2026-08-12 · aws-security
AWS announced that its 2026 CyberVadis assessment report and scorecard are now available for customers performing supplier due diligence. The post frames cloud providers as critical third parties and emphasizes the growing pressure on regulated organizations to evaluate security, control coverage, and risk management in their external dependencies. That matters for data preservation because supplier assurance is not just about prevention. It is also about proving that recovery, continuity, and control boundaries still hold when a provider, partner, or shared platform becomes the weakest link in the chain.
AWS said it completed the 2026 CyberVadis assessment with the highest score level, Mature, across all assessed areas and made the resulting materials available through CyberVadis and AWS Artifact. The post specifically targets customers that need faster, more defensible third-party risk reviews for regulated and security-sensitive workloads.
When organizations depend heavily on external providers, a control failure can become both a security incident and a compliance event. If critical records, encrypted archives, or recovery data live only inside third-party-managed systems, a supplier outage or compromise can turn routine due diligence gaps into prolonged operational loss.
Cold storage reduces dependence on any single online vendor by preserving critical data and recovery material in an offline, independently controlled form. That separation helps organizations maintain a trusted restoration path even if a provider environment, account boundary, or connected security stack is unavailable during an incident.
Read Original Post →