AWS CISO Chris Betz at AWS re:Inforce 2024 – CISO Talk EP 45
Immediately following his AWS re:Inforce 2024 Keynote talk, AWS CISO Chris Betz joins Mitch Ashley on CISO Talk. Chris shares his comprehensive approach to security, including creating a culture of security, AWS chip security, secure programming languages like Rust, securing AI and the data AI uses, and more. Mitch considers Chris Betz an example of the modern-day CISO, a CISO for 2024 and beyond. https://reinforce.awsevents.com/
Transcript
Hi, am Mitch Ashley here. I'm very excited to be joined by Chris Bets, who's ciso. We with AWS.
We are here at AWS reinforce our, you know, at a conference dedicated to security. So you can imagine how much fun we're having here if you're into security, that's a good place to be. Welcome.
It Is a team heads. Great to, great to spend some time with you, b***h. I, I, I'm very, very excited to be talking with you.
You know, you, you did your keynote today and I was really interested in several things, but I have a feeling some of your background, this led you up to this role, which by the way, is a massive job. I can't imagine having as your responsibility. Can you kinda give us a little bit of your, your journey, your path to this role at AWS?
Sure. So my, my career started in the Air Force. Uh, I was very, very fortunate, privileged to be able to learn, uh, about leadership, computer security, uh, and, and frankly spend time, uh, in the Air Force doing that kind of work.
Um, from there, I, uh, I, I spent, uh, several years, US government, um, and then, uh, I, I was really lucky. Um, I had a, uh, uh, colleague of mine who went to be the first CSO ever at CBS Oh, wow. And, uh, and, and he, he said, Hey, Chris, will you come join me?
Will you come help me build this program? Uh, and it was an incredible opportunity. I got to meet bunch of smart folks inside of CBS, get to co build a cybersecurity practice.
Um, and the, the amazing part about that is these were in the days when, when cybersecurity was new, we didn't have CISOs. And so I got to go along on that journey and I got to watch somebody else do it. Mm-Hmm.
Uh, and, and, and, and make mistakes as we go and learn and, and, and, and work. Um, from there, I, uh, I, I got the opportunity to work at Microsoft, um, leading the Microsoft Security Response Center. So Patch Tuesday, uh, global worldwide response to security issues.
Um, and, and eventually, uh, security operations for Azure, uh, and, and engineering for security operations for Azure. So, so just a really fun blend of things and got to see the inside of what was at that point, a relatively new cloud. Uh, I, I was then really lucky enough to go down to Apple, um, and work with some amazing folks leading, uh, security for Apple products, um, and getting involved in engineering security solutions, uh, and, uh, and, and parts of the operating system, learn what it took to s**t code, uh, and be part of, of a very different organization.
Uh, I spent, uh, a few years there and then, uh, when CenturyLink bought level three, um, I was given the opportunity to be the chief security officer for the combined organizations. Um, and so, uh, had incredible time learning about telecommunications, big global worldwide networks, what is involved being a chief security officer, um, at that scale of a business that, that is just foundational for so much what we do. Um, and then, uh, capital One was looking for a new chief information security officer, and I've always wanted to do banking because security and banking, it's hard.
Mm-Hmm. Uh, it's a completely different kind of challenge. Uh, and so I was, uh, invited to join, and so moved to Virginia and, uh, and spent the past few years just with an amazing set of folks.
Um, and as when I was there, capital One closed their last data center because they had moved all of their sec all of their operations to our network into AWS. Uh, and so it was very natural having been a customer of AWS actually in several of these roles, uh, to be, I, I knew the leaders here. I was very deeply involved in understanding AWS so it was a natural move.
When, uh, when, when Steve Schmidt said, Hey, Chris, what do you think about being the CIL for AWS? Uh, it was an easy answer yes. Um, and I just been here for, for nine, going on 10 months, enjoying the incredible rent of the work, the scale of the work, uh, and just the speed at which things moved, which is just absolutely.
So, so having a great time. Fantastic. What a, what a regression.
I was kinda surprised in your keynote started, one of the things just started was hardware, talking about, um, the security built into chips and to the, uh, enclaves, uh, the elements that, you know, oftentimes you're not hardware company, but you are Right. Building your own hardware. Talk about that.
It's a, one of the things that I enjoy about just the, the breadth and scope, um, what, when you get good at security, when you get good at anything, you start looking at where is the leverage? Where can you do things that add extra capability? Where are you being held back by technology as it exists?
And so you can certainly see that in our gravitant journey. We look at performance, cost, uh, security, um, the, uh, the, there's, there's just immense work. And I'm fortunate that I, I had a, a background in having to do some of that, or having to do in getting to do some of that at past companies as well.
And so it, it really is, it's fun to be able to stretch those, uh, those muscles again. Um, and, and as I mentioned in the keynote, one of the things that both impressed and surprised me is, you know, as a customer, I picked AWS because I knew what the security story, the security industry was here. I felt very, very confident about it.
