41 sessions
- Lightning talk400 - ExpertData ProtectionResilienceProvable SecurityThreat IntelligenceTuesday, Jun 175:00 p.m. Tuesday, Jun 17As attackers weaponize generative AI to scale phishing, deepfakes, and behavioral manipulation, defenders must fight back with smarter AI. This session breaks down real-world adversarial tactics and shows how Mimecast builds AI models to detect and prevent human-layer threats. Learn how we responsibly train models on behavioral data while ensuring transparency, fairness, and privacy. This presentation is brought to you by Mimecast, an AWS Partner.Session Type: Lightning talkLevel: 400 - ExpertTrack: Data Protection
- Chalk talk300 - AdvancedData ProtectionAWS ConfigAWS Secrets ManagerAWS Security HubMonday, Jun 1610:00 a.m. Monday, Jun 16Dive deep into architectural patterns for enterprise secrets management in cloud-native environments. We will dissect the implementation complexities of centralized versus decentralized secrets management and discuss the trade-offs between these patterns, including their impact on developer velocity, security, and operational overhead. Attendees will learn how to leverage AWS services to implement a flexible secrets management strategy and manage secrets lifecycle that balances the needs of developers and security teams. We'll also cover best practices for centralized compliance and auditing regardless of your chosen architecture.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Data Protection
- Chalk talk300 - AdvancedData ProtectionAWS ConfigAWS Secrets ManagerAWS Security HubTuesday, Jun 171:00 p.m. Tuesday, Jun 17Dive deep into architectural patterns for enterprise secrets management in cloud-native environments. We will dissect the implementation complexities of centralized versus decentralized secrets management and discuss the trade-offs between these patterns, including their impact on developer velocity, security, and operational overhead. Attendees will learn how to leverage AWS services to implement a flexible secrets management strategy and manage secrets lifecycle that balances the needs of developers and security teams. We'll also cover best practices for centralized compliance and auditing regardless of your chosen architecture.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Data Protection
- Breakout session200 - IntermediateData ProtectionGenerative AITuesday, Jun 171:00 p.m. Tuesday, Jun 17As organizations adopt generative AI, security teams must protect a fast-evolving attack surface. Services like Amazon Bedrock and SageMaker need to be scanned for potential risks like model tampering and data leakage, risks that traditional security doesn't see. AWS and CrowdStrike will show cloud practitioners how to secure the GenAI stack, from development to runtime. Learn how CrowdStrike Falcon Cloud Security delivers deep visibility into AI assets, scans models and packages for threats, and enforces protection at runtime. Whether you're securing LLMs, AI services, or custom pipelines, you’ll leave with practical guidance to build and scale GenAI securely on AWS. This presentation is brought to you by CrowdStrike, an AWS Partner.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Data Protection
- Lightning talk200 - IntermediateData ProtectionResilienceThreat IntelligenceCloud Security SpecialistData EngineerTuesday, Jun 179:00 a.m. Tuesday, Jun 17Bad actors don’t break in; they log in. Today, 86% of data breaches involve stolen credentials. When attackers have legitimate credentials, posture management (DSPM / CSPM) isn’t enough. How do you stop a malicious insider or a bad actor with stolen credentials from exfiltrating AWS data? In this talk, learn how data-centric threat detection can stop breaches that bypass posture controls, including ransomware, phishing, and malicious insiders. Learn how Varonis safeguards against identity-based attacks, detects active attacks with user entity behavior analytics (UEBA), provides a full forensics log for investigations and compliance, and augments AWS GuardDuty with data-centric threat detection. This presentation is brought to you by Varonis, an AWS Partner.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Data Protection
