Security

AWS unveils cloud security IR service for a mere $7K a month

Tap into the infinite scalability... of pricing


Re:Invent Amazon Web Services has a new incident response service that combines automation and people to protect customers' AWS accounts - at a hefty price.

The minimum monthly cost starts at $7,000 and the pricing tiers increase from there, based on customers' AWS spending across all enrolled accounts. 

Here's the pricing overview per the cloud giant: 

The price for the new security service drew some scrutiny on social media, as Eric Hammond, a self-described AWS enthusiast, noted: "I started to look into the features … then I noticed the pricing. On to the next announcement."

The new security service was announced at AWS's annual re:Invent conference and it continues Amazon's ongoing push into cloud security, which is necessary to keep up with its fellow cloud giants. Google, of course, famously bought Mandiant, the preeminent threat-intel and incident response company, for $5.4 billion in 2022. And Microsoft, despite its repeated security failings, remains one of if not the largest security vendors in the world. 

We should note, however, that Redmond has come under fire for charging extra for its security add-ons.

The fresh-baked AWS Security Incident Response consists of three main parts.

First, it reads findings from Amazon GuardDuty, which is AWS' monitoring and threat detection tool, plus third-party threat intel products via AWS Security Hub, a centralized threat dashboard. 

It uses AI and ML to analyze these data points, we're told, and then identifies "high-priority incidents requiring immediate attention," according to Betty Zheng, a senior developer advocate at AWS who detailed the new service in a blog yesterday.

Security Incident Response also provides a centralized console from which customers can set security notification rules and permissions across AWS and third-party security products. 

This also centralizes communication, data transfer, video conference scheduling, and other remediation efforts between the various parties responding to the security incident. Plus, it can automate case history tracking and reporting. 

Finally, the third piece of the new service includes 24/7 access to the AWS Customer Incident Response Team (CIRT), which helps customers respond to and recover from digital intrusions.

AWS Security Incident Response also provides access to self-service investigation tools, should customers want to conduct IR operations on their own, or they can work with third-party security vendors on this piece as well, with the service also providing coordinated communications between teams.

The new service is now available in 12 AWS Regions globally: US East (Northern Virginia, Ohio), US West (Oregon), Asia Pacific (Seoul, Singapore, Sydney, Tokyo), Canada (Central), and Europe (Frankfurt, Ireland, London, Stockholm).

Will this be a case of: if AWS builds it, customers will pay? We will be keeping an eye on this new IR service to see. ®

Send us news
5 Comments

Crooks stole AWS credentials from misconfigured sites then kept them in open S3 bucket

ShinyHunters-linked heist thought to have been ongoing since March

AI and analytics converge in new generation Amazon SageMaker

Calling everything SageMaker is confusing – but a new name would have been worse says AWS

Amazon promises 4x faster AI silicon in 2025, turns Trainium2 loose on the net

Tens of thousands of AWS’ Trn2 instances to fuel Anthropic's next-gen models

AWS now renting monster HPE servers, even in clusters of 7,680-vCPUs and 128TB

Heir to Superdome goes cloudy for those who run large in-memory databases and apps that need them

Ransomware scum blow holes in Cleo software patches, Cl0p (sort of) claims responsibility

But can you really take crims at their word?

BlackBerry offloads Cylance's endpoint security products to Arctic Wolf

Fresh attempt to mix the perfect cocktail of IoT and Infosec

US reportedly mulls TP-Link router ban over national security risk

It could end up like Huawei -Trump's gonna get ya, get ya, get ya

Taiwan in talks to tap Amazon's Project Kuiper space broadband

In case of submarine cable failure, call Jeff Bezos

Microsoft won't let customers opt out of passkey push

Enrollment invitations will continue until security improves

AWS says AI could disrupt everything – and hopes it will do just that to Windows

Cloud colossus reckons it can clarify hallucinations, get your apps off Microsoft's OS at pleasing speed

How Androxgh0st rose from Mozi's ashes to become 'most prevalent malware'

Botnet's operators 'driven by similar interests as that of the Chinese state'

Australia moves to drop some cryptography by 2030 – before quantum carves it up

The likes of SHA-256, RSA, ECDSA and ECDH won't be welcome in just five years