AWS Security Hub Room for Improvement

NK
Senior Cloud Cybersecurity Engineer at Societe Generale

Adding SIEM features would be beneficial because of the limited customization of AWS Security Hub. 

View full review »
Shashank N - PeerSpot reviewer
Security Engineer-DevSecOps at a computer software company with 51-200 employees

It's not user-friendly. Too much going on, too many unnecessary findings, not very visual. You can't do much compared to other similar tools that are cheaper and better.

There's this company called PingSafe, just acquired by SentinelOne, that has a great cloud security offering. Prisma Cloud is also a better alternative.

View full review »
Yusuf-Hashmi - PeerSpot reviewer
Sr. Director - Group Head - IT Security (CISO) at Jubilant Organosys Ltd., India, Leading Chemical M

The telemetry doesn't always go into the control center. When you have multiple instances running in AWS, you need a control tower to take feeds from Security Hub and analyze your results. Sometimes exemptions aren't passed between the control tower and Security Hub. The configuration gets mixed up or you don't get the desired results. 

View full review »
Buyer's Guide
AWS Security Hub
April 2024
Learn what your peers think about AWS Security Hub. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,740 professionals have used our research since 2012.
AH
Company Director at HYMH

There is room for improvement in a couple of things. One is that the dashboard isn't very customizable. Another is that the alerting level is the same across the entire account. Every organization has different needs, like sandbox accounts. Even though they have the same alert level, it might not be critical for them.

Security needs to be measured based on their own criteria. We can't add custom criteria specific to our organization. For example, having an S3 bucket publicly available might be flagged as a critical alert, but it might not be critical in a sandbox environment. 

So, it gets flagged as critical, which becomes a false positive. So, customization options and creating custom dashboards would be areas for improvement.

View full review »
Ankit Kumar - PeerSpot reviewer
Cloud Security Lead at CoinSwitch

Although AWS Security Hub does a periodic scan of your overall infrastructure, it doesn't do it in real time.

Real-time scanning should be included in the solution’s next release.

View full review »
UU
Manager - Cyber Security and SOC at Continental Tire

It's a dependent platform. It is not flexible for multi-cloud environments. They should add features for cloud diagnosis to analyze logs from the cloud in a standardized format. Additionally, its integration capabilities with external systems could be improved.

View full review »
HM
CVO at Megaaisec

One aspect that could be improved in the solution is its adaptability to different markets and geopolitical restrictions. In certain regions like Thailand, specific services from certain countries or providers, such as AWS or Azure, might be limited or blocked. It also needs improvement in would require configuring the solution more adaptable to AWS infrastructure and function.


View full review »
Ekule Mbeng - PeerSpot reviewer
DevOps Engineer at United Vision

AWS Security Hub should improve the time it takes to update. It takes a long period of time when updating. It can take 24 hours sometimes to update. Additionally, when integrating this solution with more security tools, takes time.

View full review »
Rajguru Patil - PeerSpot reviewer
Associate cloud solution architect at BlazeClan Technologies

The support must be quicker.

View full review »
SumeshKumar - PeerSpot reviewer
Manager Cloud Security at Hitachi Systems, Ltd.

From an improvement perspective, there is a need to add more compliance since, right now, AWS Security Hub only provides four to five compliances to control the tool. It should be made possible to integrate some of the other tools with AWS Security Hub so that it can give you complete visibility of the product.

AWS Security Hub needs a lot of improvement since it is a native tool meant for AWS products only. For providing compliance, a number of tools are available in the market to take care of the protection part.

In the future, AWS needs to implement a single dashboard and make different kinds of modules available. To use it as a CSPM tool, you must go with AWS Security Hub, Amazon Inspector, and AWS Config. AWS Security Hub needs to introduce a single dashboard that allows a security person to go and log in, see the status, and take action if necessary.

View full review »
SS
Senior Software Engineer at a media company with 11-50 employees

We are facing some cost-related issues with the solution. We integrated a couple of services into AWS Security Hub, and some rules are not required for our environment. However, the assessment happens based on those rules, and we have to pay some additional costs.

We need some customization into the compliances whenever we enable specific compliances. We need more granular-level customizations to enable or disable the rules in AWS Security Hub.

Suppose we enabled one of the compliances and have more than 100 rules for that compliance. If one of the customers is not using all the services, those services are not really used in the environment. We are looking for some customizations to disable that rule so that the scanning will not happen based on that rule, and we can save some cost.

View full review »
Gustavo Lichti - PeerSpot reviewer
Chief Information Security Officer at OITI

AWS Security Hub's configuration and integration are areas where it lacks and needs to improve.

View full review »
VK
Cloud & DevOps Engineer at NSEARCH

Right now, there are some difficulties we're facing with AWS Security Hub, and we need our central team to mitigate the issues. Otherwise, the number of incidents will keep increasing, and monitoring will become problematic.

For example, whenever my team gets some alarms from the central team, my team needs to initiate whether it's a real or false trigger. The central team needs to keep adjusting to the parameters or at least the concerned IPs, whether it's really from the company's pool of IPs, so the trigger process can be improved.

In the next release of AWS Security Hub, I'd like a better dashboard that could result in better alert visibility.

View full review »
VP
Manager-Cloud Security Operations at a retailer with 10,001+ employees

AWS Security Hub could improve by having more integration and flexibility with other cloud security solutions on the market. They have integration with AWS solutions and other commercial solutions but not ones that are open-source. If we have more of an open-source integration availability it would be great. 

The user interface, graphs, and dashboards of the solution could improve in the future. They are not very sophisticated and could use an update.

View full review »
AC
EMEA Sales Engineer- System Integrators & Service Providers at a computer software company with 10,001+ employees

I think post-share management can be extended further, closer to the data. The solution is not wholly self-sufficient. It would be great if they could make it a multi-cloud solution.

View full review »
AK
Engineering Manager Technology at Nykaa

The solution will only give you insight if you have configure rule enabled. It should work more like Prisma Cloud and Dome9 which have a better approach. 

The product should not be a region restriction product. It should be global. It should give you the visibility of all the instances that you have for one account, be it in one region or many regions. There should be visibility of all the region in one place.

View full review »
Buyer's Guide
AWS Security Hub
April 2024
Learn what your peers think about AWS Security Hub. Get advice and tips from experienced pros sharing their opinions. Updated: April 2024.
768,740 professionals have used our research since 2012.