How eating your own dog food helps secure the planet
Download resourcesAbout this session
Taylor Lehmann, Director in Google Cloud's Office of the CISO and a former healthcare CISO, explains dogfooding, Google's practice of using, breaking and iterating on its own products internally before customers see them, and argues it should be a criterion for choosing security vendors. He anchors the talk in Operation Aurora, the 2009 intrusion attributed to China that targeted Gmail accounts of dissidents and that Google disclosed in January 2010. Two products grew out of the response. BeyondCorp: over a decade Google removed reliance on network location and VPNs, put every application behind a certificate-based identity-aware proxy, built a device inventory and a trust inference engine, and migrated tens of thousands of apps, shipping externally as BeyondCorp Enterprise in 2019. Detection and response: the Aurora hunt team became the Threat Analysis Group, Google's log-everything search infrastructure and early machine learning became a platform spun out as Backstory, renamed Chronicle, then folded back into Google Cloud. He details how dogfooding runs today, a named manager, three tiers, tester segmentation, opt-in only, fix-time commitments and lightweight feedback, and urges organisations to ask what they would trust to protect their family, and whether vendors run what they sell.
Dogfooding (a common term in software companies for internally using your own products before they launch) is an important part of Google’s culture, and its practice has driven the creation of advanced security technologies, in some cases years before the broader need for them outside of Google was fully understood. For us, dogfooding is more than using our own products. It represents a comprehensive program of using, testing, and rapidly refining the products in the rigorous operating environment of Google. In this session, we’ll explore how Google structures its dogfooding culture and share examples and experience of how this practice might be the most important criteria security leaders should evaluate when selecting a technology provider.
Key takeaways
- Ask every security vendor whether it uses the product it sells you to protect itself, and whether lessons from its own operations flow back into the product.
- A zero-trust migration is a multi-year programme, not a purchase: start with one app and one vendor, keep workaround paths so nobody is blocked, and secure executive support first.
- Stop trusting network location: put every application, including internal ones, behind an identity-aware proxy that checks user, device certificate and device health on every request.
- Log broadly and retain for a year so incident responders can reconstruct foothold-to-exfiltration; use correlation and deduplication to handle attackers who alias hosts and IPs.
- Run dogfooding with a named manager, tiered test groups, segmented testers, opt-in only, fix-time commitments for product teams and one-line feedback that is always answered.
Speakers

Taylor Lehmann joined Google’s Office of the Chief Information Security Officer (CISO) to advise Google Cloud customers and help them achieve their business goals while adopting a high security bar - one that protects data, operations, and people… Read moreRead less
Taylor Lehmann joined Google’s Office of the Chief Information Security Officer (CISO) to advise Google Cloud customers and help them achieve their business goals while adopting a high security bar - one that protects data, operations, and people without compromise or unnecessary friction. Taylor is an experienced CISO who’s past work focused on securing global healthcare organizations, removing obstacles, and driving innovative programs that help them achieve their core missions. Taylor has held CISO roles for hospitals, health insurance, health IT organizations, and global banks. He was a named advisor and member of the global security advisory boards for both IBM and AWS. Early in his career, he spent 8 years establishing and leading PwC’s healthcare security and risk advisory function, leaving as a Director. Taylor holds an MBA from Boston College and a BS in Finance and Information Systems from the State University of New York at Buffalo.
