CyberWiseCon Europe 2025

Joachim Aumann: What “Security Needs to Be Our Top Priority” Means for Aws Builders/Customers

33:37 · 20 May 2025 – 23 May 2025 · YouTube

About this talk

This talk emphasizes the critical importance of prioritizing security within AWS cloud environments. The speaker, Jo Kiman, highlights the speed at which security breaches can occur, citing an example where an exposed API key was used to compromise a system in under a minute. He stresses the shared responsibility model of AWS, where AWS secures the underlying cloud infrastructure while the users must secure their applications and data. Kiman introduces specific AWS services such as Trusted Advisor and Inspector, which help developers monitor and improve their security posture. He also discusses the need for proactive measures, regular audits, and the importance of compliance, encouraging teams to make security an ongoing priority in their development cycles.

Full transcript

ladies and Gentlemen please welcome our next speaker Jo kiman presenting the topic what security needs to be our top priority means for AWS Builders or [Music] customers thanks for joining after lunch this session here uh why top uh security needs to be your and our top priority I'm Yim Oman 4 and a half years a solution architect at aw this talk I will use a lot of

AWS acronyms but the message you will get doing this talk is cloud cloud agnostic so you can use it for any clouds um who thinks about his work day like this hands up right super busy you have to concentrate on a lot of things you need to think about a lot of topics you need to build features these features needs to be depl loids uh scal scalable

reliable um you need to have everything ready for the next Sprint and now Yim comes and tells you that there's one thing more you need to uh what needs to be your top priority and this is security and I want to give you one example why this is so important and there was a magazine 20 22 they did a test and what they did is they used

an API I key from AWS an exess key to a service and to a user and published them on uh GitHub and what they then did they measured the time how long it takes until an attacker has used this access key and attacking the AWS environment and and your applications so some guesses in the room how long you think it took until the uh security key was

published until the attacker came in attack the system some guesses from The Room 5 minutes some some more guesses 3 minutes it was under one minute under one minute it took and and this is two years ago and maybe it's already the new measurements which be maybe 30 seconds or so or even faster this means when you do a security brege if you have a security Bridge

you cannot act anymore because there are scripts out there there are automations out there which brings your systems at risk and there are attackers which attack your system so that's why you as a developer you as a security team needs to have Security on top of your priority list and on top mind and how we support from AWS us as Builders and um security teams in the

cloud is we have the shared responsibility model we from aw take care about security of the cloud so we make sure that our data centers are secure that only privileged people can enter them or know their location and secondly our services are built with uh Security in mind as a top priority but second thing is on you Security in the cloud is your job as a builder

as a user of AWS this means you need to make sure that your data you store at aw your applications you you run are secure right and we from AWS help you with this list of services it's a exhaustive list of services we have for uh Security Services um we have it uh divided in different areas we have uh security service for identity and access management that

you can secure your servers uh users um data protection uh detection and response our security services which help you uh to to look for security breaches Network and app protection our Network Services which are protecting your uh applications data protection um you can use um for example KMS Keys you can upload your own Keys you can decrypt your data in the cloud and we have compliant Services

you don't need to remember all of them I want to go into specific example of services for developer for Builders are working in the AWS cloud and for security teams which are maybe some of you part of and want to introduce some Services you need to watch out and look for and the first service for developers is trusted advisor trusted advisor is a free service you can

look up in the AWS cloud and it gives you SEC uh security recommendation for your workload this means it knows your application it knows which Services you use and you get specific recommendation on security topics for your workload and what is important is that it's uh has already best practices built in is that you use the services and check what is uh yeah what are the recommendations

in for you there and um what I what I want to uh INF influence with this picture is this is something you need to do regularly right and like you go into a fitness studio it's it's a fitness coach right and you need to build up this muscle and you need to continuously look into your security findings and audits the next service you need to work with

when you an AWS developer is Inspector Inspector scans uh ec2 instances your Lambda functions and as well your containers which you host in ECR and this Services uh and this service then gives you recommendations in on security uh patching levels and and tells you if you use a package on an ec2 instance or if you run an outdated um uh your library so this is the next

service you as a developer need to make sure that you patch your um system accordingly that you have always um the up to-date versions on it so for developers call to action if you go home today or if you even make it then in the short break after the call out um turn on the automatic notifications that you will get emails from the services for example from

trusted advisor you can get your weekly reports for your services you're responsible for for your AWS accounts and look into them look at them at every Sprint right you do maybe retrospectives you do uh different Sprint um uh yeah meetings why not having one where you look at the recommendation this system gives you frequently after you have builded new features because as we have seen it's it's

