allowed to see plaintext data?

This session presents a practical design for securely processing sensitive workloads in the cloud. The approach is simple in principle: data remains encrypted by default, and decryption is allowed only within explicitly authorized and tightly controlled execution paths.

We walk through a real-world architecture that combines client-side encryption, per-document keys, non-exportable asymmetric keys, policy-driven key release, role-based access control, and in-memory processing. In this model, documents are encrypted before upload, keys are isolated, and decryption happens only after identity, role, and workflow checks succeed. Plaintext exists only briefly during processing and is never persisted beyond that boundary.

What makes this approach different is how decryption itself becomes a controlled, auditable event, rather than an implicit capability of the application once access is granted.

The session also covers a production-inspired workflow where sensitive security reports are analyzed to extract actionable insights for defensive teams. This example shows how downstream processing systems (including AI-assisted analysis) can be introduced without expanding the attack surface.

Attendees will leave with a concrete design pattern for reducing plaintext exposure in cloud applications, along with practical guidance on applying these principles to their own systems. The focus is on patterns that can be applied broadly to sensitive workloads, not just this specific use case.
Speakers
avatar for Anjali Mangal

Anjali Mangal

Principal Director of Security Research, Microsoft
Anjali Mangal is a Principal Director of Security Research at Microsoft, where she leads security validation, adversary emulation, and AI security initiatives across Microsoft Security products and services. Anjali's work spans threat intelligence, detection engineering, cloud security... Read More →
avatar for Vamshi Krishna Thotempudi

Vamshi Krishna Thotempudi

Senior Applied Data Scientist, focused on AI/ML, LLM-driven automation, and cloud-scale threat detection, Microsoft Security Research
Vamshi Krishna Thotempudi is a Senior Applied Data Scientist at Microsoft Security Research, working on AI/ML-driven automation, LLM-based security research, and cloud-scale threat detection. He has 13 years of experience across artificial intelligence, machine learning, natural language... Read More →
avatar for Mahima Agarwal

Mahima Agarwal

Senior Machine Learning Engineer, Microsoft Security
Mahima Agarwal is a Senior Machine Learning Engineer at Microsoft Security specializing in the intersection of AI, machine learning, and cybersecurity. Her work focuses on building large-scale systems for threat detection, security analytics, and detection engineering, including the... Read More →
avatar for Raghav Batta

Raghav Batta

Principal Manager in AI Security Research, Microsoft Security,
Raghav Batta is a Principal Manager in AI Security Research at Microsoft Security, where he leads research at the intersection of artificial intelligence and cybersecurity. His work focuses on applying large language models, agentic AI, and large-scale machine learning to improve... Read More →
Thursday November 5, 2026 1:15pm - 2:00pm PST
Room: Grand Ballroom C (Street Level)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link