CIO Brief: Secure Defaults Help — But Only for New Resources
Retrospective: this article looks back at events from April 2023, written in 2026 with the benefit of hindsight.
The short version: In April 2023, AWS changed the defaults so new cloud storage buckets are private and simpler to secure. That's a big improvement — but it only applies to buckets created after the change. Older storage keeps whatever settings it had.
Why defaults aren't the end of the story
Security improvements from cloud providers often apply to new resources only, to avoid breaking existing applications. Organizations with years of cloud history carry older resources with older, riskier settings.
The business impact
- Uneven protection: new systems are secure by default; older ones may not be.
- Audit confusion: "AWS fixed that" is only partly true.
- Hidden risk in long-lived storage holding historical data.
Questions to ask your team
- How many of our storage buckets were created before 2023, and have their settings been updated to current defaults?
- Do we review older resources when providers improve defaults?
- Are protections enforced at the account level, so they cover old and new resources alike?
What good looks like
Account-wide protections that cover every resource regardless of age, and a regular review of legacy resources whenever providers change defaults.
The decision
When a provider announces improved defaults, ask your team: "What about our existing resources?" The answer usually identifies a cleanup project worth doing.
- S3 Block Public Access and ACLs Disabled by Default for New Buckets (Apr 2023) Platform Changes
- How to Migrate Legacy S3 Buckets Off ACLs to Bucket Owner Enforced How-To & Hardening
- S3 Object Ownership and ACL Cleanup Checklist How-To & Hardening