- Builders' session400 - ExpertData ProtectionCryptography and Post-QuantumCloud Security SpecialistData EngineerSolution / Systems ArchitectAWS CloudHSMAWS Key Management Service (AWS KMS)Cross-Industry Solutions10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Gain hands-on experience implementing strong cryptographic controls using AWS CloudHSM. Learn to deploy TLS offload with Nginx, integrate Windows code signing, and create custom key stores. Explore monitoring cryptographic key usage within FIPS 140-3 level 3 hardware security modules, leveraging the latest high-performance hsm2m.medium HSM types. This session shows how these advancements help you strengthen your security posture, meet stringent compliance requirements, simplify operational management, and scale your cryptographic operations to support growing workloads - all while maintaining the performance your applications demand. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 400 - ExpertTrack: Data Protection
- Lightning talk100 - FoundationalData ProtectionGenerative AIResilienceCulture of SecurityDevOps EngineerIT ExecutiveSolution / Systems ArchitectAmazon DynamoDBAmazon Elastic Compute Cloud (Amazon EC2)Amazon Simple Storage Service (Amazon S3)Cross-Industry SolutionsFinancial ServicesMedia & EntertainmentTuesday, Jun 173:00 p.m. Tuesday, Jun 17Join Commvault CSO Bill O’Connell as he shares invaluable lessons learned throughout his career as a security leader. Drawing from his extensive experience, Bill offers perspective on the cybersecurity challenges organizations face and why some of the most critical steps in building an effective resilience strategy have often been overlooked. Gain actionable insights and practical guidance from a seasoned expert who understands what you are facing and walk away ready to improve your organization’s readiness and resilience in the face of cyber threats. This presentation is brought to you by Commvault, an AWS Partner.Session Type: Lightning talkLevel: 100 - FoundationalTrack: Data Protection
- Lightning talk300 - AdvancedData ProtectionResilienceCloud Security SpecialistIT AdministratorIT ExecutiveAWS BackupAWS Elastic Disaster RecoveryAWS Resilience HubFinancial ServicesGovernmentSoftware & InternetWednesday, Jun 182:00 p.m. Wednesday, Jun 18Data protection and resilience are critical to business success, helping to keep workflows running and allow business recovery from data loss events such as unplanned outages, natural disasters, and ransomware. Join this session to dive deep on how AWS storage offers organizations defense-in-depth data protection and resilience for application data across recovery point and time objectives, helping to mitigate risks with immutable solutions, restore testing, policy-based access controls, encryption, and auditing and reporting.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Data Protection
- Workshop400 - ExpertData ProtectionAWS BackupTuesday, Jun 1712:00 p.m. Tuesday, Jun 17Ransomware and malware can disrupt business applications. In this expert-level workshop, attendees will learn how to apply AWS Backup locking mechanisms, logically air-gapped vaults, and restore testing to help strengthen their cyber recovery posture. Experience hands-on configuration of air-gapped, immutable vaults and automated recovery point testing to meet your enterprise's objectives. Explore how these features can be combined to build a comprehensive, recovery-focused data protection strategy to withstand evolving cyber threats. You must bring your laptop to participate.Session Type: WorkshopLevel: 400 - ExpertTrack: Data Protection
- Workshop400 - ExpertData ProtectionAWS Backup9:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Ransomware and malware can disrupt business applications. In this expert-level workshop, attendees will learn how to apply AWS Backup locking mechanisms, logically air-gapped vaults, and restore testing to help strengthen their cyber recovery posture. Experience hands-on configuration of air-gapped, immutable vaults and automated recovery point testing to meet your enterprise's objectives. Explore how these features can be combined to build a comprehensive, recovery-focused data protection strategy to withstand evolving cyber threats. You must bring your laptop to participate.Session Type: WorkshopLevel: 400 - ExpertTrack: Data Protection
- Workshop300 - AdvancedData ProtectionGenerative AIAmazon BedrockAmazon Verified PermissionsAWS Key Management Service (AWS KMS)1:00 p.m. Monday, Jun 16Monday, Jun 16Master the art of identifying and mitigating prompt injection vulnerabilities in generative AI systems through this hands-on workshop. Using Amazon Bedrock, participants will explore both offensive and defensive prompt engineering techniques to understand the security implications of large language models in production environments. In this session you will understand how prompt injection attacks work, complete an interactive 'capture the flag' style challenge attempting to exploit a simulated AI environment, and learn to implement defensive controls using Amazon Bedrock Guardrails. You must bring your laptop to participate.Session Type: WorkshopLevel: 300 - AdvancedTrack: Data Protection