our it should be all our top priority and if you have systems like uh partner systems like data dog or other services which you already use you can feed in the information from these Services into Data talk and you can use the services as well to monitor these things this is for you as a developer if you are part of a security team and you need to

take care about hundreds maybe thousands of AWS service and if you make need to make them secure these are the challenges we heard from customers that they face right you have all this massive amount of data uh a colleague from a customer told me yeah it's readed like a Christmas tree and I don't know what finings I all have I don't know who is responsible for this

right and this challenges we hear from AWS and we want to have your security teams um yeah to secure your cloud and this is the service you should look at uh is in the mid in the center of the screen AWS security Hub and it's a hub service where all the security findings from other services come in so for example G Duty Macy or uh Amazon inspector

will all triage their findings into uh AWS security Hub and you will have the chance to look at them holistically from your complete AWS organizations so no matter what how many accounts you have no matter um which Services you use everything will be in this place and then you can use this service to enrich it even further and use other services I want to tell you how

a flow of uh finding will look like so a lot of uh Inspection Services will go into a security Hub and also uh security H has an open API where you can um post any U many third party Services as well into security Hub but it has well an open API that you can push any findings you may be see uh to the system and then it

comes with a very strong and important topic with compliance a lot of controls and standards are built in uh security Hub and you will see if you're compliant with your company to this security standards which is an very important thing for compliance audit auditor if you need to show this on a yearly basis to some audit person which comes and audits your system and then you have

the chance with event Hub uh uh service where you then can push recommendation to for example slack to your teams or on email to other uh to to your responsible person for this individual account um you can use even Lambda function or other services like step functions to automatically remediate findings you find in security Hub and act as soon as uh as soon finding is their insecurity

up and remediate this uh topic so for example what I see with customers is if there is a port open which should be not open to the public that I directly close this open port directly again this is an example for this and um yeah uh you can if there is a a finding detected you can use detective to see what was going on was this uh

um security incident may be used by how many attackers were already there so we have services to to look into this so now we had to a look at certain Services if you're a developer and we looked at certain Services if you are um running a security team or part of a security team now I want to give you some recommendations on your daily work what um

you can get out of today and uh increase your security poster if you apply to these tips which I give you now so this is five minutes of an ec2 instance lock when I open it to the public internet and what we see here is attackers coming all the time and try to attack our ec2 instance right this is only 5 minutes of uh uh of lock

of of an E2 instance and this means as soon as you open any port of an uh VM uh VM and and this is really cloud agnostic right ec2 in this case for AWS you will have a security attack vector and my recommendation is don't use SSH anymore via Port 22 this is not needed anymore in the current uh environments we are in because course we have

Services uh like systems manager where you can open securely an SSH tunnel through the E uh ec2 machine via Port 443 so you don't need to open these ports anymore and if you run container workloads for example uh on Amazon ECS or if you run kubernetes on eks there are tools like Cube CTL XC to directly jump into this um workloads without any open port because all

of these tools working on Port 443 which are secured with the with certification right and the next thing is I want to tell you a small story so when I started at AWS I think I was one month in I uh got we get accounts from AWS where we can uh play and and try out things and I it was a Friday evening I was uh doing

a demo I I did a workshop and I worked on this workshop and um in in my account and then it was 11 12 in the night whatever I don't know I closed the laptop went to bed at 2:30 my uh director from Seattle called me on my phone because what I have done is I open an S3 bucket to the public so I have opened um

an attack vector and the policy is on AWS this is strictly forbidden and will not be tolerated so what will happen if this happens in my account it's is scanned it it's going an alert to me and then it's going to an alert if I'm not reacting in a certain time 30 minutes my manager gets this alert and if he is not reacting his manager gets the

alert until it goes up the chain and someone will react and find and uh uh find you and make you sure that you close this and um let me quickly because I wanted to show you the tone uh let's see if it works what it does when this happens because it's an paging application every developer at AWS needs to uh or every person at AWS having this

account needs to um uh install and then we get a page which wakes you up in the night so the message is don't open any S3 bucket anymore to the public it's not needed anymore you don't need to do this anymore right we and I I think a lot of people in the room can tell certain stories that certain information was leaked in public S3 buckets um

uh databases uh customer data and so on right and this is not need it anymore because U we have for example a service called cloudfront it's our CDN service which you can use to p uh publicly certain uh yeah topics if you need to uh to the internet for example if you have images in an S3 Bucket close down this S3 bucket only uh on private access

