< ciso
brief />
Tag Banner

All news with #data security tag

113 articles

Designing Systems to Earn Customer Trust

🔒 Over years of building large-scale personalization and commerce systems, the author argues that compliance alone does not create customer trust. Real trust comes from ensuring customer intent is respected across distributed services, caches, pipelines and AI systems. The piece highlights five priorities: consistent customer intent, privacy as a distributed-systems problem, data minimization, designing for failure, and understanding AI's expanding trust boundary. Security leaders are urged to treat trust as an architectural and operational priority, with observability and metadata-driven controls.
read more →

AWS Security: July 2026 updates and guidance

🛡️ This recap highlights AWS Security blog posts, new capabilities, code samples, and guidance published in July 2026. Topics include AI agent security, data protection, network and infrastructure protections, threat detection enhancements, compliance guidance, and 21 security bulletins addressing vulnerabilities. Vendors and practitioners can use the code samples and workshops to implement recommended controls and apply patches promptly.
read more →

AWS Clean Rooms adds minimum aggregation for custom queries

🔒 AWS Clean Rooms now supports minimum aggregation thresholds for the Custom analysis rule type, preventing queries from returning results about individuals or small groups. Data providers can enforce a minimum identity count (for example, user IDs) per output row and set higher thresholds for specific columns. The update removes the need for pre-approved templates and manual code reviews, allowing ad-hoc custom SQL while specifying which columns may be filtered or joined to protect privacy.
read more →

AWS achieves NHS DSPT Standards Exceeded status

🔒 Amazon Web Services announces it has completed the 2025-26 NHS Data Security and Protection Toolkit (DSPT) assessment, achieving a status of Standards Exceeded. The DSPT measures performance against the National Data Guardian’s 10 data security standards for organizations accessing NHS patient data. AWS’s assessment status is valid until June 30, 2027, and the compliance certificate is available via the NHS England website and AWS Artifact. AWS reiterates that security and compliance are a shared responsibility between the provider and the customer.
read more →

AWS Clean Rooms adds SQL analysis log export

📥 AWS Clean Rooms now supports exporting privacy-enhanced analysis logs for SQL analyses to an S3 bucket, giving customers improved optimization and troubleshooting capabilities. Collaboration owners can grant members permission to export logs when creating a collaboration or via change requests for existing collaborations. After a query runs, privacy-enhanced Spark execution details can be exported to a chosen S3 path to help identify issues like data skew and reduce resolution time and costs.
read more →

Amazon OpenSearch Serverless raises collection limits

🔔 The next generation of Amazon OpenSearch Serverless now supports up to 10,000 collections within a single collection group, increased from the previous limit of 1,500. Collection groups let multiple collections share OpenSearch Compute Units (OCUs) even when encrypted with different AWS KMS keys. This change enables greater consolidation, improved compute utilization, and reduced per-collection costs for multi-tenant workloads. The higher limit applies automatically to new and existing nextgen collection groups in all available AWS Regions.
read more →

HIPAA Security Rule Technical Safeguards on AWS

🔒 This new guidance helps covered entities and business associates implement and evidence compliance with the HIPAA Security Rule Technical Safeguards (45 CFR §164.312) when building healthcare workloads on AWS. It explains the five standards and nine implementation specifications for access control, audit controls, integrity, authentication, and transmission security. The document also addresses proposed 2025 NPRM changes—such as mandatory encryption, MFA, and new network and configuration controls—and recommends treating all specifications as required for new workloads.
read more →

MSK Express adds native delivery to Amazon S3

🚀 Amazon MSK Express brokers now deliver Apache Kafka data directly to Amazon S3 general purpose buckets, providing a fully managed, auto-scaling capability for high-throughput data delivery. This feature handles scaling, retries, and backpressure for mission-critical workloads and can reduce ingestion and delivery costs by up to 60% versus self-managed connectors. MSK Express supports throughput up to 10 GB/s to S3 and eliminates the need to provision additional broker egress throughput, simplifying operations and lowering infrastructure costs.
read more →

Google Cloud Introduces Borderless Lakehouse

🧭 Today at Next Tokyo, Google Cloud announced enhancements to its borderless Lakehouse built on Apache Iceberg, enabling cross-cloud, zero-copy analytics and federated catalogs. The platform lets Gemini Enterprise and conversational agents query and act on live data across on-prem, AWS, Azure, and major SaaS systems without heavy ETL. New features include catalog federation (preview), Cross-Cloud Interconnects with predictable pricing, intelligent caching, and integration with Knowledge Catalog for unified governance and context.
read more →

AWS DataSync Enhanced Mode Adds HDFS, Azure Blob

🛠️ AWS DataSync Enhanced mode now supports agent-based transfers for HDFS, Microsoft Azure Blob Storage, and self-managed object storage, and agents can be deployed on Microsoft Hyper-V. Using a DataSync agent, customers can move data with Enhanced mode's parallelism, unlimited file counts, and detailed metrics. HDFS support includes multiple NameNode high-availability configurations and Transparent Data Encryption with Kerberos authentication for secure, compliant migrations.
read more →

