Source:


By Nicholas Fearn

An AWS tech stack can aid business growth and facilitate efficient operations, but misconfigurations have become all too common and stall this progress

Amazon Web Services (AWS) has become the lifeblood of millions of modern businesses, both big and small. But while this popular cloud platform enables them to manage and scale their operations with impressive speed, simplicity and affordability, it also represents a significant security and privacy risk if mismanaged by users.

An insecure or improperly configured AWS tech stack provides a gateway for cyber criminals to enter corporate systems and sensitive files. The biggest example of this occurred in 2019, when an ex-Amazon employee stole the data of 100 million Capital One customers simply by exploiting a misconfigured web application firewall in the financial service giant’s AWS tech stack.

The incident ended with a high-profile lawsuit in which the financial services giant had to pay a $190m (£140m) settlement to affected customers. Other big businesses impacted by similar incidents include Accenture, Facebook, LinkedIn, Pegasus Airlines, Uber and Twilio. So, what can organisations do to secure their AWS tech stacks?

One of the biggest risks of an insecure AWS tech stack is data theft and exfiltration by cyber criminals, according to Rik Turner, chief cyber security analyst at Omdia. He explains this can happen when S3 buckets, which contain large volumes of files and sensitive metadata, aren’t set up properly.

As a result, S3 bucket access rights can be granted to employees who don’t require them for their roles, leading to insider threats. Or, worse, these crucial storage objects can end up on the public internet for anyone to access and abuse.

Sensitive corporate and customer data exposed in this way can lead to businesses experiencing “enormous financial losses”, says Sylvester Kaczmarek, a professor at online higher education provider the Open Institute of Technology. Their finances take a hit through regulatory fines, customer lawsuits and expensive recovery efforts that can last for months. Reputational damage is often substantial, too.

Additionally, weak or reused user credentials, the absence of cyber security logging and monitoring capabilities, and weaknesses in cyber defences like firewalls leave AWS tech stacks dangerously exposed to data breaches, he adds.

Data breaches can also stem from poorly secured Relational Database Service databases, Elastic Compute Cloud (EC2) instances and application programming interfaces, explains Bob McCarter, chief technology officer of risk and compliance software provider Navex. Erroneous identity and access management policies, a lack of multi-factor authentication, unpatched software and open ports are common security issues affecting these AWS services.

Besides costly data breaches, the day-to-day operations of modern businesses can grind to a halt in the aftermath of an EC2 instance compromise. The latter results in “impaired performance”, and even “a complete malfunctioning” of critical applications and workloads, explains Turner.

These issues are largely the product of mistakes made by AWS users and not cyber attacks targeted at Amazon, according to Neil MacDonald, vice-president and distinguished analyst at Gartner. But he emphasises that mistakes can easily happen due to the “sheer size, complexity and rate of change of AWS deployments”, adding that they are “impossible” to monitor without using appropriate security tools from AWS or other technology companies.

It is, therefore, the responsibility of AWS users to take steps to protect the data they upload to AWS cloud resources. This is enshrined in the cloud security shared responsibility model, with the responsibility of cloud companies like AWS being to secure the infrastructure they sell to customers.

Best practices to secure AWS tech stacks

When it comes to securing AWS tech stacks, many effective best practices are laid out in the AWS Well-Architected framework. McCarter explains that it offers a comprehensive guide for access management, infrastructure management, data privacy, application security, and cyber threat monitoring and detection.

Crystal Morin, cyber security strategist at cloud security company Sysdig, is another vocal supporter of this framework. She says it’s great for handling the prevention, protection, detection and response sides of cyber security. “This model helps you think through how to prevent problems in the first place, ensure your workloads have security in place, and then have the right tools in place to detect and respond to cloud security threats if and when they do take place,” says Morin.

As well as adhering to AWS’s own security best practices, MacDonald points out that the Center for Internet Security also offers advice for creating and maintaining a secure AWS tech stack. He adds that many modern cyber security tools are aligned with the latest AWS best practices, whether provided by Amazon or an outside organisation.

