• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
LeadershipLeadership

Think like a hacker and play the long game—How Amazon’s chief security officer protects all that data

By
Lila MacLellan
Lila MacLellan
Former Senior Writer
Down Arrow Button Icon
By
Lila MacLellan
Lila MacLellan
Former Senior Writer
Down Arrow Button Icon
November 2, 2023, 8:00 AM ET
Steve Schmidt, chief security officer at Amazon
Steve Schmidt, chief security officer at AmazonCourtesy of Amazon

The dire threats posed by cyberattacks are becoming clearer with every passing year.

Recommended Video

Last month, Lloyd’s of London estimated that a hypothetical major cyberattack on the world’s financial payment systems could cost about $3.5 trillion globally, with the U.S. suffering about one-third of that loss. The U.S. has already seen “hundreds” of breaches that have handicapped hospital operations this year, according to the American Hospitals Association. Other companies, like the genetic testing business 23andMe, have also been victims of data theft.

Meanwhile, the conflict between Israel and Hamas has led to a spike in cyberattacks in the region, and could trigger additional activity elsewhere as the war continues and geopolitical dynamics shift.

Despite witnessing a steady stream of cyber incidents in the news, however, a lot of companies aren’t prepared, says Steve Schmidt, chief security officer at Amazon and a member of the company’s famous “s-team” of senior leaders, who report directly to CEO Andy Jassy.

Amazon has been criticized in recent years for not protecting its ever-growing cache of customer data properly. Schmidt, a former FBI section chief who was CISO at AWS for 15 years, began his job as CSO for Amazon in 2022.

Many businesses at risk of cyberattacks “don’t even know it yet because they don’t have anybody looking,” he tells Fortune. To be fair, he adds, they may not have anyone looking because of a major shortage of people with cybersecurity skills.

Schmidt’s team at Amazon—one of the most data-rich companies on the planet—is planning a hiring spree in the coming months. “If we’re hiring thousands of people, and others who are large out there are hiring thousands of people, the pool of available talent or talent is exhausted pretty darn quickly,” Schmidt says. 

Here’s how he thinks about his job protecting all of Amazon’s physical and digital properties, which he describes as a matter of “solving puzzles, playing chess, and practicing psychology.”

Get clear on what data and hardware you have

The most basic and surprisingly overlooked job a security team can tackle involves cataloging all of a company’s digital and hardware infrastructure (software, servers, devices) and keeping that data updated, Schmidt recently told Fortune. Companies should also rank their assets and assign multiple layers of security — then keep testing those layers to ensure that they’re still working.

Know your cyber threats

“Many people think of security as a job where you’re stopping things from happening, and certainly there’s an element to that,” Schmidt says. “But what I’m trying to do more than anything else is understand the motivation of our adversaries.”

To that end, Amazon recently revealed that its cyber team uses a proprietary platform it dubbed “MadPot,” a form of deception software that gives hackers the false impression that they’ve accessed real data. Once the stranger is in the system, Amazon can “get adversaries to engage with our sensors,” says Schmidt, “and let them think they’re engaging with our customers, so we can collect the adversaries’ tools. We get to learn about their techniques, we get to learn about what they’re trying to focus on, and it informs our threat intelligence services.”  

The groups that might want to bust past a company’s system range from hackers playing games to annoy each other, to thieves who behave much like highly organized crime families. The opponents targeting Amazon and other large companies may also be contractors working for a foreign government like Russia or China. Even when these people are not particularly talented, Schmidt explains, “there’s such high volume [of their attacks] that their statistical chance of success is relatively high.”

Not every company can take advantage of threat intelligence software like MadPot, says Schmidt. For these programs to work, the organization needs to have enough data and networks to produce statistically useful information. “You also need to have to have a team that’s the appropriate size and maturity to be able to digest the information effectively,” he says. For teams that are smaller or busy with immediate catch-up projects, Schmidt advises acquiring threat intelligence software.

Your worst enemy could come from within your own ranks

It’s not always a stranger who breaks in or enables a breach, of course. The reality is quite the contrary: the biggest threat usually comes from inside the house.

The two scenarios that most small and medium-sized companies should worry about most, according to Schmidt, are employees “using their legitimate access to data for things that they shouldn’t do” and “employees being exploited by a social engineering actor” seeking data in a ransomware attack.

Cybercriminals are known for gaining access to a system through the legitimate credentials of an employee. They might do that through a phishing campaign or by bribing an employee, which happened at Amazon in 2021. Once past the gates, criminals with an employee’s identity can maneuver fairly freely, which is why Amazon severely limits the amount of data that any employee can access at one time, and monitors how employees use their access.

“If you think about the way a business typically runs, there’ll be some administrators who have access to everything in the company,” says Schmidt, “The smaller the business is, the more usual it is for everybody in the company to have access to all the data.” That may be the easiest solution, he adds, but it’s bad for security.

Cybersecurity is key to unlocking innovation

Many companies see cybersecurity as a “gatekeeping” function that slows down other parts of the business. But within Amazon, security work is seen as a business accelerator, according to Schmidt, who says that’s a mindset shift that many companies may still need to make.

