New Amazon CloudHSM service vows enterprise-grade security
Amazon Web Services runs on tons and tons of shared hardware. That's a huge benefit in terms of cost but also spooks customers with strict regulatory requirements that prevent them from running their applications on shared infrastructure.
Context & Ripple Effects
AWS had already expanded its cloud’s performance envelope with supercomputer cluster capacity, while earlier coverage treated security in the cloud as a central adoption concern. CloudHSM addresses the part of that concern that shared infrastructure makes hardest for regulated enterprise buyers to accept: whether they can meet strict security requirements without abandoning AWS’s cost model.
First-order effects
- AWS gains a security-focused offer for enterprises whose regulatory rules had kept applications off shared cloud infrastructure.
- Regulated customers can evaluate AWS shared infrastructure on security controls as well as its cost advantage.
Second-order effects
- Cloud rivals seeking the same regulated workloads face pressure to pair shared infrastructure with comparable enterprise-grade security services.
- Security requirements move closer to being a product-selection criterion for cloud capacity, rather than a reason to exclude shared cloud outright.
Third-order effects
- If cloud providers can package controls that satisfy regulated buyers, compliance becomes a route for more enterprise workloads to move onto shared infrastructure rather than a durable barrier to it.
The trend: Cloud platforms are broadening from raw compute capacity into security-assured infrastructure designed to bring regulated enterprise workloads onto shared systems.