Um, I think sometimes we, we, we almost underplay our ability to tell our security story. I think Graviton four is a great example of this. I was there 2023 at re Invent when we launched Graviton four.
We talked about all sorts of capabilities. What we didn't talk about at the time, the piece of the story that was never shared was all of the security work that went in all of the enhancements that were there. And, and I think that's telling in a couple ways.
One, if we were a different company, we had different values. If we weren't going to advertise it, we wouldn't have done the work. But security is so important to us that, of course, we put that security stuff in.
And in fact, as I dug around and started talking to people, it wasn't that people didn't wanna talk about the security. It was simply that, but of course we did it. Everybody assumes this.
That's not the news. The news is the incredible capabilities, the cost of performance, et cetera. And, and we had to have the conversation.
No, no, actually these cutting edge security solutions baked in, not everybody's doing this. Not everybody's doing this. Not everybody's doing this.
And this has real value. And this is something that our customers should know because they're putting a ton of trust in us, and it's important that they understand why we are trustworthy. We need to continue to earn that trust.
So we need to make sure we're telling those stories as well. Gave a really good example to make it real of why this is important. You know, we work in the cloud.
We don't think about hardware as customers, right? But you gave the example of being able to make sure that you protect a customer's AI data, for example, from other things that are happening on the chips. So it's not Coe they're accessible by, you know, the logic on the chips that, uh, are comport to you for running the hardware, but you can guarantee that separation to protect that confidentiality and that trust that customers have And trust is so important.
Look, we, we know that each solution out there, you know, every cloud is built differently and making sure that we're able to consistently show and earn that trust because people are putting their livelihoods, their most sensitive data. And I take that very seriously. We take that very seriously and showing how we, and, and words are important, actions are even more important.
So the way we act, our security record here shows and continues to demonstrate how important we see this is. Then you surprise me and you start talking about rust Programming languages, That strong type E got memory safes and verification verifiable. You know, we've gone, we're going through this transition.
Maybe we're in the middle of it, I'm not sure, but CSO have had to grow up in kind of a network security role, but now they're being asked to be participated in this Software world. Mm-Hmm. And some know software have had a chance to do that.
Many your, I don't know, a microservice from a macro service might work Mm-Hmm. Might, whatever it might be. Um, you start talking about Rust and why it was important to have so much, uh, Amazon software move to Rust Talk.
Was that a strategy that already started before you came and you helped propel it, or did you help into that? It was a strategy that already existed here? Um, I, I guess two quick thoughts.
So, so my background and rightfully identified, um, I've been a software person. In fact, I participated in many Defcon capture the flag competitions and that kind of stuff. That's, I wasn't kidding about the pen tester and me loving a good memory.
Uh, you, you always smiling. I I love doing that kind of work. That's fun.
That's, that, that's when I get a few extra hours after the kids and after the family get to, yeah, no. So that, those are, those are good days. Um, but the theme for the talk, and, and what I really wanted to help share with the audience was I came here thinking, oh, I've been a customer for years.
I talked to these security folks, I understand what they're doing. And then I find these hidden gems all over the place. So I couldn't bring all of it, but I pulled a few up, you know, that the security features we built into Gravitant for that.
Unbeknownst to everybody in the world, we took a look at a next generation shard store and we said, rust is the right choice because we can do all this provable security, we can be memory safe, we can be type safe, and we can be highly performant. And so teams are rewriting things that already exist using these languages, improving security. Would I have a customer ever know that I CS OR, you know, at, at, at, at at Capital One?
Never been conversation that I knew and nor is that visible externally, but I've got just these anecdotes and, and what you saw was just a small portion of them of where I had not truly appreciated how deep the passion goes for security, how deep the level of care goes for security, and how we make that, uh, that that clearly visible. It's exciting. It's, it, it's exciting to know that you're building in an environment where the trust is kind of built.
Building our frameworks out, you know, policies that were written, uh, Around Ai, for example, talk about ai and if you had put your customer hat back on slide unknowns about ai Mm-Hmm. How is it different? You know?
Yes. The, the model is the code data changes over time. It kind of has a different flow than normal software looks and feels.
I wonder too, from a security perspective, we have to do things that are different, protect it. Do we have to respond differently, um, when there are threats against it or we have an incident? What, how do you think about that?
It's great question. Um, I tend to think of it in, in three layers. So there's the work we do to train or fine tune a model.
It's when we bring our most sensitive data to make the model operate the way we need to. And, you know, the, the, the, the, the fundamentals of how we protect that, I mean, heck, I said it, you know, the, the, the, the AWS this, your data is your data, period, end of story. This is your environment.
These are your weights, this is your protection. Making sure we've got the right protections around that. And that, as you would expect as an AWS customer, all of those things that you expect of every AWS service are just as true for generative AI is incredibly important.
