AWS launches data lake to help you spot your next big security threat

aws reinvent 2022
(Image credit: Future / Mike Moore)

Amazon Web Services (AWS) has revealed a new security-focused data lake service aimed at helping users get more out of their security information.

The new Amazon Security Lake service looks to centralize all of an organization’s security data from across a number of different sources, whether from the cloud or on-premise, in one place, in order to drill down precisely into security threats.

Announced at AWS re:Invent 2022, Amazon Security Lake is built on Amazon S3, and can be created, “in just a few clicks”, and will make it easy for security teams to automatically collect, combine, and analyze security data at petabyte scale.

Amazon Security Lake

“Security data is usually scattered across your environment from applications, firewalls and identity providers,” AWS CEO Adam Selipsky said during his opening re:Invent keynote.

“To uncover insights like coordinated malicious activity into your business, you have to collect and aggregate all of this data, make it accessible to all of the analytics tools that you use to support threat detection, investigation and incident response — and then keep the data pipelines updated and continuously do that as events evolve. What this adds up to is that what you really want is a tool that makes it easy to store, to analyze, to understand trends and to generate insights from security data.”

The launch could signify a major step forward for AWS’ security prowess, with the new platform bringing together a number of its existing data analytics and management services.

Once created, users will be able to bring in data from the likes of GuardDuty, CloudTrail and Lambda,  giving users the opportunity to run queries using Amazon Athena, OpenSearch and SageMaker.

Security Lake conforms to the AWS-headed Open Cybersecurity Schema Framework, meaning it can bring together data from a number of the world’s largest tech firms, as well as integrate up to 50 third-party partner analytics systems.

“Customers must be able to quickly detect and respond to security risks so they can take swift action to secure data and networks, but the data they need for analysis is often spread across multiple sources and stored in a variety of formats,” said Jon Ramsey, vice president for Security Services at AWS.

“Amazon Security Lake lets customers of all sizes securely set up a security data lake with just a few clicks to aggregate logs and event data from dozens of sources, normalize it to conform with the OCSF standard, and make it more broadly usable so customers can take action quickly using their security tools of choice.”

Amazon Security Lake is available now in preview across US East (N. Virginia), US East (Ohio), US West (Oregon), Asia Pacific (Sydney), Asia Pacific (Tokyo), Europe (Frankfurt), and Europe (Dublin), with availability in additional AWS Regions coming soon.

Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Read more
Concept art representing cybersecurity principles
“Everything starts with security" - AWS CISO on how making security simple can be the key to safety
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
AWS S3 feature abused by ransomware hackers to encrypt storage buckets
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
Padlock against circuit board/cybersecurity background
Preparing for the future of cybersecurity with next-gen SIEM
Cloud computing graphics.
Sovereign Cloud: redefining the future of secure digital innovation
Latest in Security
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
Latest in News
Pebble smartwatch countdown
Pebble confirms its smartwatch announcement is just hours away
Logo of YouTube Shorts
Is YouTube auto-playing Shorts when you open the app? Well, you’re not alone - here’s how to fix it
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
Nintendo Switch 2
Nintendo Switch 2 expected to have AI upscaling and I can't wait to finally play Tears of the Kingdom with upgraded graphics
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Intel Lunar Lake concept
Intel's Panther Lake processors won't arrive until Q1 2026 - corroborates previous delay rumors despite former Intel CEO's promise of 2025 launch