Archive · · 12 min read

Accelerating innovation at AWS Security

CJ Moses, CISO of AWS, delivers a leadership session to highlight the state of security and what's next.

Accelerating innovation at AWS Security
At re:Invent or attending remotely? Check out my “Ultimate Guide to AWS re:Invent 2022” post for some tips and tricks to get the most out of the show.

The security leadership session at AWS re:Invent 2022 was called, “What we can learn from customers: Accelerating innovation at AWS Security”. CJ Moses, CISO of AWS, used this session to explain what AWS is doing to help everyone with security, to highlight some key releases in 2022, and what we can expect in 2023 when it comes to security.

CJ definitely put his own stamp on the leadership sessions. More in this Twitter thread 👇.

Twitter Thread 🧵

Tweet 1/57 👇 Next tweet

the @awscloud #security leadership session featuring @mosescj58 is starting now… What we can learn from customers: Accelerating innovation at AWS Security #reinvent

Tweet 2/57 👇 Next tweet 👆 Start

@mosescj58 up now, rocking some killer kicks 👟 #reinvent

Tweet 3/57 👇 Next tweet 👆 Start

@mosescj58 celebrating 15 years with @awscloud 🥳🥳🥳 congrats CJ! #reinvent

Tweet 4/57 👇 Next tweet 👆 Start

“Everyday I get to learn about the problems we can solve for customers, and how we can do that”, @mosescj58 #reinvent

Tweet 5/57 👇 Next tweet 👆 Start

@mosescj58 drawing the parallels between his sport—racing—and #security - both driven by data - safety is a key factor for success #reinvent

Tweet 6/57 👇 Next tweet 👆 Start

good Bezos quote, “Customers are always wonderfully, beautifully unsatisfied.” #reinvent

Tweet 7/57 👇 Next tweet 👆 Start

more than 90% of all the things @awscloud creates is directly from customers…the other 10% was built on behalf of those customers 😉 #reinvent

Tweet 8/57 👇 Next tweet 👆 Start

@mosescj58 sharing some of his previous roles in law enforcement and the parallels in his role with @AWSSecurityInfo today both looking for one tiny indicator amid a torrent of data #reinvent

Tweet 9/57 👇 Next tweet 👆 Start

@awscloud has the scale to enable security pre-AWS @mosescj58 was working with @jeffbarr back in 2007. those conversations kicked off a ton of security work …which brought CJ to AWS #reinvent

Tweet 10/57 👇 Next tweet 👆 Start

1st challenge: isolate workloads in a data center …wow, think about that vs. what we heard in Peter DeSantis’ keynote on Monday about @awscloud Lambda function isolation #reinvent

Tweet 11/57 👇 Next tweet 👆 Start

@mosescj58 reminiscing about the scrappy startup days of @AWSSecurityInfo bean bag chairs => hand me down cube from AOL (!) in a dingy corner…working together as a small team cracking on a deeply interesting & challenging problem #reinvent

Tweet 12/57 👇 Next tweet 👆 Start

experiments lead to virtualizing the network layer. that was what provided the isolation needed #reinvent

Tweet 13/57 👇 Next tweet 👆 Start

that 👆 was the start of @awscloud VPC #reinvent

Tweet 14/57 👇 Next tweet 👆 Start

“We’ve grown a tiny bit”, @mosescj58 aims for understatement of the show #reinvent

Tweet 15/57 👇 Next tweet 👆 Start

by, the main “home” for @AWSSecurityInfo is https://aws.amazon.com/security/ …though there’s a ton of info everywhere in the service docs/whitepapers/etc. #reinvent

Tweet 16/57 👇 Next tweet 👆 Start

events seen on the @awscloud global network…. …that’s a lot of zeros #reinvent

Tweet 17/57 👇 Next tweet 👆 Start

that’s a new visual for the shared responsibility model. I think that’s much clearer than the older one w/way too many layers shown #reinvent

Tweet 18/57 👇 Next tweet 👆 Start

great reference on the shared responsibility model: https://aws.amazon.com/compliance/shared-responsibility-model/ #reinvent