Given that lots of AWS-related security incidents are caused by inadequate access controls, Jake Moore – global cyber security advisor at antivirus maker ESET – urges organisations to implement the principle of least privilege to ensure access rights are limited to those who require them for their roles. This should be enforced as part of a wider identity and access management strategy.

Of course, staff hiring, attrition and promotion can make it difficult to manage AWS access controls. Still, Moore says businesses can use cyber security monitoring tools to track these changes and ensure access controls are amended accordingly, minimising security incidents. In addition to investing in these tools, he urges organisations with AWS stacks to regularly audit their cyber security posture to ensure security gaps are identified and closed swiftly. Automated analysis tools can help with this.

To ensure cyber criminals can’t steal sensitive data stored on and travelling between AWS servers, OPIT’s Kaczmarek says organisations must encrypt data when it’s at rest and in transit. Utilising the AWS Key Management service will help protect data at rest. Meanwhile, tight network security configurations are the key to securing transit data and wider network traffic. These should apply for virtual private clouds, Security Groups and Network Access Control Lists, according to Kaczmarek.

Organisations operating AWS tech stacks can log all network traffic using AWS CloudTrail and monitor it using AWS CloudWatch, says Kaczmarek. He adds that these efforts can be complemented by using multi-factor authentication, implementing security patches when they’re issued and replacing manual processes with infrastructure as code. The previous step is paramount for “consistency and auditing”, he claims.

 

Read the full article below:

Related posts

Value of the Capstone Project: OPIT Student Interview With Irene
OPIT - Open Institute of Technology
OPIT - Open Institute of Technology
Jun 12, 2025 6 min read

During the Open Institute of Technology’s (OPIT) 2025 graduation day, the OPIT team interviewed graduating student Irene about her experience with the MSc in Applied Data Science and AI. The interview focused on how Irene juggled working full-time with her study commitments and the value of the final Capstone project, which is part of all OPIT’s master’s programs.

Irene, a senior developer at ReActive, said she chose to study at OPIT to update her skills for the current and future job market.

OPIT’s MSc in Applied Data Science and AI

In her interview, Irene said she appreciated how OPIT’s course did not focus purely on the hard mathematics behind technologies such as AI and cloud computing, but also on how these technologies can be applied to real business challenges.

She said she appreciated how the course gave her the skills to explain to stakeholders with limited technical knowledge how technology can be leveraged to solve business problems, but it also equipped her to engage with technical teams using their language and jargon. These skills help graduates bridge the gap between management and technology to drive innovation and transformation.

Irene chose to continue working full-time while studying and appreciated how her course advisor helped her plan her study workload around her work commitments “down to the minute” so that she never missed a deadline or was overcome by excessive stress.

She said she would recommend the program to people at any stage in their career who want to adapt to the current job market. She also praised the international nature of the program, in terms of both the faculty and the cohort, as working beyond borders promises to be another major business trend in the coming years.

Capstone Project

Irene described the most fulfilling part of the program as the final Capstone project, which allowed her to apply what she had learned to a real-life challenge.

The Capstone Project and Dissertation, also called the MSc Thesis, is a significant project aimed at consolidating skills acquired during the program through a long-term research project.

Students, with the help of an OPIT supervisor, develop and realize a project proposal as part of the final term of their master’s journey, investigating methodological and practical aspects in program domains. Internships with industrial partners to deliver the project are encouraged and facilitated by OPIT’s staff.

The Capstone project allows students to demonstrate their mastery of their field and the skills they’ve learned when talking to employers as part of the hiring process.

Capstone Project: AI Meets Art

Irene’s Capstone project, “Call Me VasarAI: An AI-Powered Framework for Artwork Recognition and Storytelling,” focused on using AI to bridge the gap between art and artificial intelligence over time, enhancing meaning through contextualization. She developed an AI-powered platform that allows users to upload a work of art and discover the style (e.g. Expressionism), the name of the artist, and a description of the artwork within an art historical context.

