Hero guide: Secure Data Innovation Guide

This guide highlights AWS re:Inforce sessions for data innovators, focusing on securing data and analytics workloads. It covers secure data analytics, governance, and generative AI, providing tools and insights to build resilient, compliant data platforms that drive innovation while ensuring robust security.

Image Alt

Sanchit Jain

D&A Practice Lead

Quantiphi Inc

This guide curates a selection of sessions from Data and Analytics at AWS re:Inforce, explicitly tailored for Data Innovators focused on securing data and analytics workloads. Designed for professionals ranging from intermediate to expert levels, the primary goal is to empower organizations to innovate securely by advancing data-driven strategies and strengthening governance and compliance controls.

Key focus areas include secure data analytics, foundational data architecture, and the integration of generative AI, all with an emphasis on robust security and governance. Attendees will gain actionable insights into building and protecting resilient data platforms, leveraging the latest AWS technologies to unlock the full value of their data while maintaining stringent security standards.

Whether your priority is safeguarding sensitive information, implementing advanced data governance frameworks, or enabling secure generative AI applications, this guide equips you with the knowledge and tools to drive secure innovation and confidently manage your data estate in the cloud.

Securing Data for Tomorrow

Securing data lakes and databases is vital to protect sensitive business and customer information from unauthorized access, breaches, and cyber threats. Strong security ensures data integrity, supports compliance, and enables safe, effective use of valuable data assets

DAP451 | Builders' session | Reducing risk of sensitive data exposure in modern security lakes

Master advanced data protection for modern data lakes with hands-on PII detection, encryption, and automated workflows—leave with production-ready, compliant architectures

DAP351 | Builders' session | Securing data lakes: From ingestion to AI analysis

Build end-to-end security for AWS data lakes and AI/ML workloads. Gain practical skills in secure ingestion, dynamic access, and compliance monitoring with real-world exercises.

DAP353 | Builders' session | Leveraging generative AI for data protection insights

Learn to manage encryption keys and access policies across accounts using natural language queries. Gain actionable insights and dashboards for enterprise-wide key visibility.

COM222 | Lightning talk | Serverless threat response for Amazon S3 malware detection

Automate malware remediation for Amazon S3 using GuardDuty, Lambda, and Step Functions. Build scalable, serverless workflows to boost threat response and compliance.

SEC431 | Chalk talk | Dive deep into data protection architectures for Amazon Bedrock Agents

Understand how Amazon Bedrock secures data in generative AI, including cross-region and multi-agent scenarios. Learn proven patterns for architecting secure AI solutions.

GRC442 | Code talk | Beyond shift-left: Embedding controls in infrastructure pipelines

Embed automated compliance checks in infrastructure with AWS CDK and Terraform. Discover compliance-as-code patterns to enforce security without slowing development.

No Trespassing In The Cloud

Implementing proper governance in the cloud is crucial to protect sensitive data, ensure regulatory compliance, and manage access. Strong governance prevents breaches, reduces legal risks, maintains data quality, and enables secure, efficient data sharing and operations.

IAM351 | Builders' session | Data perimeter challenge

Learn to implement and validate data perimeter policies using SCPs, RCPs, and VPC endpoint policies to ensure only trusted identities access corporate data within set boundaries.

IAM341 | Code talk | Visualizing workforce identity: Graph-based analysis for access rights

Gain actionable insights by visualizing IAM Identity Center data in graph databases, helping detect excessive permissions and track resource access patterns across your organization.

IAM343 | Code talk | Scale beyond RBAC: Transform app access control using AVP and Cedar

Discover how to shift from RBAC to scalable PBAC using Cedar, centralizing authorization and enabling fine-grained, least-privilege access with minimal code changes.

IAM334 | Chalk talk | Multi-Region AWS identity patterns for regulated industries

Explore proven patterns for secure, compliant cross-region and partition access—including AWS GovCloud and European Sovereign Cloud—enabling centralized, least-privilege operations.

IAM331 | Chalk talk | Secure your lakehouse in AWS with fine-grained access control at scale

Master identity management and fine-grained access at scale for AWS data lakes, leveraging IAM Identity Center and Lake Formation to secure decentralized data environments.

GRC351 | Builders' session | Build a security posture leaderboard using generative AI

Build interactive security dashboards and generate executive-ready insights using GenAI and AWS analytics, boosting compliance and security visibility for all stakeholders.

Learn In a Hands-on Way

Hands-on AWS labs: build security, compliance, and development skills through real-world scenarios. Learn to configure tools, automate workflows, and apply AI-driven solutions to innovate securely, ensuring immediate business impact and staying ahead in cloud security and operations.

TDR342 | Code talk | Operationalizing Amazon Security Lake with analytics and generative AI

Code and visualize security analytics solutions atop Amazon Security Lake, using AWS services to operationalize data for advanced threat detection and incident response.

APS271 | Workshop | Threat modeling for builders

Apply threat modeling concepts through group exercises and expert guidance, learning to identify, assess, and mitigate security threats using STRIDE and real-world case studies.

IAM373 | Workshop | Identity without barriers: User-aware access for AWS analytics services

Get practical skills in configuring secure identity propagation across AWS services and accounts, mastering audit logging, and troubleshooting integration challenges.

APS471 | Workshop | Boost developer productivity with Amazon Q Developer

Experience hands-on how Amazon Q Developer and Bedrock automate coding, reviews, and documentation to speed up development, boost quality, and ensure compliance.

GRC373 | Workshop | Hands-on security monitoring: Implementing AWS observability controls

Build and automate real-time threat detection, dashboards, and response workflows using AWS observability tools to maintain security compliance hands-on.

IAM301 | Breakout session | How MongoDB uses Cedar policy language for fine-grained authorization

Learn how MongoDB revamped Atlas access management using Cedar and Amazon Verified Permissions for scalable, fine-grained, policy-based authorization.

Closing comments

For those attending AWS re:Inforce in person, I suggest prioritizing participation in workshops and chalk talks, as they will not be available online later. I trust you found this guide helpful and look forward to connecting with you at re:Inforce during the hallway track.