Tweet 19/57 👇 Next tweet 👆 Start

“If you have access or control, you have responsibility”, @mosescj58 << great summary and ‘cheatsheet’ for the @awscloud shared responsibility model #reinvent

Tweet 20/57 👇 Next tweet 👆 Start

getting a bit of a peek behind the @AWSSecurityInfo curtain here from @mosescj58 #reinvent

Tweet 21/57 👇 Next tweet 👆 Start

more on @awscloud Shield at https://aws.amazon.com/shield/ …AWS WAF at https://aws.amazon.com/waf/ #reinvent

Tweet 22/57 👇 Next tweet 👆 Start

@AWSSecurityInfo saw more than 224M malware samples in six months! #reinvent

Tweet 23/57 👇 Next tweet 👆 Start

all of the data that @AWSSecurityInfo gathers from their perspective informs new @awscloud services and features that’s why we’re seeing so many new feature advances in things like Amazon Macie and Amazon GuardDuty #reinvent

Tweet 24/57 👇 Next tweet 👆 Start

more on @awscloud Macie at https://aws.amazon.com/macie/ …Amazon GuardDuty at https://aws.amazon.com/guardduty/ #reinvent

Tweet 25/57 👇 Next tweet 👆 Start

exposed credentials are a continuing challenge. IAM helps reduce the blast radius (good ol’ principle of least privilege) and @awscloud Security Hub helps shine a light on those issues #reinvent

Tweet 26/57 👇 Next tweet 👆 Start

@mosescj58 calls out—again, and will do again & again—how valuable MFA or multi-factor authentication is more details at https://aws.amazon.com/iam/features/mfa/ remember if you’re onsite, you can pick up a hardware MFA key…and you can always use an MFA app #reinvent

Tweet 27/57 👇 Next tweet 👆 Start

details on getting an MFA key onsite 👇 https://twitter.com/AWSSecurityInfo/status/1597263326589120514 #reinvent

Tweet 28/57 👇 Next tweet 👆 Start

get an MFA key online (with some restrictions) at https://aws.amazon.com/security/amazon-security-initiatives/free-mfa-security-key/ #reinvent

Tweet 29/57 👇 Next tweet 👆 Start

@mosescj58 moving into six 🔑 learnings for @AWSSecurityInfo: 1. educate everyone about #security 2. build a security-first culture 3. hire & develop the best #reinvent



Tweet 30/57 👇 Next tweet 👆 Start

...continuing the six 🔑 learnings... 4. shift left & automate 5. invest in a dynamic workforce 6. make security the department of “yes, and…” #reinvent



Tweet 31/57 👇 Next tweet 👆 Start

btw, @mosescj58’s voice is toast 🍞, but he’s powering through like a champ hang in there CJ! #reinvent

Tweet 32/57 👇 Next tweet 👆 Start

moving on to predictions for 2023 now... #reinvent

Tweet 33/57 👇 Next tweet 👆 Start

increasing threat continue to drive the shift to the cloud …this is a data problem. @awscloud Security Lake is designed to help remove barriers in analyzing that data and drawing insights from it #reinvent

Tweet 34/57 👇 Next tweet 👆 Start

more on @awscloud Security Lake in this blog post by @channyun…but you already knew that 😉 https://aws.amazon.com/blogs/aws/preview-amazon-security-lake-a-purpose-built-customer-owned-data-lake-service/ #reinvent

Tweet 35/57 👇 Next tweet 👆 Start

next prediction: we need more #security professionals. broaden your search net. we need more diversity and neurodiversity in our community more perspectives only make things better #reinvent

Tweet 36/57 👇 Next tweet 👆 Start

next prediction: automate everything why? there’s just too much data that needs protecting…and too much security data that needs to be processed. the only way is automation #reinvent


Tweet 37/57 👇 Next tweet 👆 Start

the new automated data discovery from Amazon Macie aims to help with this session SEC209, “Continuous innovation in AWS threat detection & monitoring services” covers this in more depth (on the @AWSEvents YouTube channel soon) #reinvent

Tweet 38/57 👇 Next tweet 👆 Start

the blog post on Macie is up at https://aws.amazon.com/blogs/aws/automated-data-discovery-for-amazon-macie/ #reinvent