Irene commented on how her supervisor helped her fine-tune her ideas into a stronger project and offered continuous guidance throughout the process with weekly progress updates. After defending her thesis in January, she noted how the examiners did not just assess her work but guided her on what could be next.

Other Example Capstone Projects

Irene’s success is just one example of a completed OPIT Capstone project. Below are further examples of both successful projects and projects currently underway.

Elina delivered her Capstone project on predictive modeling of natural disasters using data science and machine learning techniques to analyze global trends in natural disasters and their relationships with climate change-related and socio-economic factors.

According to Elina: “This hands-on experience has reinforced my theoretical and practical abilities in data science and AI. I appreciate the versatility of these skills, which are valuable across many domains. This project has been challenging yet rewarding, showcasing the real-world impact of my academic learning and the interdisciplinary nature of data science and AI.”

For his Capstone project, Musa worked on finding the optimal pipeline to fine-tune a language learning model (LLM) based on the specific language and model, considering EU laws on technological topics such as GDPR, DSA, DME, and the AI Act, which are translated into several languages.

Musa stated: “This Capstone project topic aligns perfectly with my initial interests when applying to OPIT. I am deeply committed to developing a pipeline in the field of EU law, an area that has not been extensively explored yet.”

Tamas worked with industry partner Solergy on his Capstone project, working with generative AI to supercharge lead generation, boost SEO performance, and deliver data-driven marketing insights in the realm of renewable energy.

OPIT’s Master’s Courses

All of OPIT’s master’s courses include a final Capstone project to be completed over one 13-week term in the 90 ECTS program and over two terms in the 120 ECTS program.

The MSc in Digital Business and Innovation is designed for professionals who want to drive digital innovation in both established companies and new digital-native contexts. It covers digital business foundations and the applications of new technologies in business contexts. It emphasizes the use of AI to drive innovation and covers digital entrepreneurship, digital product management, and growth hacking.

The MSc in Responsible Artificial Intelligence combines technical expertise with a focus on the ethical implications of modern AI. It focuses on real-world applications in areas like natural language processing and industry automation, with a focus on sustainable AI systems and environmental impact.

The MSc in Enterprise Cybersecurity prepares students to fulfill the market need for versatile cybersecurity solutions, emphasizing hands-on experience and soft-skills development.

The MSc in Applied Data Science and AI focuses on the intersection between management and technology. It covers the underlying fundamentals, methodologies and tools needed to solve real-life business problems that can be approached using data science and AI.

Read the article
OPIT Career Services: How We Support Your Future
OPIT - Open Institute of Technology
OPIT - Open Institute of Technology
Jun 12, 2025 6 min read

In May 2025, Greta Maiocchi, Head of Marketing and Administration at the Open Institute of Technology (OPIT), went online with Stefania Tabi, OPIT Career Services Counselor, to discuss how OPIT helps students translate their studies into a career.

You can access OPIT Career Services throughout your course of study to help with making the transition from student to professional. Stefania specifically discussed what companies and businesses are looking for and how OPIT Career Services can help you stand out and find a desirable career with your degree.

What Companies Want

OPIT degrees are tailored to a wide range of individuals, with bachelor’s degrees for those looking to establish a career and master’s degrees for experienced professionals hoping to elevate their skills to meet the current market demand.

OPIT’s degrees establish the foundation of the key technological skills that are set to reshape industries shortly, in particular artificial intelligence (AI), big data, cloud computing, and cybersecurity.

Stefania shared how companies recruiting tech talent are looking for three types of skills:

  • Builders – These are the superstars of the industry today, capable of developing the technologies that will transform the industry. These roles include AI engineers, cloud architects, and web developers.
  • Protectors – Cybercrime is expected to cost the world $10.5 trillion by the end of 2025, which means companies place a high value on cybersecurity professionals capable of protecting their investment, data, and intellectual property (IP).
  • Decoders – Industry is producing more data than ever before, with global data storage projected to exceed 200 zettabytes this year. Businesses seek professionals who can extract value from that data, such as data scientists and data strategists.

