Currently, our organization utilizes AWS for various purposes, including SaaS (Software as a Service), PaaS (Platform as a Service), and hosting applications in the cloud. We develop our applications and use AWS services as a platform for basic functions and secondary development needs. Additionally, we rely on PaaS for accounting services. Approximately, 50% of our applications are hosted in the cloud environment, making it a significant part of our current setup.
Helps to host SaaS and PaaS applications
Pros and Cons
- "Currently, our organization utilizes AWS for various purposes, including SaaS (Software as a Service), PaaS (Platform as a Service), and hosting applications in the cloud. We develop our applications and use AWS services as a platform for basic functions and secondary development needs. Additionally, we rely on PaaS for accounting services. Approximately, 50% of our applications are hosted in the cloud environment, making it a significant part of our current setup."
- "One aspect that could be improved in the solution is its adaptability to different markets and geopolitical restrictions. In certain regions like Thailand, specific services from certain countries or providers, such as AWS or Azure, might be limited or blocked. It also needs improvement in would require configuring the solution more adaptable to AWS infrastructure and function."
What is our primary use case?
What needs improvement?
One aspect that could be improved in the solution is its adaptability to different markets and geopolitical restrictions. In certain regions like Thailand, specific services from certain countries or providers, such as AWS or Azure, might be limited or blocked. It also needs improvement in would require configuring the solution more adaptable to AWS infrastructure and function.
For how long have I used the solution?
I have been using the solution for the past ten years.
What do I think about the stability of the solution?
The stability is good. The solution is considered one of the most stable and reliable cloud platforms globally among the three major cloud service providers.
Buyer's Guide
AWS Security Hub
January 2025
Learn what your peers think about AWS Security Hub. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The scalability is good. It’s better than any other tool available. We have 1000 users for the solution.
How are customer service and support?
In our organization, we rely on third-party support for our cloud operations. We have a local operations team that works with various suppliers to handle our cloud-related support and maintenance needs.
How was the initial setup?
The initial setup was complex. We need 100 technical staff for deployment.
What other advice do I have?
I would definitely recommend this solution to others who are considering using it. While there might be room for improvement in the future to align with evolving technology trends, it has been a good option for us and meets our current business and technological needs. Overall, I rate the solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Devops Specialist at nSearch Global
Easy to implement and has a responsive technical support team, but it needs a better dashboard and improved trigger process
Pros and Cons
- "I like that AWS Security Hub currently has several good features, around four or five. The technical support for AWS Security Hub is also responsive."
- "Whenever my team gets some alarms from the central team, my team needs to initiate whether it's a real or false trigger. The central team needs to keep adjusting to the parameters or at least the concerned IPs, whether it's really from the company's pool of IPs, so the trigger process can be improved. In the next release of AWS Security Hub, I'd like a better dashboard that could result in better alert visibility."
What is our primary use case?
We use AWS Security Hub for monitoring various malware activities, DDoS attacks, and other attacks. We have a dedicated team looking after these constant issues.
What is most valuable?
I like that AWS Security Hub currently has several good features, around four or five. The technical support for AWS Security Hub is also responsive.
The solution is also easy to integrate with AWS Cloud because it's an AWS product. However, if my company goes for a hybrid deployment, it still needs some analysis of whether AWS Security Hub can be easily integrated with hybrid models.
What needs improvement?
Right now, there are some difficulties we're facing with AWS Security Hub, and we need our central team to mitigate the issues. Otherwise, the number of incidents will keep increasing, and monitoring will become problematic.
For example, whenever my team gets some alarms from the central team, my team needs to initiate whether it's a real or false trigger. The central team needs to keep adjusting to the parameters or at least the concerned IPs, whether it's really from the company's pool of IPs, so the trigger process can be improved.
In the next release of AWS Security Hub, I'd like a better dashboard that could result in better alert visibility.
For how long have I used the solution?
I last worked with AWS Security Hub six months ago.
What do I think about the scalability of the solution?