and use this feature with cloudfront that it's securely connect Ed from cloudfront to S3 and it's using the AWS backbone and with cloudfront you get a lot of benefits for example you get DS prodection you get um possibility to have higher security instead of open3 pockets PL plainly and as I said for AWS uh employees it's strictly forbidden and we have a lot of more policies which

are strictly forbidden and you will get the same alerts and same calls from your manager at night and yeah so this is the tip the second tip I want to give you the third is this I've taken this photo when I was at a universitary laboratory it's a German but what you see here this London 16 someone put a password at this desk and then I I

found it funny and I did a photo of this right and we love sometimes if you see this kind of photo right and and we think hey why you do right the same thing is with exess keys if you use them in your code right any AWS access key or IM access key is nothing more then a printed out password for your service for your application and

we have too often seen these exess Keys ending up in apis in SDK deployed on a mobile phone right which is and everyone has on his phone right we have seen these Keys too often leaking to the public um and and this is something which is really uh a problem and that's why you should not do this anymore don't print out any passwords don't print or use

any Keys you uh for for your users or for your application we have a solution for this and it it's uh called IM IM roles this means that you can give your Lambda function your ec2 instance or your uh application running at at some service on AWS specific rights to do a certain action and for example a Lambda function can call an S S3 bucket and you

can Define in this role the specific S3 bucket you want to call so please don't use any access Keys anymore and there are another service which I'm really a fan of and a lot of customers start using as well as IM roles anywhere so if you have a third party which needs to access your system or your endpoints there is a way with a roles anywhere to

do this securely without any API key or token what am am roads anywhere works on uh certification so you have a private certification uh certificate you give to your third party and this is checked with uh your Authority normal client certification handling so what I want to influence in this third tip is please make sure you don't print out any passwords anymore you don't have any hardcoded

credentials in anywhere in the code we have too often seen this up uh seen this happening on on GitHub or and in any other public spaces so for the next tip I need your help this is uh from a a picture from the movie 300 who who have seen it okay a lot of people who knows why they have lost why they have lost there were only

300 yes exactly so they lost right where if you have seen the movie right there was a valley and they fighted again at this attack Vector where or 300 uh where where the valy was very narrow and 300 could prot protect this uh vector and and this huge Army which came were running against this narrow place right but what happens in the movie and actually happened in

history a SC or someone whispered that there is a way around this Valley and they were then attacked from the back and were uh beaten up and they lost the battle so what you need to do is this should not happen to you you need to know which are your attack vectors what are your public endpoints do you know this for your AWS account for all your

applications for all your um services for all your accounts this is what you need to do you need to know if there is someone going behind you and they attack you from a a surface what you uh maybe don't know even right so you security groups close down as much as you can of course you need to have open ports like 443 for example this is okay

and then you use other services like awsw or web application service to protect your ble ground right uh with the anology of of Spartans right you protect as much as you can your a tech vector and please make sure that there is no Whisperer or something what you're not aware of a away around your protection line which is then uh attacking you from behind right and uh

one more service I have put here um it's Shield Advanced um I don't know if you know it and that's why I like it to put it there because it's not an very much known service but with Shield Advance your organization will get in and in attack phase of DS attack for example access to an very skilled very great AWS team you can then contact and they

have you on 50 minutes it's it's a defensive team which is there to help you in your Battleground on your valy right so if you have uh certain requirements think about AWS advanc the next anology is this and what I have done and why I've you choose this what I do if someone sends me a newsletter which I don't want to receive I ask them to delete

all my personal data and send them to me right and this is the data then they need to Shredder or need to get out of the system security needs to be on top of our priority but as well I I think compliance is as well a topic which you need to think about right pii personal identify data as I don't want that it's stored everywhere in in

in the application or at any systems right I I need to make sure this for my applications I guarantee this as well right so if you have pii personal identified data in your application make sure you know where they are right and you need uh automation to detect them right you have thousands of data all our application works with so much data you need to have Automation

in place which tells you hey at this application at this data store you have personal identifier data because there could be your arim coming and asking delete all of them right and you then need to Define uh controls and life cycle management which make sure that this data is deleted why life cycle management because the ru the law says delete this as well from backup data right

so make sure you get this right as well right because I uh to be honest right if I first saw this law I said okay this is hard but this is in benefit from all of us I use it sometimes and I want that the companies I trust and give my data having this in place I want that you shoot high on your security standards uh this

