Mark Nunnikhoven Profile picture
Dec 1 57 tweets 48 min read
the @awscloud #security leadership session featuring @mosescj58 is starting now…

What we can learn from customers: Accelerating innovation at AWS Security

#reinvent Image
@mosescj58 up now, rocking some killer kicks 👟

#reinvent ImageImage
@mosescj58 celebrating 15 years with @awscloud 🥳🥳🥳

congrats CJ!

#reinvent Image
“Everyday I get to learn about the problems we can solve for customers, and how we can do that”, @mosescj58

#reinvent Image
@mosescj58 drawing the parallels between his sport—racing—and #security

- both driven by data
- safety is a key factor for success

#reinvent Image
good Bezos quote, “Customers are always wonderfully, beautifully unsatisfied.”

#reinvent Image
more than 90% of all the things @awscloud creates is directly from customers…the other 10% was built on behalf of those customers 😉

#reinvent
@mosescj58 sharing some of his previous roles in law enforcement and the parallels in his role with @AWSSecurityInfo today

both looking for one tiny indicator amid a torrent of data

#reinvent ImageImage
@awscloud has the scale to enable security

pre-AWS @mosescj58 was working with @jeffbarr back in 2007. those conversations kicked off a ton of security work

…which brought CJ to AWS

#reinvent Image
1st challenge: isolate workloads in a data center

…wow, think about that vs. what we heard in Peter DeSantis’ keynote on Monday about @awscloud Lambda function isolation

#reinvent
@mosescj58 reminiscing about the scrappy startup days of @AWSSecurityInfo

bean bag chairs => hand me down cube from AOL (!) in a dingy corner…working together as a small team cracking on a deeply interesting & challenging problem

#reinvent Image
experiments lead to virtualizing the network layer. that was what provided the isolation needed

#reinvent Image
that 👆 was the start of @awscloud VPC

#reinvent Image
“We’ve grown a tiny bit”, @mosescj58 aims for understatement of the show

#reinvent Image
by, the main “home” for @AWSSecurityInfo is aws.amazon.com/security/

…though there’s a ton of info everywhere in the service docs/whitepapers/etc.

#reinvent
events seen on the @awscloud global network….

…that’s a lot of zeros

#reinvent Image
that’s a new visual for the shared responsibility model. I think that’s much clearer than the older one w/way too many layers shown

#reinvent Image
great reference on the shared responsibility model: aws.amazon.com/compliance/sha…

#reinvent
“If you have access or control, you have responsibility”, @mosescj58 << great summary and ‘cheatsheet’ for the @awscloud shared responsibility model

#reinvent
getting a bit of a peek behind the @AWSSecurityInfo curtain here from @mosescj58

#reinvent ImageImage
@AWSSecurityInfo saw more than 224M malware samples in six months!

#reinvent ImageImage
all of the data that @AWSSecurityInfo gathers from their perspective informs new @awscloud services and features

that’s why we’re seeing so many new feature advances in things like Amazon Macie and Amazon GuardDuty

#reinvent
more on @awscloud Macie at aws.amazon.com/macie/

…Amazon GuardDuty at aws.amazon.com/guardduty/

#reinvent
exposed credentials are a continuing challenge. IAM helps reduce the blast radius (good ol’ principle of least privilege) and @awscloud Security Hub helps shine a light on those issues

#reinvent ImageImage
@mosescj58 calls out—again, and will do again & again—how valuable MFA or multi-factor authentication is

more details at aws.amazon.com/iam/features/m…

remember if you’re onsite, you can pick up a hardware MFA key…and you can always use an MFA app

#reinvent
get an MFA key online (with some restrictions) at aws.amazon.com/security/amazo…

#reinvent
@mosescj58 moving into six 🔑 learnings for @AWSSecurityInfo:

1. educate everyone about #security
2. build a security-first culture
3. hire & develop the best

#reinvent ImageImageImageImage
...continuing the six 🔑 learnings...

4. shift left & automate
5. invest in a dynamic workforce
6. make security the department of “yes, and…”

#reinvent ImageImageImageImage
btw, @mosescj58’s voice is toast 🍞, but he’s powering through like a champ

hang in there CJ!

#reinvent
moving on to predictions for 2023 now...

#reinvent Image
increasing threat continue to drive the shift to the cloud

…this is a data problem. @awscloud Security Lake is designed to help remove barriers in analyzing that data and drawing insights from it

#reinvent ImageImage
more on @awscloud Security Lake in this blog post by @channyun…but you already knew that 😉

aws.amazon.com/blogs/aws/prev…

#reinvent
next prediction: we need more #security professionals. broaden your search net. we need more diversity and neurodiversity in our community

more perspectives only make things better

#reinvent Image
next prediction: automate everything

why? there’s just too much data that needs protecting…and too much security data that needs to be processed. the only way is automation

#reinvent ImageImageImage
the new automated data discovery from Amazon Macie aims to help with this

session SEC209, “Continuous innovation in AWS threat detection & monitoring services” covers this in more depth (on the @AWSEvents YouTube channel soon)

#reinvent ImageImage
the blog post on Macie is up at aws.amazon.com/blogs/aws/auto…