We're not having any issues with AWS Security Hub, scalability-wise. We have multiple accounts on AWS Security Hub, and triggers are generated from the central account. From there, we'll accept the request so that all incidents will be diverted toward the central team that does the monitoring. We'll then receive an alarm if there's been any breach, and accordingly, we'll look into whether the concerned IP is from our set of listed IPs or not. Otherwise, we'll implement them. We're still in the analysis phase for AWS Security Hub, though, so we'll be able to give a more accurate comment on stability after we complete our report.
How are customer service and support?
Currently, I'd say AWS Security Hub technical support is good.
How was the initial setup?
There was no complaint about the implementation of AWS Security Hub. It was easy to implement.
What's my experience with pricing, setup cost, and licensing?
I'm not part of the central team, so I have no information on the pricing for AWS Security Hub.
What other advice do I have?
My company works with AWS Security Hub.
I'm working with the latest version of AWS Security Hub, deployed on the private cloud, AWS.
My team is still evaluating AWS Security Hub, as it's only been six months since my company started using it.
Around fifty to sixty projects use AWS Security Hub. In my project, there's one security staff in charge of maintenance. There'll also be a central team or a complete, dedicated security team that will oversee the maintenance of the AWS Security Hub. That team will have ten to twelve members looking after multiple company accounts.
Though I'm still in the initial evaluation phase for AWS Security Hub, I would recommend it to others because it has good features. Still, you need to understand better the various features available to get the maximum benefits from AWS Security Hub.
My rating for AWS Security Hub is seven out of ten.
My company develops products and onboards customers to AWS Security Hub.
I'm part of the implementation team.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Buyer's Guide
AWS Security Hub
January 2025
Learn what your peers think about AWS Security Hub. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,158 professionals have used our research since 2012.
Chief Information Security Officer at OITI
A stable and scalable cloud-based security management solution that provides security
Pros and Cons
- "Cloudposse is a valuable feature as it guarantees my security."
- "AWS Security Hub's configuration and integration are areas where it lacks and needs to improve."
What is our primary use case?
I have been using the solution for monitoring AWS, and Security Hub helped me view the security of my cloud.
What is most valuable?
Cloudposse is a valuable feature as it guarantees my security.
What needs improvement?
AWS Security Hub's configuration and integration are areas where it lacks and needs to improve.
For how long have I used the solution?
I have been using AWS Security Hub for five years. I am a user of the solution.
What do I think about the stability of the solution?
It is a stable solution.
What do I think about the scalability of the solution?
It is a scalable solution.
How was the initial setup?
The initial setup is easy. It requires little to no maintenance. The solution is deployed on the cloud.
What's my experience with pricing, setup cost, and licensing?
The pricing is fine. It is not an expensive tool.
What other advice do I have?
I rate the overall solution an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager-Cloud Security Operations at a retailer with 10,001+ employees
Excellent integration features, reliable, and responsive technical support
Pros and Cons
- "AWS Security Hub has very good integration features. It allows for AWS native services integration, and it helps us to integrate some of the services outside of AWS. They have partners, such as Amazon Preferred Network Partners (APN). If you have different security tools around APN, we can integrate those findings with AWS Security Hub reducing the need to refer to different portals or different UIs. You can have AWS Security Hub act as a single common go-to dashboard."
- "The user interface, graphs, and dashboards of the solution could improve in the future. They are not very sophisticated and could use an update."
What is our primary use case?
AWS Security Hub helps us in centralizing all the different types of findings we have. We can view all the vulnerability findings, configuration issues, or security best practices. We have a consolidated view of an AWS account from a security point of view which is very good.
What is most valuable?
AWS Security Hub has very good integration features. It allows for AWS native services integration, and it helps us to integrate some of the services outside of AWS. They have partners, such as Amazon Preferred Network Partners (APN). If you have different security tools around APN, we can integrate those findings with AWS Security Hub reducing the need to refer to different portals or different UIs. You can have AWS Security Hub act as a single common go-to dashboard.
What needs improvement?
AWS Security Hub could improve by having more integration and flexibility with other cloud security solutions on the market. They have integration with AWS solutions and other commercial solutions but not ones that are open-source. If we have more of an open-source integration availability it would be great.
