Skip to content
OnCloudSec
ServicesAI AssessmentInsightsAboutContactFree assessment

Insights

AWS

Articles in AWS.

AllMicrosoft 365Entra ID & IdentityAzureAWSMulti-CloudAI SecurityNewsRetrospectivesIncident TeardownsHow-To & HardeningDetection & ResponseCIO Briefings
AWSPlatform Changes

Amazon Macie Launches (Aug 2017): Machine Learning for Finding Sensitive Data in S3

In August 2017, AWS launched Amazon Macie, a service that used machine learning to discover, classify and protect sensitive data stored in Amazon S3. It...

AWSHow-To & Hardening

How to Use Amazon Macie to Discover PII in Your S3 Buckets

Amazon Macie scans S3 buckets for sensitive data such as names, financial information and credentials. Here is how to run it effectively without a surprise...

AWSHow-To & Hardening

Amazon Macie Rollout Checklist: Cost Controls and Finding Triage

Use this checklist before and after enabling Amazon Macie to get value quickly while keeping costs predictable.

AWSCIO Briefings

CIO Brief: You Can't Protect Data You Haven't Found

The short version: In 2017, AWS released Macie, a tool that finds sensitive data like customer records hidden in cloud storage. Its premise is simple and...

AWSIncident Teardowns

Verizon Customer Records Exposed via a Vendor's S3 Bucket (July 2017)

In July 2017, UpGuard researchers reported that records belonging to millions of Verizon customers were sitting in a publicly accessible Amazon S3 bucket....

AWSHow-To & Hardening

How to Use S3 Bucket Policies and Access Points to Enforce Least Privilege

Bucket policies decide who can access data in Amazon S3. Written loosely, they leak data; written tightly, they make many attacks impossible. Here is how to...

AWSDetection & Response

Detecting S3 Bucket Policy Misconfiguration: CloudTrail, GuardDuty and Athena Queries

Overly broad bucket policies are a frequent root cause of S3 exposures. Detecting policy changes that widen access — and catching risky policies already in...

AWSCIO Briefings

CIO Brief: Third-Party Cloud Risk — Writing Security Into Vendor Contracts

The short version: In 2017, a Verizon vendor exposed customer records — including account PINs used for phone support — in a cloud storage folder anyone...

AWSIncident Teardowns

198 Million Voter Records in an Open S3 Bucket (June 2017): Anatomy of a Misconfiguration

In June 2017, researcher Chris Vickery of UpGuard found an Amazon S3 bucket containing personal data on about 198 million American voters. It belonged to...

AWSHow-To & Hardening

How to Find and Lock Down Public S3 Buckets Across Every AWS Account

Public S3 buckets were behind dozens of data leaks in 2017. AWS has since made buckets private by default, but older accounts, older buckets and deliberate...

AWSDetection & Response

Detecting Public S3 Bucket Access: CloudTrail, GuardDuty and Athena Queries

The best time to catch a public S3 bucket is the moment it becomes public. Detection rules on configuration changes close the window between a mistake and...

AWSCIO Briefings

CIO Brief: Your Vendors' Cloud Buckets Are Your Data Exposure

The short version: In 2017, a data company working for the Republican National Committee left personal details on 198 million voters in an unprotected cloud...

AWSIncident Teardowns

The AWS S3 Outage of February 2017: A Typo That Broke the Internet

On February 28, 2017, Amazon S3 in the US-EAST-1 region became unavailable for about four hours. Thousands of websites and apps stopped working, and even...

AWSHow-To & Hardening

How to Architect S3 Workloads for Multi-Region Resilience

Amazon S3 is extremely durable, but a single region can still become unavailable. Here is how to design S3-backed workloads to keep running — or at least...

AWSHow-To & Hardening

Running a Cloud Outage Tabletop Exercise for Your IT Team

Outages are rare enough that teams forget how to handle them. A tabletop exercise — a structured discussion of a realistic scenario — is the cheapest way to...

AWSCIO Briefings

CIO Brief: Availability Is Security — Building Outage Risk Into Your Cloud Strategy

The short version: In 2017, a mistyped command at Amazon took down a core storage service in one region for about four hours, and thousands of websites went...

AWSPlatform Changes

AWS Shield Launches at re:Invent 2016: Free DDoS Protection Becomes the Default

At AWS re:Invent in late 2016, Amazon announced AWS Shield, its managed DDoS protection service. The headline was simple: every AWS customer would get...

AWSHow-To & Hardening

How to Configure AWS Shield Advanced and AWS WAF Rate-Based Rules

AWS Shield Standard protects every AWS account against common network-layer DDoS attacks automatically. Application-layer attacks need more work. Here is...

AWSHow-To & Hardening

DDoS Readiness Checklist for AWS-Hosted Applications

Use this checklist to check whether an AWS-hosted application is ready for a denial-of-service attack. Each "no" is a gap to plan for.

AWSCIO Briefings

CIO Brief: Shield Standard vs. Advanced — Is Paid DDoS Protection Worth It?

The short version: Every AWS customer gets Shield Standard free, and it handles the most common DDoS attacks. Shield Advanced is a paid upgrade that adds...

← NewerPage 5 of 5
OnCloudSec

Cloud & AI security for Microsoft 365, Azure and AWS

Services

Copilot Readiness AuditMicrosoft 365 Security AssessmentEntra ID Hardening SprintAWS Security BaselineAzure Landing Zone Security Review

Insights

Microsoft 365Entra ID & IdentityAzureAWSAI Security

Company

AboutAuthorsContactPrivacyRSS
© 2026 OnCloudSec. Vendor names are trademarks of their owners; OnCloudSec is not affiliated with Microsoft, Amazon or other vendors mentioned.