Simple Enough Blog logo
  • Home 
  • Projects 
  • Tags 

  •  Language
    • English
    • Français
  1.   Blogs
  1. Home
  2. Blogs
  3. The Invisible Part of the Iceberg: AWS Security Hub

The Invisible Part of the Iceberg: AWS Security Hub

Posted on June 24, 2026 • 6 min read • 1,121 words
Aws   SecurityHub   Helene   Getting-Started  
Aws   SecurityHub   Helene   Getting-Started  
Share via
Simple Enough Blog
Link copied to clipboard

GuardDuty, Macie, Inspector… each AWS service shows only one facet of your security. AWS Security Hub aggregates everything hidden below the surface: findings, compliance standards, and a security score, in a single view. An overview of this centralization service.

On this page
I. What is AWS Security Hub?   II. The problem: the invisible part of the iceberg   III. Key features   The unified format: ASFF   Compliance standards   The security score   IV. Integrations: the heart of the engine   V. Quick start guide   Step 1: Enable the prerequisites   Step 2: Enable Security Hub   Step 3: Centralize multiple accounts (recommended)   Step 4: Aggregate multiple regions   Step 5: Automate the triage   Step 6: Wire up the response   VI. Pricing   VII. Best practices   VIII. Limits and considerations   IX. Conclusion   🔗 Useful links  
The Invisible Part of the Iceberg: AWS Security Hub
Photo by Helene Hemmerter

When we talk about security on AWS, we first think of the visible services: GuardDuty detecting threats, Macie watching sensitive data, Inspector scanning vulnerabilities. These are the tips of the iceberg poking above the water. But beneath the surface lies a far larger mass: hundreds of scattered findings, compliance rules to follow, multiple accounts to correlate. AWS Security Hub is precisely the service that makes that invisible part usable, by gathering it into a single view.


I. What is AWS Security Hub?  

AWS Security Hub is a Cloud Security Posture Management service. Its role isn’t to detect threats itself, but to centralize, normalize, and prioritize the alerts produced by the other security services — whether AWS or third-party.

Concretely, it offers three things:

  • Aggregation of security findings from multiple sources, in a common format.
  • Automated compliance checks against recognized frameworks (AWS, CIS, PCI DSS, NIST).
  • An overall security score, summarizing the state of your environment at a glance.

It’s the control tower above your security services: without it, each service speaks in its own corner.


II. The problem: the invisible part of the iceberg  

On any reasonably serious AWS account, security alerts come from everywhere:

  • GuardDuty flags a suspicious connection;
  • Inspector surfaces a CVE on an EC2 instance;
  • Macie spots an S3 bucket containing personal data;
  • IAM Access Analyzer detects a publicly exposed resource.

Multiply that across multiple accounts and multiple regions, and you get a flood of findings, each in its own dashboard, with its own format. Impossible to know what’s urgent — or even to see everything.

It’s this submerged mass — invisible because it’s scattered — that Security Hub brings to the surface and organizes.


III. Key features  

The unified format: ASFF  

Security Hub normalizes all findings into a common format, the AWS Security Finding Format (ASFF). Whether an alert comes from GuardDuty, Inspector, or a third-party tool, it is described with the same fields (severity, affected resource, type, recommendation). No more heterogeneous formats: everything becomes comparable and filterable.

Compliance standards  

Security Hub continuously runs automated checks against security frameworks:

  • AWS Foundational Security Best Practices (FSBP) — the best practices recommended by AWS;
  • CIS AWS Foundations Benchmark — a recognized hardening standard;
  • PCI DSS, NIST 800-53, etc. — for regulated environments.

Each control is evaluated (passed / failed) and contributes to the score.

The security score  

From the controls, Security Hub computes a compliance percentage per standard and overall. It’s a simple indicator to track over time and present to leadership: “we went from 68% to 91% FSBP compliance this quarter.”


IV. Integrations: the heart of the engine  

Security Hub’s value comes from what it knows how to listen to. Its main sources:

SourceWhat it brings
Amazon GuardDutyThreat detection (suspicious behavior)
Amazon InspectorVulnerabilities (CVEs) on EC2, containers, Lambda
Amazon MacieDiscovery of sensitive data in S3
IAM Access AnalyzerResources exposed or shared too broadly
AWS ConfigConfiguration compliance (the controls engine)
Third-party partnersExternal security tools compatible with ASFF

On the output side, Security Hub can send its findings to Amazon EventBridge (to automate a response), to Amazon Security Lake, or to your ticketing and SIEM tools.