AWS DataSync Enhanced Mode Adds EFS and FSx Support

🔄 AWS DataSync Enhanced mode now supports Amazon EFS and Amazon FSx for Lustre as source or destination locations. Enhanced mode provides parallel data processing, removes file count limits, and offers detailed transfer metrics to simplify large-scale migrations and high-performance workloads. This capability is available in all Regions where AWS DataSync is offered.
read more →

AWS Glue Data Quality adds Catalog anomaly detection

🛠️ AWS Glue Data Quality now supports anomaly detection for Catalog-based evaluations and can write evaluation results to AWS Glue Data Catalog (GDC) tables. These features apply to both ETL jobs and Catalog evaluations, enabling ML-driven time-series forecasting to surface unexpected changes in table statistics without manual thresholds. Evaluation outcomes, profiling metrics, and anomaly predictions (with confidence bounds) are persisted to GDC tables and can be queried via standard SQL. The capabilities are available in all AWS commercial regions and AWS GovCloud (US).
read more →

AWS Glue Data Quality adds Distribution Analyzer

📊 AWS announced a Distribution Analyzer for AWS Glue Data Quality that produces frequency distribution profiles for datasets. The feature generates histograms for numeric columns and value distributions for categorical, date, and boolean columns, with support for custom bin counts to tune granularity. Distribution statistics integrate with existing DQDL rulesets, are stored in Amazon S3, and are accessible via APIs for querying and visualization.
read more →

Organizations Delay Microsoft Copilot Over Data Risk

🔒 Two-thirds of organizations have delayed or cancelled Microsoft Copilot deployments due to fears the AI assistant could expose confidential SharePoint data. CoreView’s State of Microsoft 365 Security and Governance 2026 report (21 July) highlights confusion over Copilot's access and permissions and widespread concerns about data leakage. C-level executives are most likely to pause rollouts, and respondents link hesitation to prior Microsoft 365 security incidents and missing foundational controls.
read more →

Global IAM Data Governance Tags for BigQuery

🔒 This post introduces the preview of IAM data governance tags for BigQuery column-level security. Built on Google Cloud Resource Manager tags with purpose=DATA_GOVERNANCE, these tags are global, support hierarchical classification up to five levels, and are replicated for disaster recovery. The article explains creating tag keys/values, attaching tags to columns via JSON or SQL, and defining regional BigQuery data policies for masking or raw access. It highlights decoupled governance, regional policy enforcement, and layered security requirements.
read more →

Bridge SQL and Python with BigQuery DataFrames

🔗 This post introduces the %%bqsql IPython cell magic and the BigFrames library to bridge Python (pandas) and BigQuery SQL within notebooks. It explains setup steps for local or Colab environments, how to enable the BigQuery sandbox, and how to load the bigframes extension. The article walks through a USDA wheat data example showing chained workflows that alternate between Python and BigQuery SQL, plus tips for schema handling and visualization.
read more →

AWS Clean Rooms adds intermediate tables for SQL

🧩 AWS Clean Rooms now supports writing SQL query results to intermediate tables within a collaboration, enabling multi-step analytical workflows between partners. These intermediate tables allow reuse of complex joins and creation of shared ID mapping tables for downstream analyses, all within the collaboration’s privacy boundary. The feature helps reduce costs and improve performance for subsequent analyses such as reach, frequency, and attribution.
read more →

Professional athletes, wearables, and privacy risks

🔒 Wearables raise acute privacy concerns for professional athletes because biometric data can directly affect livelihoods. While such data can aid training and injury prevention, access by coaches, teams, or leagues risks misuse in discipline, contract negotiations, and betting markets. Experts warn commercialization could enable gamblers and teams to exploit sensitive signals like sleep or heart rate, and aging or injured players may be most vulnerable. Legal and ethical safeguards remain unresolved.
read more →

Amazon Bedrock Managed Knowledge Base Launch

🚀 Amazon Bedrock Managed Knowledge Base is now generally available as a fully managed retrieval-augmented generation (RAG) service. The offering removes the need to manage vector databases, data pipelines, and retrieval infrastructure by handling ingestion, storage optimization, and advanced retrieval. It supports six native connectors—S3, SharePoint, Confluence, Google Drive, OneDrive, and a web crawler—with automatic syncing and managed vector storage tuned for price-performance. Native integration with Amazon Bedrock AgentCore provides auto-generated permissions and observability for agent deployments.
read more →

Lake Formation adds S3 file access via table grants

🔐 AWS Lake Formation now allows reading and writing the underlying Amazon S3 data files for tables registered in the AWS Glue Data Catalog, unifying permissions for SQL and direct file access. It issues temporary, scoped credentials tied to Lake Formation table grants—SELECT for read and SUPER for read/write—and is supported in Amazon EMR 7.13+. You can use Spark or Trino with provided APIs or an open source plugin, and all activity is logged in AWS CloudTrail. This capability is available at no extra charge in supported Regions.
read more →