- Code talk400 - ExpertData ProtectionGenerative AIProvable SecurityCryptography and Post-QuantumData ScientistAmazon Elastic Compute Cloud (Amazon EC2)8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18Highly sensitive workloads often rely on cryptographic proof about the code, config, and other aspects of the execution environment before unsealing code for data to be processed. In this code talk we will see examples of cryptographic attestation using AWS Nitro Enclaves, Nitro Trusted Platform Module (NitroTPM), and Amazon EC2 instance identity documents. We will also visit common scenarios where this is useful in multi-party computation setups for data analytics and generative AI.Session Type: Code talkLevel: 400 - ExpertTrack: Data Protection
- Code talk300 - AdvancedData ProtectionAWS CloudFormationAWS Key Management Service (AWS KMS)AWS Private Certificate AuthorityTuesday, Jun 173:00 p.m. Tuesday, Jun 17Modern Kubernetes applications require robust encryption for securing data between containers and external clients. In this session, learn how to implement comprehensive end-to-end encryption in transit for Kubernetes applications using AWS Private Certificate Authority and open-source tools. Live demonstrations will enable you to discover automated certificate lifecycle management patterns, helping secure external traffic to ingress controllers and internal pod-to-pod communication. Explore real-world architectures that leverage AWS services to automate building PKI infrastructure that enhances the Kubernetes application's security posture while maintaining operational excellence.Session Type: Code talkLevel: 300 - AdvancedTrack: Data Protection
- Workshop400 - ExpertData ProtectionDevSecOpsCryptography and Post-QuantumMigrationAcademic / ResearcherCloud Security SpecialistDeveloper / EngineerAWS Key Management Service (AWS KMS)AWS SDK for JavaAWS Transfer FamilyFinancial ServicesGovernmentHealthcare & Life SciencesWednesday, Jun 1812:00 p.m. Wednesday, Jun 18This workshop provides a practical exploration of post-quantum cryptography, comparing its performance against classical algorithms and demonstrating real-world implementation using AWS services. Participants will learn to establish quantum-safe tunnels using AWS KMS and AWS SDK for Java v2, implementing hybrid post-quantum TLS for secure data transfer. The session covers critical aspects including CPU and bandwidth performance metrics of post-quantum key exchange algorithms, modifications to TLS handshake protocols, and integration with AWS Transfer Family. Hands-on demonstrations will illustrate how to protect sensitive communications against both current and future quantum computing threats through hybrid classical/quantum-resistant approaches. You must bring your laptop to participate.Session Type: WorkshopLevel: 400 - ExpertTrack: Data Protection
- Chalk talk300 - AdvancedData ProtectionGenerative AIZero TrustBusiness ExecutiveIT ExecutiveIT Professional / Technical ManagerAmazon BedrockAmazon SageMakerCross-Industry SolutionsTuesday, Jun 1712:00 p.m. Tuesday, Jun 17Don't let the perceived complexity of responsible AI keep you from deploying generative AI applications on AWS. In this chalk talk, we will present a framework for breaking down AI safety and security risks, introduce AWS best practices for keeping enterprise data secure in generative AI applications using zero trust principles, and mitigate safety risks using technologies such as Bedrock Guardrails. Discover as a group with fellow security leaders how to identify safety and security risks relevant to your workload, implement appropriate mitigation strategies, and measure efficacy over time.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Data Protection
