← Back to News

AWS draws a hard line between KMS and CloudHSM

2026-07-30 · aws-security

AWS has published fresh guidance on choosing between AWS KMS and AWS CloudHSM, focusing on the operational and custody differences between the two hardware-backed key management models. For security teams, that is more than an architecture note: it is a direct reminder that backup protection depends on who controls the keys and where those keys live. Cold storage is only as strong as the custody model around the secrets that unlock it. When key decisions are vague, organizations can end up with encrypted backups that are reachable, reversible, or operationally dependent on the wrong trust boundary.


What Happened

AWS published a new security post explaining how AWS KMS and AWS CloudHSM both rely on hardware security modules while serving different operational needs. The guidance positions the choice as a key-management architecture decision rather than a simple feature comparison.

The Cost of Data Loss

If key custody is poorly designed, ransomware recovery, legal hold restoration, and disaster recovery can all break at the exact moment encrypted data is needed. Losing control of the key layer can turn otherwise healthy backups into unusable ciphertext or, just as dangerously, make recovery material too accessible to an attacker.

How Cold Storage Prevents This

Cold storage works best when critical backup sets are paired with hardware-backed, tightly governed key custody and minimal online exposure. Separating retained data from day-to-day attack paths, while isolating the most sensitive recovery keys, makes it far harder for a single compromise to destroy both production data and the means to recover it.

Read Original Post →