Security

AWS unveils cloud security IR service for a mere $7K a month

Tap into the infinite scalability... of pricing


Re:Invent Amazon Web Services has a new incident response service that combines automation and people to protect customers' AWS accounts - at a hefty price.

The minimum monthly cost starts at $7,000 and the pricing tiers increase from there, based on customers' AWS spending across all enrolled accounts. 

Here's the pricing overview per the cloud giant: 

The price for the new security service drew some scrutiny on social media, as Eric Hammond, a self-described AWS enthusiast, noted: "I started to look into the features … then I noticed the pricing. On to the next announcement."

The new security service was announced at AWS's annual re:Invent conference and it continues Amazon's ongoing push into cloud security, which is necessary to keep up with its fellow cloud giants. Google, of course, famously bought Mandiant, the preeminent threat-intel and incident response company, for $5.4 billion in 2022. And Microsoft, despite its repeated security failings, remains one of if not the largest security vendors in the world. 

We should note, however, that Redmond has come under fire for charging extra for its security add-ons.

The fresh-baked AWS Security Incident Response consists of three main parts.

First, it reads findings from Amazon GuardDuty, which is AWS' monitoring and threat detection tool, plus third-party threat intel products via AWS Security Hub, a centralized threat dashboard. 

It uses AI and ML to analyze these data points, we're told, and then identifies "high-priority incidents requiring immediate attention," according to Betty Zheng, a senior developer advocate at AWS who detailed the new service in a blog yesterday.

Security Incident Response also provides a centralized console from which customers can set security notification rules and permissions across AWS and third-party security products. 

This also centralizes communication, data transfer, video conference scheduling, and other remediation efforts between the various parties responding to the security incident. Plus, it can automate case history tracking and reporting. 

Finally, the third piece of the new service includes 24/7 access to the AWS Customer Incident Response Team (CIRT), which helps customers respond to and recover from digital intrusions.

AWS Security Incident Response also provides access to self-service investigation tools, should customers want to conduct IR operations on their own, or they can work with third-party security vendors on this piece as well, with the service also providing coordinated communications between teams.

The new service is now available in 12 AWS Regions globally: US East (Northern Virginia, Ohio), US West (Oregon), Asia Pacific (Seoul, Singapore, Sydney, Tokyo), Canada (Central), and Europe (Frankfurt, Ireland, London, Stockholm).

Will this be a case of: if AWS builds it, customers will pay? We will be keeping an eye on this new IR service to see. ®

Send us news
5 Comments

AWS unboxes quantum cat qubit kit called Ocelot

Sprinting after Microsoft and co, Amazon claims it too has a QC chip that's good at all-important error correction

Check out this free automated tool that hunts for exposed AWS secrets in public repos

You can find out if your GitHub codebase is leaking keys ... but so can miscreants

Hardware quality problems and server supply chain kinks slow Amazon’s $100 billion AI build

Reverses life extensions for some servers it now feels aren’t useful in the inferencing age

How nice that state-of-the-art LLMs reveal their reasoning ... for miscreants to exploit

Blueprints shared for jail-breaking models that expose their chain-of-thought process

US Cyber Command reportedly pauses cyberattacks on Russia

PLUS: Phishing suspects used fishing gear as alibi; Apple's 'Find My' can track PCs and Androids; and more

Qualcomm pledges 8 years of security updates for Android kit using its chips (YMMV)

Starting with Snapdragon 8 Elite and 'droid 15

Microsoft expands Copilot bug bounty targets, adds payouts for even moderate messes

Said bugs 'can have significant implications' – glad to hear that from Redmond

Drug-screening biz DISA took a year to disclose security breach affecting millions

If there's something nasty on your employment record, extortion scum could come calling

AWS vacates its board seat at European cloud crew CISPE

... weeks after US titan was outvoted by other members to let Microsoft join the Euro cloud trade association

C++ creator calls for help to defend programming language from 'serious attacks'

Bjarne Stroustrup wants standards body to respond to memory-safety push as Rust monsters lurk at the door

Bybit declares war on North Korea's Lazarus crime-ring to regain $1.5B stolen from wallet

Up to $140M in bounty rewards for return of Ethereum allegedly pilfered by hermit nation

Malware variants that target operational tech systems are very rare – but 2 were found last year

Fuxnet and FrostyGoop were both used in the Russia-Ukraine war