Secure Cloud Data Access on AWS
A hands-on lab using Varonis DatAdvantage Cloud (DAC) to discover sensitive data, expose risky access, and remediate real misconfigurations in a live AWS account.
What you get
Your own dedicated AWS account and DAC tenant (1:1), pre-integrated and populated so you spend time investigating and fixing.
The scenario: Northwind Health Analytics
Northwind Health Analytics is spinning up a new AI/analytics initiative on AWS. Moving fast, the cloud team made common mistakes. Your job for the next two hours is to be the security team, using DAC.
- Stood up a "data lake" from production copies — left buckets public.
- Mislabeled a bucket — one named for cardholder data is harmless; a blandly named one holds real patient records.
- Hardcoded secrets in config files and DB tables.
- Reused an "automation" identity with
Action:* Resource:*. - Opened Aurora to the internet (
0.0.0.0/0on 3306/5432), over-privileged DB user, weak password. - Generated day-to-day activity incl. failed logins and odd queries.
Your mission
Find the sensitive data, determine who can reach it, and remediate — some fixes from the DAC UI, others via the AWS console with DAC guiding you.
How it runs (~3 hours)
| Segment | Time | What happens |
|---|---|---|
| Intro & DAC value on AWS | ~20 min | Why data-centric security matters for AI. |
| Live demo | ~20 min | Presenter deploys a Local Collector & integrates an account. |
| Labs 1–7 | ~110 min | Work at your own pace. |
| Extras / Wrap-up | ~40 min | Challenges, Q&A, DAC assessment offer. |
Heads-up on access
Your AWS account comes from the self-service login at the top of this page. Enter your workshop code and email to get a one-click console link.