#reinvent
another feature that helps here is external key store (XKS) for @awscloud KMS (key management system)

blog post on that is available at aws.amazon.com/blogs/aws/anno…

#reinvent Image
s/service/system/👆

#reinvent
this one is massive. @awscloud Verified Permissions

blog post: aws.amazon.com/blogs/security…

product page: aws.amazon.com/verified-permi…

#reinvent Image
another @AWSSecurityInfo IAM feature: multiple MFA devices for root users and IAM users

blog at aws.amazon.com/blogs/security…

#reinvent Image
btw, Verified Permissions is part of the broader “provable security” initiative from @AWSSecurityInfo

tons of great features/services have come from this push

program page is up at aws.amazon.com/security/prova…

#reinvent
@mosescj58 diving into some post-quantum cryptography details. lots of work going on here in the community

blog post: aws.amazon.com/about-aws/what…

#reinvent Image
@mosescj58 takes a quick pause as we get a video to intro @united

#reinvent ImageImage
now to a fireside chat between @mosescj58 and @deneendefiore, CISO @united

#reinvent ImageImage
@deneendefiore is speaking to the resiliency challenges with technology. every traveller interaction @united crosses a lot of different systems, #security and resiliency are critical at each stage

#reinvent
on automation, @deneendefiore talks about leveraging @AWSSecurityInfo services and automating their own systems to ensure that builders @united are starting from strong, secure-by-default positions

#reinvent
@deneendefiore @AWSSecurityInfo @united on culture: @deneendefiore points out that aviation is already a safety aware culture. it’s an “easy” bridge to #security …when compared to other verticals

that common understanding makes collaboration a lot easier

if you don’t have it, you can build that culture

#reinvent
another great call out that everyone can use: find the cultural points in your organization that are already there. use those as #security entry points

@deneendefiore & @united use regular safety briefings that are already in place

❤️👆

#reinvent
@deneendefiore @united @mosescj58 calls out @awscloud's approach with #security learning/education

check out and use their solution at learnsecurity.amazon.com/en/index.html

#reinvent
@deneendefiore @united @mosescj58 @awscloud @deneendefiore's focus for 2023:

- be brilliant at the basics
- advance capabilities as your environment changes (tech/biz/regulatory/etc.)
- enable the business!

#reinvent Image
@deneendefiore @united @mosescj58 @awscloud on to the challenges around recruiting, developing, and maintaining #security talent...

#reinvent
@deneendefiore is a great example of a lot of #security career path...from anywhere. there's no one path to get into security

if you're hiring, understand that. yes, it's more work, but so, so worth it

#reinvent Image
@deneendefiore key point from @mosescj58: you can hire a diverse set of ppl, but if you don't have a culture of inclusion...they aren't going to stay or succeed!

#reinvent Image
@deneendefiore @mosescj58 ...and that's a wrap from the #security leadership session by @mosescj58 at #reinvent 2022!

hopefully, he's now off to get some tea 🍵 for his voice

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mark Nunnikhoven

Mark Nunnikhoven Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @marknca

Dec 2
if you're still on site for @awscloud #reinvent this morning, remember it's a great time to catch a few super popular sessions on repeat

sessions run until ~12:30pm pacific!
@awscloud there's overflow for the fully booked, "Introducing Amazon VPC Lattice: Simplifying application networking" (NET215) at the Content Hub in the Venetian at 11:30am pacific

#reinvent Image
ditto for "Introducing Amazon CodeCatalyst" (DOP206) which starts in 30m...this time the overflow is in the Content Hub at Caesars Forum

#reinvent Image
Read 4 tweets
Dec 1
what will the theme of @Werner’s #reinvent keynote be this year? who’s the musical act for @AWSEvents re:Play tonight? what will be your favourite t-shirt of his?

let’s find out now…

/🧵 Image
dark & stormy, Matrix-style intro video...

#reinvent ImageImage
“The world is asynchronous”, @Werner

#reinvent Image
Read 135 tweets
Nov 29
here we go! @aselipsky up for today’s @awscloud #reinvent keynote…

/🧵 Image
@aselipsky takes the stage to Sweet Child of Mine 🎸🎵

#reinvent Image
50K in person, ~300K remote attendees

#reinvent Image
Read 77 tweets
Nov 29
here we go! Monday Night Live with Peter DeSantis is about to kick off at @awscloud #reinvent 2022!

a 🧵👇 (/cc @AWSEvents)
@awscloud @AWSEvents I love how much fun Peter has with this keynote!

#reinvent
Peter reminds everyone that this keynote is all about "how" @awscloud does things. lots of behind the scenes info in this one..

#reinvent
Read 74 tweets
Nov 28
a few notable, new @awscloud announcements so far today from #reinvent

👇

/cc @AWSEvents

/1
Amazon S3 multi-region access points get new functionality that allows you to shift data access requests to different regions as things hit the fan

#reinvent

aws.amazon.com/blogs/aws/new-…

/2 #reinvent
GAME CHANGER*: @awscloud Config _finally_ allows for proactive rules that can be run BEFORE spinning something up to catch issues

* changes the game in that we can all remove a bunch of Lambda/EventBridge stuff now

aws.amazon.com/blogs/aws/new-…

/3 #reinvent
Read 10 tweets
Nov 27
attending @awscloud #reinvent this week? already in Las Vegas?

1. pick up snacks for the week
2. pick up your badge & swag at registration (open until 8pm)
3. go for a bit of walk to familiarize yourself with the campus
4. follow @AWSEvents & download the app

/1
I'm attending remotely this year (😔), but still published my ultimate guide over on the @acloudguru blog. check it out at:

acloudguru.com/blog/business/…

/2 #reinvent
things really start to get rolling tomorrow (Monday). for remote attendees, the keynotes and leadership sessions will be streamed

you can sign up now: reinvent.awsevents.com/register/virtu…

...and add those to your calendar

/3 #reinvent
Read 4 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(