Good to know: Security Hub relies on AWS Config to run its controls. Config must therefore be enabled to benefit from the compliance standards.


V. Quick start guide  

Step 1: Enable the prerequisites  

  1. Log in to the AWS console.
  2. Enable AWS Config in the relevant regions (required for the controls).
  3. Enable the source services you want (GuardDuty, Inspector, Macie…).

Step 2: Enable Security Hub  

  1. Go to Services > Security Hub.
  2. Click Enable Security Hub.
  3. Choose the standards to apply (FSBP, CIS, PCI DSS…).

Step 3: Centralize multiple accounts (recommended)  

If you use AWS Organizations, designate a delegated administrator account for Security Hub. It will aggregate findings from all member accounts — this is where the iceberg metaphor fully makes sense: a single console for the entire organization.

Step 4: Aggregate multiple regions  

Configure cross-region aggregation to bring findings from all your regions back into a primary region.

Step 5: Automate the triage  

Create automation rules to, for example, automatically raise the severity of a finding on a critical resource, or suppress known false positives.

Step 6: Wire up the response  

Through EventBridge, trigger actions on certain findings: SNS notification, a Lambda remediation function, ticket creation.


VI. Pricing  

Security Hub follows a pay-as-you-go model, based mainly on two elements:

  1. Security checks — billed by the number of checks performed per account and per region.
  2. Finding ingestion — the first few thousand events per month are free; beyond that, billing is per ingested finding.

AWS offers a 30-day free trial to assess the volume — and therefore the cost — before committing.

For up-to-date pricing, see: AWS Security Hub Pricing

Cost tip: disable standards you don’t use and limit checks to the regions actually in use. A large part of the bill comes from controls running in unused regions.


VII. Best practices  

  • Enable Config first. Without it, the compliance standards won’t run.
  • Centralize via Organizations. A delegated administrator account avoids navigating account by account.
  • Start with a single standard (FSBP) before stacking others: 100% of one framework beats 40% of four.
  • Treat the score as a trend, not an absolute grade: the goal is progress.
  • Automate the noise. Use automation rules to mute recurring false positives and focus attention on what’s real.
  • Connect the response via EventBridge: a finding with no action doesn’t improve your security.

VIII. Limits and considerations  

  • Security Hub detects nothing on its own: without active source services, the console stays empty. It orchestrates; it doesn’t replace GuardDuty or Inspector.
  • The controls depend on AWS Config: forgetting to enable it skews the score.
  • Aggregation is per region: remember to configure cross-region aggregation so you don’t create a new blind spot.
  • The cost can creep up silently with the number of accounts, regions, and standards: monitor it from the start.

IX. Conclusion  

AWS Security Hub makes no noise: it doesn’t detect, it doesn’t alert on the front line. Its role is quieter, but essential — to reveal and organize that invisible part of your security, the part that, scattered across services, accounts, and regions, always ends up escaping attention. By aggregating findings, measuring compliance, and assigning a score, it turns a chaos of alerts into a readable, steerable security posture.

Enabled alone, GuardDuty or Inspector lights up one facet. Connected to Security Hub, they finally reveal the entire iceberg.


🔗 Useful links  

  • Official AWS Security Hub documentation
  • AWS Security Finding Format (ASFF)
  • AWS Security Hub pricing
  • Available security standards and controls
  • Centralize security with a delegated administrator account
 Which Chart to Choose for Your Data: The Complete Guide
MCP Servers: Integration and Ecosystem 
  • I. What is AWS Security Hub?  
  • II. The problem: the invisible part of the iceberg  
  • III. Key features  
  • IV. Integrations: the heart of the engine  
  • V. Quick start guide  
  • VI. Pricing  
  • VII. Best practices  
  • VIII. Limits and considerations  
  • IX. Conclusion  
  • 🔗 Useful links  
Follow us

We work with you!

   
Copyright © 2026 Simple Enough Blog All rights reserved. | Powered by Hinode.
Simple Enough Blog
Code copied to clipboard