slide was influenced by an customer a CTO of a company uh it's a German um website where you can sell mobile uh cars online and and it's a trading market for cars and what he said we at some point in time he was speaking to the management to the sea level I said we freeze now for three months and I work on all open security findings we

have right and and you and and and then they froze everything worked on all security uh topics and if there are new security incident or topic came up it went on top of their backlog and they were directly addressing them right because what it is a security warning a security alert you may receive brings your company at risk right and and and it's right there are huge

finds of of public if if your customer data for example of your application is leaked to the public so that's why it's so important it's should be your top priority it should be on top of your backlog if you have a finding and this is what he implemented and um they reduced all this uh security findings in in a certain time and then went to went on

with feature development of course but with the strict rule if there's a security finding it goes on top of your backlog you need to make uh them then I want to give you another example of a customer sa uh I've written a blog post um with a security expert from sap how sap secures 6,000 AWS account and what they do is they use a partner called Ora

security and orca security gives them the ability to continuously scans all the 6,000 accounts right and if there is a security alert it's out automatically um uh paging and emailing the account owner to to know hey make sure you address your topic and also have automatically REM remediations in place for example I talked about Port 22 they put directly if someone opens the port it's directly closed

and put uh to uh put the IP address of uh s internal Network into uh the um into the security right and and and this gives at least they talk publicly about this we have written this blog post and this gives confidence to the customers of sap which running the EAP system the Eep system is the backbone of your complete uh business right in the cloud and

you need to make sure that your customers can trust you in the same way right that you have this mechanisms in place that um your customers can trust that you do your job correct corly and the next thing is what we have uh done from AWS to help you to fulfill these requirements is we build it up the well architected framework and it has a security pillar

for them you maybe you don't know the well architected uh framework it's an service for free in the console so you can go in and then it's a questionnaire you can do with your team to see if you um they applied to these standards these standards which you see here at the B architector Frameworks are standards we from AWS have developed over the last 15 to 20

years with our customers and this is the condensed way you will get recommendations to what uh to do when you have a certain findings uh even hey use this service to protect you against this threat I know no developer me included don't like to do questionnaires right but it's something right do it in a beer garden with the team get you two hours and go through everyone

prints it out right but do this um uh task because it will give you a confidence in the team that okay we apply to certain security standards or not right and then can uh yeah increase the security of your system so don't be scared it's it's a big photo of Jeff basos um and he has said an important uh topic good intention don't work do think about

this right no developer in your organization want to open a security gate right no one wants no developer wants this but it happens because we are all humans we have a stressful job maybe we forgot sometimes uh to to look at certain topics right what you need to do is you have mechanisms in place and this mechanisms is not only once a year or every quarter this

needs to be every Sprint or every time you make a big feature release you need to look at your uh security architecture right good intention don't work because everyone here in the room every developer wants to not open any security bridge but we are all human so have your mechanism in place to make your secure my last slide key takeaways right I want that you take your

security scanning and monitoring seriously and you do this on Sprint basis I put Sprint there because uh I think it's relating to a lot of of us here right but if an alert is there immediately react right look at your findings triage them look at the uh security gaps you have and close them this needs to be on top of your priority list because every open finding

brings your company your business at risk and with this um well architected framework make sure that you build best practice of security directly in your architecture right we have heard that for example I was in the talk uh before that cost needs to be as well in architected into your applications right cost is very important security is even more important all of your customers rely on that

you get this right right and with this I want to thank you I will send out the slides and I'm open for question if you have some okay thank you very much and now it's time for the questions I don't think we have anything in the uh in the survey but SL but maybe you have still questions who likes 300 okay remember this if you if you

see the next button uh video or topic or picture yeah so maybe I have some questions sure to to use the time uh so so is a WS planning to do something like Global policies as you said for example about the policy that you have enforc that you cannot open S free bucket but it would be nice if you could for all your accounts in particular arons

inws just just do that that write down this kind of the policy and that it won't be possible um if you create an S3 bucket it is secured by default right it is closed so you need to intentionally open his pocket for example right um I I think this was a change we introduced that it's by default closed I'm not aware because we want to give our

customers all the flexibility that we introduce uh um possibility to possibility but what we try to do is to make it secure by default and that you as a customer need to actively do right I like AWS config a lot as well it's a service where you can scan as well and then you see what is configured and you can map it um but I'm not sure

and I don't think it's the way we Design Services that we say hey this is a hard stop but maybe I'm proing wrongly soon but yeah okay yeah any other questions okay then thank you so much for coming um I think I will be at this corner ask the expert uh ask the speakers and thank you