The user interface, graphs, and dashboards of the solution could improve in the future. They are not very sophisticated and could use an update.
For how long have I used the solution?
I have been using AWS Security Hub for approximately four years.
What do I think about the stability of the solution?
The solution is stable.
How are customer service and support?
The technical support is good in my experience, they have been prompt with their service.
How was the initial setup?
The initial setup is very easy and straightforward.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is not very competitive but it is reasonable.
What other advice do I have?
I rate AWS Security Hub an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
EMEA Sales Engineer- System Integrators & Service Providers at a computer software company with 10,001+ employees
Provides great detection and real-time alerts; lacks self-sufficiency
Pros and Cons
- "Very good at detection and providing real-time alerts."
- "The solution lacks self-sufficiency."
What is our primary use case?
I'm a user of this solution and a sales engineer.
What is most valuable?
The solution is very good at detection and providing real-time alerts.
What needs improvement?
I think post-share management can be extended further, closer to the data. The solution is not wholly self-sufficient. It would be great if they could make it a multi-cloud solution.
For how long have I used the solution?
I've been using this solution for one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
They provide good technical support.
How was the initial setup?
The initial setup is simple but not overly simple. There is still some work to do there.
What's my experience with pricing, setup cost, and licensing?
I'm satisfied with the pricing.
What other advice do I have?
I would suggest not relying on the cloud provider only. There are other third-party tools that can help with future strategies. Locking into one vendor can create problems and it's a good idea to use security tools from a third party and have multi-hybrid cloud.
I rate the solution seven out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Engineering Manager Technology at Nykaa
Good infrastructure insight, stable, but regional restrictions need lifting
Pros and Cons
- "Finding out if your infrastructure is secure is a valuable feature."
- "The solution will only give you insight if you have configure rule enabled. It should work more like Prisma Cloud and Dome9 which have a better approach."
What is our primary use case?
This solution is for security posture management for the cloud. It will show the security posture of your cloud infrastructure. It can be used for mapping and it can give you a good insight into whether your infrastructure is secure or not.
What is most valuable?
Finding out if your infrastructure is secure is a valuable feature.
What needs improvement?
The solution will only give you insight if you have configure rule enabled. It should work more like Prisma Cloud and Dome9 which have a better approach.
The product should not be a region restriction product. It should be global. It should give you the visibility of all the instances that you have for one account, be it in one region or many regions. There should be visibility of all the region in one place.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the stability of the solution?
I had no issues with the stability of the solution.
How are customer service and technical support?
We have contacted the technical team regarding removing the global restrictions in the product. They have advised us that this is in their roadmap for the future. We have worked with them closely on many issues.
What other advice do I have?
I rate AWS Security Hub a seven out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free AWS Security Hub Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Cloud Security Posture Management (CSPM) Security Orchestration Automation and Response (SOAR)Popular Comparisons
Datadog
Prisma Cloud by Palo Alto Networks
Microsoft Defender for Cloud
Zscaler Zero Trust Exchange Platform
SentinelOne Singularity Cloud Security
Tenable Security Center
VMware Aria Automation
Orca Security
CrowdStrike Falcon Cloud Security
Skyhigh Security
Lacework FortiCNAPP
Check Point CloudGuard CNAPP
Trend Vision One - Cloud Security
Tenable Cloud Security
Buyer's Guide
Download our free AWS Security Hub Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is better - Azure Sentinel or AWS Security Hub?
- AWS Cloud Security Posture tool - has anyone used either Wiz or Ermetic cloud security products and can compare them to AWS Security Hub?
- What are your best practices for Identity and Access Management (IAM) in the Cloud?
- What is the minimum security features set required for Cloud Backup and Storage Software?
- What are your best practices to achieve DevOps security in the cloud?
- Is there a single tool to unify cloud compliance reporting?
- What is Unified Cloud Security? Can you define the scope and use cases of the term?
- What is an Application Security Posture Management (ASPM)?
- Which solutions offer a preventive, proactive approach to cloud security posture management?
- What are the potential PaaS attack vectors in the cloud?