中文

Where Does AWS Stand in the Cybersecurity Conversation?

AWS dominates the cloud market, but its voice in the cybersecurity community is not as prominent as that of Microsoft and Google. Although AWS is not inferior in security capabilities, its shared responsibility model and customer-centric approach to information disclosure make it appear conservative in security thought leadership. Multiple analysts point out that this low-key stance may stem from business strategy rather than insufficient security investment.

2022-11-297views
Where Does AWS Stand in the Cybersecurity Conversation?

As enterprises accelerate their move to the cloud, Amazon Web Services (AWS) is riding the wave, outperforming peers and firmly occupying the spotlight in enterprise technology. However, unlike Microsoft and Google, this cloud giant has not turned its spotlight on the security sector.

Security researchers and analysts point out that this does not mean AWS lags behind competitors in security or cybersecurity investment. But there is indeed an impression that AWS is not as open and transparent as Microsoft Azure and Google Cloud in sharing insights with the broader cybersecurity community.

AWS's security messaging relies heavily on the "shared responsibility model." This model promises that AWS is responsible for the security "of the cloud," while customers must secure "in the cloud." The company primarily shares research, threat intelligence, or vulnerability and risk assessments related to AWS products. This public information, including security bulletins, is first directed at AWS customers.

AWS also helps shape security governance frameworks through participation in the U.S. Cybersecurity and Infrastructure Security Agency (CISA) advisory committee. This cloud giant plays an active role in the cybersecurity community, but according to nearly a dozen experts and analysts interviewed by Cybersecurity Dive, the consensus is that it simply remains quiet about it.

Mauricio Sanchez, research director for networking at Dell'Oro Group, believes that the differences in how the three cloud giants are perceived in cybersecurity largely stem from differing business philosophies. In an email, he said: "AWS seems to have adopted a strategy of 'not competing in security is better for profits,' while Microsoft and Google have chosen to make it a business priority." AWS declined Cybersecurity Dive's request for comment on how it engages with the cybersecurity community and its space for sharing security information.

The king of the cloud

AWS's importance to Amazon cannot be underestimated. The cloud division contributes only 16% of Amazon's net sales, yet it is key to Amazon's profitability. In the third quarter ending September 30, Amazon's North America and international segments both posted operating losses, making AWS the sole reason the company remained profitable.

Overall, AWS, Microsoft, and Google together hold two-thirds of the global cloud market, but AWS alone controls 34% of the market—more than the other two hyperscalers combined. According to John Dinsdale, chief analyst at Synergy Research Group, Microsoft Azure controls 21% of the public cloud market, with Google Cloud following at 11%.

Claude Mandy, chief evangelist for data security at Symmetry Systems, said AWS does not try to be a thought leader in security. "They are thought leaders in the cloud and leaders in that space," Mandy said. "They want to be synonymous with the leading cloud service provider."

Market research firms list AWS as a key player in the global cloud security market, but the scale of its security business is largely unknown. Amazon does not separately disclose security-related revenue in its earnings reports or filings with the U.S. Securities and Exchange Commission. In the company's most recent earnings call, security was mentioned only in passing once.

Sanchez said: "Unfortunately, in cybersecurity, perception often matters more than substance. I think AWS does get unfairly blamed because they don't market and monetize cloud security solutions as aggressively as Microsoft and Google."

How AWS positions itself in cybersecurity

If one hyperscaler insists on being the thought leader in cloud security and earns that reputation, the other two may ultimately face perceived or actual consequences. All three major cloud providers regularly host security-focused conferences and participate in industry events, and all embed security into their solutions.

AWS continues to support federal government initiatives such as the Joint Cyber Defense Collaborative (JCDC), where its executives often work alongside peers and heads of federal cyber agencies to promote collaboration and advocate for expanding the cybersecurity workforce. In August, a coalition of 18 companies launched the Open Cybersecurity Schema Framework (OCSF) project, originally initiated by AWS and Splunk, aimed at creating a common model for sharing data needed to identify and contain cyberattacks.

AWS does not hide these efforts, but it does not trumpet them either. This may be intentional. Zeus Kerravala, founder and chief analyst at ZK Research, said: "AWS doesn't market security because they are the market leader and see it as part of their job. However, they could do more."

The security strategy explained by company executives at its security conference AWS re:Inforce in July is to balance providing embedded security capabilities (minimizing customer effort) with guiding customers to third-party vendors that can meet specific needs. AWS's website lists nearly 20 cloud security products and features, covering identity and access management, detection, network and application protection, data protection, incident response, and compliance.

These services are integrated into customers' AWS computing environments, but more customization options are available through AWS Marketplace. A simple search for "cloud security" yields nearly 4,200 product results, including offerings from well-known vendors such as Palo Alto Networks, IBM Security, Check Point, and CrowdStrike.

AWS leads with a developer-centric strategy, Microsoft takes an enterprise-centric approach, and Google falls in between. These strategic differences lead to vastly different outcomes. Sanchez noted that Microsoft is leveraging its long history in enterprise endpoint operating systems into a cloud security advantage, while AWS offers a vast marketplace, showing it is more willing to partner with third-party security vendors than to lock customers into internal products. "Google is in the middle, and until recently, it didn't seem to lean toward either end."

Google completed its $5.4 billion acquisition of Mandiant in September, which Sanchez believes "clearly signals they want to be recognized as a security provider like Microsoft."

Security perception stems from different strengths

AWS's first-mover advantage in the cloud has led to an accumulation of security capabilities. According to researchers and analysts, it provides an embedded security baseline that keeps most customers free from worrying about anomalous activity. Davis McCarthy, principal security researcher at Valtix, said Amazon likely addressed cloud security requirements before Microsoft and Google, with the latter two now facing a "trial by fire" in a more intense threat environment.

For most small and medium-sized organizations, this "one-click" approach offers more protection than they could develop internally, but large enterprises often have special needs requiring customization and complex configurations. Custom development and proactive threat hunting based on intelligence shared by cloud providers would further enhance an organization's defenses.

Microsoft stands out in this regard, partly due to its legacy in the enterprise market. It regularly shares specific details of vulnerabilities and how they apply to enterprise environments to support threat hunting and analysis. This historical accumulation and ongoing public engagement with the cybersecurity community explains why many view Microsoft as a long-term reliable source of information gathering and sharing.

McCarthy said: "The threat environment is increasingly targeting the cloud, and Microsoft has been part of that conversation, while AWS has not. I look forward to seeing more from AWS, more leadership in this space."