Hero guide: First-Time Attendee Guide

AWS re:Inforce 2025 offers more than 200 sessions focused on cloud security, with content spanning foundational topics and advanced technical deep-dives. For first-time attendees, it’s important to balance foundational learning with exposure to AWS culture and networking opportunities.

Image Alt

Chris Williams

DevRel Mgr

HashiCorp

As a 1st time attendee, you might be overwhelmed by all of the options. In this guide I'm going to (1) make some recommendations on what you should attend, and (2) give you some general tips for surviving the conference!

 

How to survive re:Inforce:

  • Prioritize Comfort and Health:
    • Wear the most comfortable shoes you can get away with. You’ll walk far more than you expect.
    • Stay hydrated! Bring a large refillable water bottle and drink more water than you think you need.
  • Layer your clothing - conference rooms can be cold due to strong air conditioning.
  • Manage Your Schedule & Energy
    • Plan your days, but be flexible. Review the conference schedule daily and be ready for last-minute changes.
    • Limit alcohol, especially at evening events.
    • Prioritize sleep.
  • Optimize Your Experience
    • Make your bag modular. Use a crossbody purse or small backpack so you can carry only what you need.
    • Bring a battery bank for your phone. You (or someone with you) WILL run out.
    • Network! The "Hallway Track" is the best way to make new connections  

"Must Attend" Essentials

These are the sessions that will set the tone for your re:Inforce experience. Paying attention at these will tell you which additional breakouts, coding sessions, labs, and workshops you'll want to dive further into (p.s. use the filter mechanism in the catalog to help!).

SEC200 | Keynote | Simplifying security at scale

The keynote sets the tone for the entire conference & tells you where AWS is focusing it's efforts (i.e. what sessions to pay close attention to).

SEC301 | Innovation talk | From possibility to production: A strong, flexible foundation for AI security

How AWS is going to be treating AI Security is going to be of paramount importance

SEC303 | Breakout session | Behind the shields: AWS and Anthropic's approach to secure AI

How AWS is going to be treating AI Security is going to be of paramount importance

IAM431 | Chalk talk | A deep dive on IAM policy evaluation

Master advanced IAM policy evaluation to troubleshoot access issues, secure resources, and confidently manage permissions—essential for every AWS security journey.

APS271 | Workshop | Threat modeling for builders

Everyone should do at least 1 workshop to see what they are all about. This looks like a fun one. If it's not your cup of tea pick another!

AI

It's 2025 - AI is being implemented *everywhere*. If you aren't learning how to properly secure your environments, LLMs, Agents, Agent permissions, etc...

IAM441 | Code talk | The right way to secure AI agents with code examples

Learn to secure AI agents with real AWS code examples—vital for anyone building or managing AI apps that need robust identity, consent, and fine-grained access.

GRC336 | Chalk talk | AI compliance by design: Building responsible solutions

Learn how to build AI solutions that meet new regulations, protect data, and ensure responsible, compliant innovation—crucial for anyone deploying AI on AWS.

APS353 | Builders' session | Red teaming your generative AI application at scale

This one just sounds fun!! Get hands-on with AI security by attacking and defending GenAI apps. Learn real-world LLM vulnerabilities and risk mitigation skills.

APS351 | Builders' session | Securing generative AI agents using AWS Well-Architected Framework

I love the Well Architected Framework. This is a good way to learn it and the GenAI Lens security best practices.

DevSecOps

This persona is near and dear to me  Knowing how the infrastructure, code, platform, and security are all interconnected is vital to the stability of any service. Now that we're adding AI into the mix we'll need to understand how THAT interacts with the other aspects.

GRC442 | Code talk | Beyond shift-left: Embedding controls in infrastructure pipelines

See how to automate compliance checks in your infrastructure code, ensuring security and speed—perfect for anyone building or securing regulated AWS environments.

IAM374 | Workshop | Integrating AWS IAM Access Analyzer into a CI/CD pipeline

Gain hands-on skills automating IAM policy checks in CI/CD pipelines—essential for building secure apps and catching permission issues before deployment.

GRC335 | Chalk talk | Strengthen security controls with AWS observability services

Learn to boost security by centralizing logs, building custom dashboards, and enabling real-time alerts—key skills for effective AWS threat detection and compliance.

NIS304 | Breakout session | Integrate Zero Trust into your cloud network

Discover how to build a modern, secure cloud network by integrating Zero Trust principles and AWS services—essential for evolving your security strategy.

Closing comments

TL;DR
1. Go to the keynote
2. Use the catalog filters to find your perfect sessions
3. Enjoy the hallway track! Meet new people and have fun
4. Come say hi if you see me