Growing Demand

Stefania also shared statistics about the growing demand for these roles. According to the World Economic Forum, there will be a 30-35% greater demand for roles such as data analysts and scientists, big data specialists, business intelligence analysts, data engineers, and database and network professionals by 2027.

The U.S. Bureau of Labor Statistics, meanwhile, predicts that by 2032, the demand for information security will increase by 33.8%, by 21.5% for software developers, by 10.4% for computer network architects, and by 9.9% for computer system analysts. Finally, the McKinsey Global Institute predicts a similar 15-25% increase in demand for technology professionals in the business services sector.

How Career Support Makes a Difference

Next, Stefania explained that while learning essential skills is vital to accessing this growing job market, high demand does not guarantee entry. Today, professionals looking for jobs in the technology field must stand out from the hundreds of applicants for each position with high-level skills.

Applicants demonstrate technical expertise in relevant fields by completing OPIT’s courses. They also need to prove that they can deliver results, demonstrating not just what they know but how they have applied what they know to transform or benefit a business. Professionals also need adaptability, adaptive problem-solving skills, and a commitment to continuous learning. OPIT’s final Capstone projects can be an excellent way to demonstrate the value of newly acquired skills.

Each OPIT program prepares students for future careers by providing dedicated support and academic guidance at every step.

What Kind of Support Does Career Services Offer?

Career Services is specifically focused on assisting students in making the transition to the job market, and you can make an appointment with them at any time during your studies. Stefania gave some specific examples of how Career Services can support students on their journey into the career market.

Stefania said she begins by talking with students and discussing what they truly value to help them discover the type of career that aligns with their strengths. With students who are still undecided on how to start to build their careers, she helps them craft a tailored job and internship search plan.

Stefania has also worked with students who want to stand out during the job application process among the hundreds of applicants. This includes hands-on help in reframing resumes, tailoring LinkedIn profiles, and developing cover letters that tell a unique story.

Finally, Stefania has assisted students in preparing for interviews, helping them research the company, develop intelligent questions about the role to ask the interviewer and engage in mock interviews with an experienced recruiter.

Connecting With Employers

OPIT Career Services also offers students exposure to a wide range of employers and the opportunity to build relationships through masterclasses, career talks, and industry roundtables. The office also helps students build career-ready skills through interactive, hands-on workshops and hosts virtual career fairs with top recruiters.

Career Services also plays an integral role in connecting students with companies for their Capstone project in the final phase of their master’s program. So far, students have worked with companies including Sintica, Cosmica, Cisco, PayPal, Morgan Stanley, AWS, Dylog, and Accenture. Projects have included developing predictive modeling for natural disasters and fine-tuning AI to answer questions about EU tech laws in multiple languages.

What Kinds of Jobs Have OPIT Graduates Secured?

Stefania capped off her talk by sharing some of the positions that OPIT graduates have now fulfilled, including:

  • Chief Information Security Officer at MOMO for MTN mobile services in Nigeria
  • Data Analyst at ISX Financial in Cyprus
  • Head of Sustainability Office at Banca Popolare di Sondrio in Italy
  • Data Analyst at Numisma Group in Cyprus
  • Senior Software Engineer at Neaform in Italy

OPIT Courses

OPIT offers both foundational bachelor’s degrees and advanced master’s courses, which are both accessible with any bachelor’s degree (it does not have to be in the field of computer science).

Choose between a BSc in Modern Computer Science for a strong technical base or a BSc in Digital Business to focus on applications.

Meanwhile, courses that involve a final Capstone project include an MSc in Applied Data Science and AI, Digital Business and Innovation, Enterprise Cybersecurity, and Responsible Artificial Intelligence.

Read the article