- Breakout session300 - AdvancedData ProtectionCryptography and Post-QuantumMigrationCloud Security SpecialistIT ExecutiveSolution / Systems ArchitectAWS Certificate Manager (ACM)AWS Key Management Service (AWS KMS)AWS Private Certificate AuthorityCross-Industry SolutionsFinancial ServicesGovernmentTuesday, Jun 174:00 p.m. Tuesday, Jun 17Explore Fannie Mae's transformation of their Public Key Infrastructure (PKI) from a legacy system to a cloud-native solution on AWS. This session details their phased migration strategy, addressing challenges like decentralized trust store updates and securing buy-in from application teams. Learn how Fannie Mae overcame migration hurdles, including legacy dependencies and compliance requirements, to achieve 100% adoption while maintaining security and reducing certificate-related overhead. Gain insights into cost optimization, risk mitigation, and architectural best practices for enterprise-scale certificate management in the cloud. This presentation offers actionable strategies for organizations undertaking similar PKI modernization efforts. Finally, we will share the latest in enterprise-scale certificate management in the cloud.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Data Protection
- Chalk talk500 - DistinguishedData ProtectionCryptography and Post-QuantumAcademic / ResearcherCloud Security Specialist10:00 a.m. Wednesday, Jun 18Wednesday, Jun 18The world is moving to new Post-Quantum Cryptography (PQC) over the next 5-10 years. Learn about the quantum algorithm known as Shor's and how it breaks the traditional public key algorithms we use today. This talk will show how the quantum period-finding algorithm is used in Shor's algorithm to break Elliptic Curve Cryptography and RSA. It will also outline the steps AWS and the broader cryptographic community have taken to avoid the risk a large-scale quantum computer poses to information systems we use today. The session will conclude with an outline of AWS's PQC migration strategy and how you can make your applications and services quantum-resistant.Session Type: Chalk talkLevel: 500 - DistinguishedTrack: Data Protection
- Lightning talk300 - AdvancedData ProtectionAutomationCryptography and Post-QuantumAdvisor / ConsultantCloud Security SpecialistSolution / Systems ArchitectAWS Key Management Service (AWS KMS)Cross-Industry SolutionsFinancial ServicesSoftware & Internet12:00 p.m. Monday, Jun 16Monday, Jun 16As organizations increasingly demand greater control over their sensitive data (such as PII and user-generated content), Atlassian's elegant solution combines AWS KMS and client-side encryption via AWS Encryption SDK to deliver a robust data protection strategy that centers around customer-managed keys. The session unveils the architectural decisions, implementation challenges, and best practices that enabled Atlassian to meet growing customer demands for control. Ideal for cloud architects and security professionals exploring Bring Your Own Key (BYOK) solutions for their SaaS platforms.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Data Protection
- Breakout session300 - AdvancedData ProtectionCryptography and Post-QuantumMigrationAmazon DynamoDBAmazon Simple Storage Service (Amazon S3)AWS Payment Cryptography1:00 p.m. Monday, Jun 16Monday, Jun 16Join Mercado Libre's engineering team as they reveal how Latin America's leading e-commerce platform revolutionized its payment processing using AWS Payment Cryptography. Discover their strategic journey from physical HSMs to cloud-native security, including proof-of-concept methodology and production deployment patterns. Learn how they successfully migrated massive transaction volumes while maintaining stringent security standards. This session showcases their achievement in eliminating hardware constraints, reducing infrastructure costs, and scaling to process millions of transactions with sub-10ms latency, setting new benchmarks in payment processing efficiency.Session Type: Breakout sessionLevel: 300 - AdvancedTrack: Data Protection
- Lightning talk300 - AdvancedData ProtectionCulture of SecurityPrivacySupply Chain SecurityCloud Security SpecialistDeveloper / EngineerSolution / Systems ArchitectAmazon Elastic Compute Cloud (Amazon EC2)AWS Key Management Service (AWS KMS)Cross-Industry SolutionsFinancial ServicesGovernmentWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Monzo Bank deploys security-critical applications requiring a high level of assurance around code integrity, system hardening, and limited attack surface. They achieved this using reproducible builds and the cryptographic attestation and isolated compute environment provided by AWS Nitro Enclaves. In this talk, we'll describe the challenges they overcame in building and deploying production workloads using this approach and share what they learned along the way.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Data Protection
