Instaclustr’s Managed Elasticsearch Service on AWS Gets PCI-DSS Certification

Jun 14, 2021 | Data, News, Privacy

by Ben Slater, Chief Product Officer, Instaclustr

Instaclustr has announced that its Managed Elasticsearch Service on AWS for data logging, search, and analytics has achieved PCI-DSS compliance. Instaclustr’s Managed Apache Cassandra and Managed Apache Kafka solutions on AWS have also earned re-certification.

Elasticsearch_Press_release_Website_pr-1024x536

Instaclustr’s Managed Elasticsearch is based on the Open Distro for Elasticsearch, which will soon be updated to OpenSearch. Using the open source distribution ensures that Instaclustr customers always have control and portability of their data, are not subject to vendor lock-in, and are free from licensing costs.

This PCI-DSS certification for Managed Elasticsearch adds to Instaclustr’s existing PCI-DSS and SOC 2 accreditations, which demonstrate the company’s commitment to thorough data security practices and architecture. Enterprises with the most stringent security requirements can utilize Instaclustr’s advanced managed open source data solutions knowing that their environment is continually aligned with the most rigorous security protocols.

The PCI-DSS (Payment Card Industry Data Security Standard) is the payment card industry’s mandated information security standard and applies to all organizations that store, process, and/or transmit cardholder data. PCI-DSS certification requirements dictate that all system components either within the cardholder data environment or with access to it must feature specific and strict technical, physical, and operational security controls. Beyond applications directly involving finance and payment card transactions, PCI-DSS controls are currently seeing increased adoption across other industries, as the recognized “gold standard” for security practices.

“We remain proactive in ensuring the data technologies we deliver for enterprise customers are always held to the highest security standards,” said Ben Slater, Chief Product Officer, Instaclustr. “Instaclustr-managed Elasticsearch now joins our Cassandra and Kafka solutions in achieving PCI-DSS certification. Also, in addition to meeting PCI-DSS compliance for customers who require it, new security enhancements we’ve implemented will result in improved levels of security for all of our managed service customers, regardless of product or platform they are leveraging.”

With the re-certification of Managed Cassandra and Managed Kafka, the following enhancements have also been made:

— Private Network Clusters are now optional.
— Console SSO is supported.
— Requirements for cardholder data encryption have been revised to now only require encryption of the Primary Account Number (PAN). This is significant for Elasticsearch, as it allows additional flexibility for customers; for example, to search by customer name in Kibana.

Additionally, when looking at Kibana specifically, Instaclustr supports connecting customers’ Instaclustr-provisioned Kibana instance to an Open Identity Connect (OIDC) SSO provider, which provides an enhanced user experience.

Enterprises requiring full PCI-DSS compliance can opt-in when creating an Elasticsearch cluster on the Instaclustr managed platform to enable the required security options (for example, password complexity in the Instaclustr console). There are additional customer responsibilities involved to achieve full compliance. For more detailed information, please see the Instaclustr support page.

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more