Triad ICS
Menu

Insights/Technical Deep-Dives

AWS S3 Bucket Security: A Step-by-Step Hardening Guide for SaaS Founders

Published

Reading time2 minutes

FromTriad ICS Research

Exposed S3 buckets remain a common source of data leaks. Nine steps to close the gaps.

Amazon S3 is where many Indian SaaS products keep their most sensitive files: invoices, KYC documents, exports and backups. AWS has improved the defaults considerably, but buckets created years ago, or changed in a hurry, often still carry old risks. Work through these steps in order.

1. Turn on Block Public Access at the account level

Since April 2023, new buckets have Block Public Access enabled by default. Older buckets may not. Enable all four Block Public Access settings at the account level so a single bucket policy mistake cannot expose data.

2. Disable ACLs

Set Object Ownership to “Bucket owner enforced”. This disables access control lists and makes bucket policies and IAM the only way access is granted, which is far easier to reason about.

3. Review every bucket policy

Look for a Principal of “*”, broad actions such as s3:*, and cross-account access you do not recognise. IAM Access Analyzer will flag buckets shared outside your account.

4. Enforce encryption, in transit and at rest

New objects are encrypted with SSE-S3 by default since January 2023. For sensitive data, use SSE-KMS with a customer-managed key so you control and audit key usage. Add a bucket policy that denies any request where aws:SecureTransport is false.

5. Use short-lived, scoped access

Serve private files with pre-signed URLs that expire in minutes. Avoid long-lived access keys in application code; use IAM roles instead.

6. Restrict network paths

For internal workloads, use a VPC gateway endpoint for S3 and a bucket policy condition that only allows access through it.

7. Protect against deletion and ransomware

Enable versioning, and consider S3 Object Lock for backups and audit data so they cannot be overwritten or deleted during the retention period.

8. Log and monitor

Enable CloudTrail data events for sensitive buckets, or S3 server access logs, and send alerts on unusual activity. Amazon Macie can help locate personal data you did not know you were storing.

9. Think about where the data lives

For personal data of Indian users, AWS Mumbai (ap-south-1) and Hyderabad (ap-south-2) regions keep storage in India, which simplifies conversations with customers and with sector regulators that have localisation expectations.

Finally, check it

Configuration drifts. Put these checks into an automated posture review, run it regularly, and treat any new public bucket as an incident until proven otherwise.

This article is general information, not legal advice. Compliance services do not guarantee certification; certification bodies issue certificates.

Turn Insight into Action