- Lightning talk100 - FoundationalData ProtectionGenerative AICulture of SecurityProvable SecurityCloud Security SpecialistIT ExecutiveSolution / Systems ArchitectAmazon BedrockAmazon Simple Storage Service (Amazon S3)Amazon Simple Storage Service Glacier (Amazon S3 Glacier)Financial ServicesRetail & Consumer GoodsTravel & Hospitality6:00 p.m. Monday, Jun 16Monday, Jun 16As a security leader you’re being asked to find ways to securely enable your business to use data to drive innovation. Yet, data security is historically the least mature domain for enterprise organizations. In this session, learn how forward-thinking CISOs are leveraging AI to transform their data security strategy so that it evolves into the most mature security program and the driving force for innovation and business growth. This presentation is brought to you by Cyera, an AWS Partner.Session Type: Lightning talkLevel: 100 - FoundationalTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionGenerative AIAutomationCryptography and Post-QuantumCloud Security SpecialistData EngineerDevOps EngineerAmazon AthenaAWS Key Management Service (AWS KMS)Amazon Q in QuickSightCross-Industry SolutionsFinancial ServicesGovernment1:00 p.m. Monday, Jun 16Monday, Jun 16Discover practical methods for managing encryption keys and access policies across multiple organizational accounts through natural language queries. This session demonstrates how to gain data protection insights by combining serverless functions with audit logs and analytics tools to create interactive dashboards. Learn to visualize enterprise-wide encryption key usage and answer critical questions about key utilization and resource protection. Walk away with implementable solutions for improving encryption key visibility and control across your accounts. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- Lightning talk200 - IntermediateData ProtectionCulture of SecurityDevSecOpsCloud Security SpecialistIT ExecutiveSolution / Systems ArchitectAmazon Simple Storage Service (Amazon S3)AWS LambdaMedia & EntertainmentSoftware & InternetWednesday, Jun 181:00 p.m. Wednesday, Jun 18Privacy compliance workflows often start messy - manual, fragmented, and hard to scale. In this session, I’ll walk through ways to move your team toward managed, cloud-native solutions using AWS services. We’ll explore how to handle data subject requests securely and efficiently with event-driven design, identity checks, and auditability in mind. You’ll leave with a clear blueprint, practical lessons, and a path to gradually automate your privacy compliance in AWS - no matter where you're starting.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Data Protection
- Breakout session200 - IntermediateData ProtectionBusiness ExecutiveIT ExecutiveSolution / Systems ArchitectEnergy & UtilitiesFinancial ServicesGovernment8:00 a.m. Wednesday, Jun 18Wednesday, Jun 18In an era of evolving data protection regulations and digital sovereignty requirements, organizations face increasing complexity maintaining compliance while leveraging cloud capabilities. This breakout session explores practical architectural approaches for meeting sovereignty requirements on AWS, with a focus on European and global regulatory frameworks. We will examine key architectural patterns that enable data residency control, operational transparency, and sovereign workload isolation. The session covers the AWS Sovereignty Pledge, including sovereign design best practices, as well as the upcoming AWS European Sovereign Cloud.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Data Protection
- Lightning talk200 - IntermediateData ProtectionCryptography and Post-QuantumTuesday, Jun 171:00 p.m. Tuesday, Jun 17Discover how AWS simplifies post-quantum cryptography (PQC) implementation to protect your data from future quantum computing threats. Join AWS's PQC team for a comprehensive overview as we demystify PQC, presenting it as a natural evolution of existing security practices. Learn about AWS's quantum-safe strategy, explore real customer implementations, and understand emerging PQC standards and timelines. Security practitioners will gain practical insights to strengthen their organization's quantum-ready security posture and leave with clear, actionable next steps for their PQC journey.Session Type: Lightning talkLevel: 200 - IntermediateTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionGenerative AIZero TrustThreat IntelligenceCloud Security SpecialistDeveloper / EngineerSolution / Systems ArchitectAmazon AthenaAmazon Simple Storage Service (Amazon S3)AWS WAFFinancial ServicesGamesHealthcare & Life SciencesTuesday, Jun 1712:00 p.m. Tuesday, Jun 17Learn to protect your intellectual property from unrestricted access by generative AI bots that can overwhelm servers and evade traditional detection methods. This session guides you through implementing AWS WAF rules to identify and manage AI bot traffic, even when they change IPs and signatures. Discover practical strategies to safeguard your datasets and maintain control over your content while running workloads on AWS. Leave with actionable knowledge to enhance your security posture against AI bot scraping. