AWSCIO BriefingsRetrospectives

CIO Brief: Encryption by Default — What It Does and Doesn't Protect

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2023, written in 2026 with the benefit of hindsight.

The short version: Since January 2023, AWS automatically encrypts all new files stored in S3. That's good — but encryption by default doesn't stop someone with the wrong access from reading your data. Who can access data still matters most.

What encryption at rest protects

Default encryption protects data on physical disks in AWS's data centers. If someone stole a hard drive, the data would be unreadable. That risk is real but small.

What it doesn't protect

If an attacker steals a password or cloud key with permission to read your storage — or if storage is accidentally made public — the data is decrypted automatically for them. Most cloud data breaches happen this way.

Where encryption adds real control

Using your own managed encryption keys for sensitive data adds a second lock: people need permission to the storage and to the key. You can also turn off a key to make data unreadable, and every use of the key is logged.

Questions to ask your team

  • Which of our data uses company-controlled encryption keys, rather than defaults?
  • Who can use and manage those keys?
  • Would we know if someone suddenly decrypted large amounts of sensitive data?

What good looks like

Default encryption everywhere, company-managed keys for sensitive data, separate key administrators, and monitoring of key usage.

The decision

Don't treat "encrypted at rest" as a finished control in audits. Ask instead: "Who can decrypt this data, and how would we know if they did?"

s3 default encryption impactS3 default encryption2023

More on this story