Schmidt advises CEOs to measure their security teams by “how they’re increasing velocity versus slowing things down.” Is your CISO or head of data asking how they can enable a new product, not simply policing and blocking what people do?

“I personally view the use of the word ‘no,’ in a security context, as a failure,” Schmidt says. Stopping something from happening may feel prudent in the short term, but saying no all the time will stop a company from growing in areas where it needs to innovate, he contends. Perhaps worse, he adds, it will eventually frustrate product builders and may lead to them to find ways to circumvent the security team as much as possible. Ideally, companies want to engender just the opposite: early and frequent collaboration between engineers, product teams, and security leaders.

Play the long game

As CSO at one of the world’s largest companies, Schmidt is no longer working in the tactical day-to-day of cybersecurity. Instead he’s playing the long game, planning for 3 to 5 years out, studying how malicious actors might be evolving, and what kind of investments may be required to maintain strong defenses.

Security teams at companies of all sizes should be doing the same, he says. They ought to be looking out for emerging tech, and launching upgrades now that may take a few years to roll out. “Many years ago, Amazon started moving over to hardware multi-factor authentication because we saw the evolving threats from both the nation-state actors and the social engineering-slash-ransomware organizations,” says the CSO. “Making that change took us four or five years because of the size of our company, even though we’re a really tech-focused organization, so most companies out there have to figure out: ‘What are the threats that are going to be facing me? What are the techniques that I need to start investing in now in order to protect myself against those threats?’”

Nov. 2, 2023: This story has been updated with the correct term for MadPot, and clarified that MadPot is Amazon’s proprietary software. 

Do you have insight to share? Got a tip? Contact Lila MacLellan at lila.maclellan@fortune.com or through secure messaging app Signal at 646-820-9525.

Join us at the Fortune Workplace Innovation Summit May 19–20, 2026, in Atlanta. The next era of workplace innovation is here—and the old playbook is being rewritten. At this exclusive, high-energy event, the world’s most innovative leaders will convene to explore how AI, humanity, and strategy converge to redefine, again, the future of work. Register now.
About the Author
By Lila MacLellanFormer Senior Writer
LinkedIn icon

Lila MacLellan is a former senior writer at Fortune, where she covered topics in leadership.

See full bioRight Arrow Button Icon

Latest in Leadership

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Leadership

Google Cloud revenue is now 18% of Alphabet’s business. Is this the beginning of the end of Google’s search identity?
Big TechGoogle
Google Cloud revenue is now 18% of Alphabet’s business. Is this the beginning of the end of Google’s search identity?
By Alexei OreskovicApril 29, 2026
4 hours ago
A man in a suit and tie
InvestingMeta
Meta just bumped its 2026 capex forecast up to as much as $145 billion for the AI boom—and investors flinched
By Amanda GerutApril 29, 2026
7 hours ago
teri
BankingBanks
Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
By Nick LichtenbergApril 29, 2026
7 hours ago
pete hegseth
PoliticsIran
‘A strategic blunder’: Democrats confront Hegseth as the Iran war’s price tag hits $25 billion
By The Associated Press, Ben Finley, Stephen Groves, David Klepper and Konstantin ToropinApril 29, 2026
9 hours ago
Jamie Dimon says bureaucracy sinks companies and the solution may be getting rid of the ‘jerks’ who don’t want to solve it
C-SuiteJamie Dimon
Jamie Dimon says bureaucracy sinks companies and the solution may be getting rid of the ‘jerks’ who don’t want to solve it
By Marco Quiroz-GutierrezApril 29, 2026
10 hours ago
Hilton CEO Christopher Nassetta
EconomyHospitality
Hilton’s CEO says the economy is actually C-shaped to the benefit of the middle class. Most of his competitors disagree
By Tristan BoveApril 29, 2026
10 hours ago

Most Popular

Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
3 days ago
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
Energy
‘Take the money and run’: Johns Hopkins economist Steve Hanke on why the UAE quit OPEC
By Shawn TullyApril 29, 2026
23 hours ago
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
AI
‘The cost of compute is far beyond the costs of the employees’: Nvidia executive says right now AI is more expensive than paying human workers
By Sasha RogelbergApril 28, 2026
2 days ago
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
Economy
Jamie Dimon gets candid about national debt: ‘There will be a bond crisis, and then we’ll have to deal with it’
By Eleanor PringleApril 29, 2026
19 hours ago
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
Banking
‘They left me no choice’: Powell isn’t going anywhere—blocking Trump from another Fed appointee
By Eva RoytburgApril 29, 2026
11 hours ago
More than two-thirds of U.S. schools say they’re unable to afford the cost of student free lunch—and MAHA’s dietary guidelines may make it worse
Economy
More than two-thirds of U.S. schools say they’re unable to afford the cost of student free lunch—and MAHA’s dietary guidelines may make it worse
By Sasha RogelbergApril 29, 2026
21 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.