So you get that layer one that's training, make sure we bake those pieces out. Layer two, that kind of, that second layer is now you've done the training, you've done the fine tuning, you've got the model that you want, and you're now doing inference against it. And so how do you make sure that you've got the right protections around the model?
That the prompts that go in are appropriate? The responses that come back only contain the information that you want and that the, all the additional data you bring in other than the prompt, the rag, and all the rest of those pieces are, are managed and secure as well. And so you get both the inferencing environment that we create, as well as things like, uh, bedrock's guardrails where we take the lessons that we've learned as we're building AI solutions and we codify and try to make that as easy and accessible as possible so that both the prompts in and the responses out can get filtered and get reviewed and have the right tools in place.
And then there's level three, layer three, excuse me, is, uh, in, in, in this, in, in my mental model of generative ai, nobody uses a model on its own. A model exists for a business because they're trying to accomplish something and that, and so you need that application that uses the model that brings all the other data about the customer, whatever else you're trying to do with the model. And, and this is AWS at its best today.
This is all the work that we do with all the services to make sure things are secure. And it's something you can't keep your, you can't, you can't miss. You have to make sure that you're paying attention to.
And so when I think about generative ai, there are some parts that are different, but there's some parts that are very, very similar. And I think working at each one of these layers, training inference and the application around it, we build security in all three places. You can see a little bit about where and how we've done that to give people the tools to do that, make it as easy as possible.
We'll end up and we'll continue to end up with some brilliant JI solutions that are also very secure. It's exciting, especially as, um, as AWS has rolled out AI capabilities and so many services, you in fact have to be a consumer of your own AI service as part of the service restrict delivery. And what we're working really hard to do is codify as many of those lessons as possible either in blogs and documentation so we can help other people go on the same journey, even better wherever we can in tools that make it so that it is seamless, transparent, just in natural motion, so that builders everywhere get the benefits of all that security expertise without needing to reinvent it as they go.
Very nice. I, I assume we have an opportunity to talk to a lot of, um, other people. We're CISOs not just within, that's what about the CISO community?
Yeah, it's incredibly tight. We get to talk to, we get, frankly, we talk to each other all the time and yeah, in this role I get to talk to even more people. I'm sorry, I interrupted.
No, no, No, no. It's, it, I don't think most people realize that, uh, we're able to share threat information, information, talk about security. Uh, yet an interesting way of describing it of, you know, we're all part of a community.
Many of our customers, your customers, they're also customers of the competition, right? So this, if they're, uh, compromised for some reason, your customer now is suffering because of that, because of the, even if it's not your service and could impact you and your relationship with them. So we don't want bad things to happen to our competitors from a security stand.
That's one of the things that I appreciate the most about the, the, the security community is, regardless of which CISO role I've been, whether it's been telco, finance, um, or now technology, honestly, some of the people I talk to most often are companies that are our peers. And, and, and, and because we have a job to do, the bad guys are on the outside and we have to keep them away from our customers. That is incredibly important.
And as I, as we talked about earlier, um, I, I really do think that the work that the US government did with the CIS Act of 2015 really helps those conversations, that ability to share threat intelligence on a constant basis and to really go, you know, help protect all of our customers, uh, no matter where they're, where they're, gives You some antitrust protection to be able to have those conversations. Exactly. Yep.
So before we, uh, finish up, I wish we had about four more hours, but I dunno if you do. But, uh, what, what are the conversations you think we need to be having over the next six to 12 months? Is you gotta look forward, obviously things are happening very quickly, things happen very quickly at AWS showing on services, but gen ai and there'll be something else that'll pop up on the horizon.
What, what do you kind of foresee are the right conversations to be starting now? I think generative AI remains and will remain for the next six months, 12 months, a constantly evolving conversation as we get better at it. And we, we are all continuing to explore and provide each other the right tools that, that constant Steve Schmidt talked about today.
That constant testing, that constant evolution, that virtuous cycle is incredibly important. Um, I also think that we we're not done with the zero trust conversation yet. Mm-Hmm.
Uh, I think the zero trust conversation, uh, you know, almost every company I've worked with who's gotten, uh, closer to where they wanna be with zero Trust, it takes a combination of a variety of technologies and some really careful refinement to do it. But when those companies get there and the data shows how substantially more secure that they are. And so I think that's again, a, a really good and, and ongoing conversation.
How do we make that easier, faster, more seamless for companies to pick up and, and, uh, and, and really get closer to that zero trust goal? Wonderful. Well, we need to talk about security culture.
Well, culture of security. We need to talk about advanced zero trust. There's so many things we need to get back together for.
So I hope we get a chance to do that so as well, right. Chris bets CISO with AWS. Thank you.
Be Welcome. And thank you for the great keynote today, and thank you for being part of our conversation.




