AWS has significantly upgraded its Security Hub platform to address the growing complexity of enterprise security, especially around AI workloads and multicloud environments. This update integrates Microsoft Azure resource monitoring alongside existing AWS capabilities, allowing organizations to manage security risks across both leading cloud providers from a single interface.
Previously focused on cloud security posture management solely within AWS, Security Hub now supports discovery and continuous monitoring of Azure virtual machines, container registries, Function Apps, and identities. It applies vulnerability checks and configuration assessments aligned with the CIS Microsoft Azure Foundations Benchmark. Security findings from Azure appear alongside those from AWS, sharing uniform formats, prioritization, and automated workflows—streamlining security operations by eliminating the need to switch between consoles or manage inconsistent rule sets.
Underpinning this multicloud integration is AWS Config, a service that AWS has extended to evaluate Azure resource changes nearly in real time, a marked improvement over the typical daily polling cycle of most third-party tools. This real-time, event-driven approach enables faster detection of misconfigurations and exposure risks. AWS has designed the integration to be simple, requiring only a one-time, read-only tenant authorization in Azure to begin unified monitoring.
The update also introduces AI-targeted capabilities within Security Hub. GuardDuty AI Protection focuses on securing AI workloads running on AWS, complemented by AI-powered investigations currently in preview. Additionally, Security Hub AI Inventory helps identify and catalog AI assets for better oversight in complex environments. These features acknowledge the rapidly expanding AI attack surface and the need for dedicated defenses in enterprise-grade systems.
In terms of pricing, AWS consolidated previous pricing structures into a straightforward, per-resource-per-month model covering four key resource types: virtual machines, container images, functions, and identities. This pricing applies uniformly across both AWS and Azure resources, reflecting AWS’s intention to make Security Hub a cost-effective, comprehensive solution instead of a patchwork of tools.