Tweet 39/57 👇 Next tweet 👆 Start

another feature that helps here is external key store (XKS) for @awscloud KMS (key management system) blog post on that is available at https://aws.amazon.com/blogs/aws/announcing-aws-kms-external-key-store-xks/ #reinvent

Tweet 40/57 👇 Next tweet 👆 Start

s/service/system/👆 #reinvent

Tweet 41/57 👇 Next tweet 👆 Start

more on @awscloud KMS at https://aws.amazon.com/kms/ #reinvent

Tweet 42/57 👇 Next tweet 👆 Start

Tweet 43/57 👇 Next tweet 👆 Start

another @AWSSecurityInfo IAM feature: multiple MFA devices for root users and IAM users blog at https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/ #reinvent

Tweet 44/57 👇 Next tweet 👆 Start

btw, Verified Permissions is part of the broader “provable security” initiative from @AWSSecurityInfo tons of great features/services have come from this push program page is up at https://aws.amazon.com/security/provable-security/ #reinvent

Tweet 45/57 👇 Next tweet 👆 Start

@mosescj58 diving into some post-quantum cryptography details. lots of work going on here in the community blog post: https://aws.amazon.com/about-aws/whats-new/2022/03/aws-kms-acm-support-latest-hybrid-post-quantum-tls-ciphers/ #reinvent

Tweet 46/57 👇 Next tweet 👆 Start

@mosescj58 takes a quick pause as we get a video to intro @united #reinvent

Tweet 47/57 👇 Next tweet 👆 Start

now to a fireside chat between @mosescj58 and @deneendefiore, CISO @united #reinvent

Tweet 48/57 👇 Next tweet 👆 Start

@deneendefiore is speaking to the resiliency challenges with technology. every traveller interaction @united crosses a lot of different systems, #security and resiliency are critical at each stage #reinvent

Tweet 49/57 👇 Next tweet 👆 Start

on automation, @deneendefiore talks about leveraging @AWSSecurityInfo services and automating their own systems to ensure that builders @united are starting from strong, secure-by-default positions #reinvent

Tweet 50/57 👇 Next tweet 👆 Start

@deneendefiore @AWSSecurityInfo @united on culture: @deneendefiore points out that aviation is already a safety aware culture. it’s an “easy” bridge to #security …when compared to other verticals that common understanding makes collaboration a lot easier if you don’t have it, you can build that culture #reinvent

Tweet 51/57 👇 Next tweet 👆 Start

another great call out that everyone can use: find the cultural points in your organization that are already there. use those as #security entry points @deneendefiore & @united use regular safety briefings that are already in place ❤️👆 #reinvent

Tweet 52/57 👇 Next tweet 👆 Start

@deneendefiore @united @mosescj58 calls out @awscloud's approach with #security learning/education check out and use their solution at https://t.co/TNoUHSzX8i #reinvent

Tweet 53/57 👇 Next tweet 👆 Start

@deneendefiore @united @mosescj58 @awscloud @deneendefiore's focus for 2023: - be brilliant at the basics - advance capabilities as your environment changes (tech/biz/regulatory/etc.) - enable the business! #reinvent

Tweet 54/57 👇 Next tweet 👆 Start

@deneendefiore @united @mosescj58 @awscloud on to the challenges around recruiting, developing, and maintaining #security talent... #reinvent

Tweet 55/57 👇 Next tweet 👆 Start

@deneendefiore is a great example of a lot of #security career path...from anywhere. there's no one path to get into security if you're hiring, understand that. yes, it's more work, but so, so worth it #reinvent

Tweet 56/57 👇 Next tweet 👆 Start

@deneendefiore key point from @mosescj58: you can hire a diverse set of ppl, but if you don't have a culture of inclusion...they aren't going to stay or succeed! #reinvent

Tweet 57/57 👇 Next tweet 👆 Start

@deneendefiore @mosescj58 ...and that's a wrap from the #security leadership session by @mosescj58 at #reinvent 2022! hopefully, he's now off to get some tea 🍵 for his voice

Read next