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- MeetupData ProtectionWednesday, Jun 1812:00 p.m. Wednesday, Jun 18This meetup focuses on building comprehensive ransomware resilience strategies. Discuss evolving attack vectors and explore multi-layered defense approaches, focusing on storage and data resilience. Share insights on creating and testing incident response playbooks, implementing robust backup and recovery solutions, and maintaining business continuity. Delve into real-world scenarios, regulatory considerations, and emerging strategies shaping the future of ransomware defense and organizational resilience.Session Type: MeetupTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionAmazon MacieAWS Glue DataBrewAWS Lake FormationTuesday, Jun 171:00 p.m. Tuesday, Jun 17Master advanced data protection techniques for modern data lakes. Learn to implement automated sensitive data discovery, dynamic data masking, and granular redaction controls using AWS services. We will get hands-on to architect real-time PII detection pipelines, implement column-level encryption, and deploy automated data transformation workflows. Improve your data security posture as you walk away with production-ready architectures for protecting sensitive data throughout its lifecycle, from ingestion through analytics - all while maintaining data utility and regulatory compliance. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionAmazon MacieAWS Glue DataBrewAWS Lake FormationWednesday, Jun 184:00 p.m. Wednesday, Jun 18Master advanced data protection techniques for modern data lakes. Learn to implement automated sensitive data discovery, dynamic data masking, and granular redaction controls using AWS services. We will get hands-on to architect real-time PII detection pipelines, implement column-level encryption, and deploy automated data transformation workflows. Improve your data security posture as you walk away with production-ready architectures for protecting sensitive data throughout its lifecycle, from ingestion through analytics - all while maintaining data utility and regulatory compliance. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionWell-Architected FrameworkAutomationDevSecOpsCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAmazon EventBridgeAWS Key Management Service (AWS KMS)AWS Secrets ManagerCross-Industry SolutionsFinancial ServicesGovernment2:00 p.m. Monday, Jun 16Monday, Jun 16Ever wondered how tech giants protect their crown jewels in the cloud? Attend this cutting-edge session to unlock the vault of industry-leading practices using AWS Secrets Manager's latest features. Journey through real-world scenarios mastering automated rotation, encryption at rest, access control, replication, intelligent caching and security incidents. You'll craft a robust secrets fortress using AWS Secrets Manager, AWS KMS, AWS Lambda, Amazon EventBridge, and AWS Config that scales with your applications. Transform your security posture and reduce operational overhead while meeting enterprise compliance requirements in the cloud age. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionWell-Architected FrameworkAutomationDevSecOpsCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAmazon EventBridgeAWS Key Management Service (AWS KMS)AWS Secrets ManagerCross-Industry SolutionsFinancial ServicesGovernmentWednesday, Jun 1811:00 a.m. Wednesday, Jun 18Ever wondered how tech giants protect their crown jewels in the cloud? Attend this cutting-edge session to unlock the vault of industry-leading practices using AWS Secrets Manager's latest features. Journey through real-world scenarios mastering automated rotation, encryption at rest, access control, replication, intelligent caching and security incidents. You'll craft a robust secrets fortress using AWS Secrets Manager, AWS KMS, AWS Lambda, Amazon EventBridge, and AWS Config that scales with your applications. Transform your security posture and reduce operational overhead while meeting enterprise compliance requirements in the cloud age. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- MeetupData ProtectionTuesday, Jun 171:00 p.m. Tuesday, Jun 17This meetup explores the evolving landscape of secrets management in modern, distributed environments. Discuss strategies for implementing managed secrets, tackling multi-cloud and hybrid challenges, and integrating with DevOps workflows. Share experiences with tools, cloud-native approaches, and best practices for the entire secrets lifecycle - from creation and rotation to auditing and clean up. Explore how to maintain security and compliance while enabling development speed in complex infrastructures.Session Type: MeetupTrack: Data Protection
