AWSPlatform ChangesRetrospectives

AWS Shield Launches at re:Invent 2016: Free DDoS Protection Becomes the Default

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2016, written in 2026 with the benefit of hindsight.

At AWS re:Invent in late 2016, Amazon announced AWS Shield, its managed DDoS protection service. The headline was simple: every AWS customer would get baseline DDoS protection automatically, at no extra cost.

What changed

AWS Shield came in two tiers:

  • Shield Standard — applied automatically to all AWS customers, defending against the most common network- and transport-layer attacks such as SYN floods and reflection attacks.
  • Shield Advanced — a paid subscription adding enhanced detection, access to AWS's DDoS response specialists, attack visibility, and cost protection against scaling charges caused by an attack.

The launch came just weeks after the Dyn attack, when DDoS had suddenly become a boardroom topic.

Why it mattered

Before Shield, smaller companies either bought a third-party scrubbing service or hoped they would not be targeted. Making baseline protection a default lowered the floor for everyone running on AWS. It also nudged architectures toward services that benefit most from it: Amazon CloudFront, Route 53 and Elastic Load Balancing.

What it did not do

Shield Standard does not stop application-layer floods — large numbers of legitimate-looking HTTP requests. For that you still need AWS WAF with rate-based rules, caching and sensible application design.

In hindsight

Shield's launch marked a shift in the shared responsibility model: cloud providers began absorbing some security work by default. The pattern continued with default encryption, default S3 public access blocks and mandatory MFA. Defaults are powerful — but they only cover what they cover, and knowing the boundary is still your job.

aws shieldAWS Shield & WAF2016

More on this story