- Chalk talk300 - AdvancedData ProtectionWell-Architected FrameworkAutomationDevSecOpsZero TrustCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAWS Identity and Access Management (IAM)AWS Private Certificate AuthorityCross-Industry SolutionsGovernmentSoftware & InternetTuesday, Jun 174:00 p.m. Tuesday, Jun 17Discover how innovative ISVs are elevating security posture for their cloud-native and hybrid customers by preventing privileged access to networks and eliminating long-lived user credentials. Learn about Zero Trust principles and the benefits of short-lived credentials for accessing shared resources. Explore practical approaches to overcoming PKI infrastructure challenges while balancing security and operational needs. Through real-world examples, understand how to architect products that protect customers, simplify compliance, and scale securely in regulated industries. Gain actionable insights to reduce risk and enhance security as you build and grow your cloud solutions.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Data Protection
- Chalk talk300 - AdvancedData ProtectionWell-Architected FrameworkAutomationDevSecOpsZero TrustCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAWS Identity and Access Management (IAM)AWS Private Certificate AuthorityCross-Industry SolutionsGovernmentSoftware & Internet11:00 a.m. Monday, Jun 16Monday, Jun 16Discover how innovative ISVs are elevating security posture for their cloud-native and hybrid customers by preventing privileged access to networks and eliminating long-lived user credentials. Learn about Zero Trust principles and the benefits of short-lived credentials for accessing shared resources. Explore practical approaches to overcoming PKI infrastructure challenges while balancing security and operational needs. Through real-world examples, understand how to architect products that protect customers, simplify compliance, and scale securely in regulated industries. Gain actionable insights to reduce risk and enhance security as you build and grow your cloud solutions.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Data Protection
- Builders' session300 - AdvancedData ProtectionCloud Security SpecialistData EngineerSolution / Systems ArchitectAmazon SageMakerAWS GlueAWS Lake FormationCross-Industry Solutions11:00 a.m. Monday, Jun 16Monday, Jun 16Data lakes require comprehensive security controls throughout their lifecycle, particularly for AI/ML workloads. This session provides hands-on experience implementing end-to-end security for AWS data lake architectures. Learn to configure secure data ingestion patterns, implement automated classification, and establish dynamic access controls. Through practical exercises, you will build automated compliance monitoring workflows, learn best practices for securing AI/ML pipelines, and discover how to implement data lake security controls that enable innovation while maintaining appropriate governance. You must bring your laptop to participate.Session Type: Builders' sessionLevel: 300 - AdvancedTrack: Data Protection
- Chalk talk300 - AdvancedData ProtectionPrivacyProvable SecurityCryptography and Post-QuantumCloud Security SpecialistDeveloper / EngineerSolution / Systems ArchitectAmazon API GatewayAmazon DynamoDBAmazon Elastic Compute Cloud (Amazon EC2)Financial ServicesGovernmentSoftware & Internet2:00 p.m. Monday, Jun 16Monday, Jun 16Financial institutions are faced with protecting sensitive data like customer PII, payment flows, and digital assets; requiring unique defense-in-depth capabilities. This chalk talk explains how to leverage AWS Nitro Enclaves to enhance application security during sensitive data processing and encryption. We'll highlight practical use cases from payment and digital asset customers where the features of AWS Nitro Enclaves provide an additional layer of performance and protection.Session Type: Chalk talkLevel: 300 - AdvancedTrack: Data Protection
- Lightning talk300 - AdvancedData ProtectionCulture of SecurityPrivacyZero TrustCloud Security SpecialistDevOps EngineerSolution / Systems ArchitectAWS Control TowerAWS IAM Identity CenterAWS OrganizationsFinancial ServicesRetail & Consumer Goods12:00 p.m. Monday, Jun 16Monday, Jun 16We will explore the implementation of Resource Control Policies (RCPs) to enhance data perimeters in multi-account AWS environments. RCPs enable organizations to centrally implement resource access controls across multiple accounts, ensuring that only trusted identities can access sensitive data. By effectively implementing RCPs, organizations can mitigate risks such as service confusion and maintain secure and compliant configurations. This session will provide practical insights into designing and implementing RCPs to strengthen data security in complex AWS infrastructures.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Data Protection
- Breakout session200 - IntermediateData ProtectionGenerative AICloud Security SpecialistDevOps EngineerAmazon BedrockAmazon Virtual Private Cloud (Amazon VPC)AWS Key Management Service (AWS KMS)Financial ServicesHealthcare & Life SciencesWednesday, Jun 1811:00 a.m. Wednesday, Jun 18How can organizations empower teams with generative AI capabilities while maintaining rigorous data security standards responsibly? Veradigm initially hesitated to adopt generative AI due to data privacy, security, and regulatory compliance concerns. Join Veradigm's Principal Developer for Internal AI Solutions to discover how they implemented practical security measures to build and deploy a compliant generative AI assistant using Amazon Bedrock that enhanced their team capabilities while strengthening their security posture. Learn about essential security controls, architectural decisions, and valuable lessons learned from successfully implementing AI for employees operating in a highly regulated environment.Session Type: Breakout sessionLevel: 200 - IntermediateTrack: Data Protection
- Code talk400 - ExpertData ProtectionCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAWS Key Management Service (AWS KMS)AWS Private Certificate AuthorityAWS Secrets ManagerCross-Industry Solutions11:00 a.m. Monday, Jun 16Monday, Jun 16This session delves into achieving data observability while optimizing cost and security for AWS data protection services such as AWS KMS, AWS Private CA, and AWS Secrets Manager. Discover how to leverage AWS services for comprehensive monitoring, alerting, and cost optimization, ensuring your data remains secure and available. We will demonstrate a solution that aggregates AWS CloudTrail logs, Amazon CloudWatch events, and more to create observability dashboards for security teams. Learn practical preventative controls to ensure service usage aligns with security requirements. By the end of this session, you'll have the skills to proactively detect unauthorized access, failed rotations, and misconfigurations.Session Type: Code talkLevel: 400 - ExpertTrack: Data Protection
- Code talk400 - ExpertData ProtectionGenerative AIDevSecOpsCryptography and Post-QuantumCloud Security SpecialistIT Professional / Technical ManagerSolution / Systems ArchitectAWS Key Management Service (AWS KMS)AWS Private Certificate AuthorityAWS Secrets ManagerCross-Industry SolutionsFinancial ServicesGovernmentWednesday, Jun 181:00 p.m. Wednesday, Jun 18This session delves into achieving data observability while optimizing cost and security for AWS data protection services such as AWS KMS, AWS Private CA, and AWS Secrets Manager. Discover how to leverage AWS services for comprehensive monitoring, alerting, and cost optimization, ensuring your data remains secure and available. We will demonstrate a solution that aggregates AWS CloudTrail logs, Amazon CloudWatch events, and more to create observability dashboards for security teams. Learn practical preventative controls to ensure service usage aligns with security requirements. By the end of this session, you'll have the skills to proactively detect unauthorized access, failed rotations, and misconfigurations.Session Type: Code talkLevel: 400 - ExpertTrack: Data Protection
- Lightning talk300 - AdvancedData ProtectionTuesday, Jun 179:00 a.m. Tuesday, Jun 17Cloud software is essential to running modern enterprises—but most SaaS tools don’t offer native backup and restore capabilities for user data. This session will help enterprise security and IT teams understand where their resilience strategy may fall short and what questions to ask when assessing critical SaaS tools like Jira, Confluence, and GitHub. We’ll explain why this gap exists, the risks it introduces, and how to mitigate them with purpose-built backup solutions. This presentation is brought to you by Rewind, an AWS Partner.Session Type: Lightning talkLevel: 300 - AdvancedTrack: Data Protection