AWS Security Hub Extended: Unified Security with Partner Solutions

San Francisco, CA – Amazon Web Services (AWS) is bolstering its cloud security offerings with the general availability of AWS Security Hub Extended, a new plan designed to streamline enterprise security management. Unveiled initially at AWS re:Invent 2025, the Extended plan aims to simplify the procurement, deployment, and integration of a comprehensive security stack, extending beyond native AWS services to incorporate solutions from a curated selection of AWS partners. This move reflects a growing demand for unified security operations and a more holistic approach to threat detection and response in increasingly complex cloud environments.

The core challenge for many organizations lies in managing a fragmented security landscape, often involving multiple vendors, disparate tools, and complex procurement processes. AWS Security Hub Extended directly addresses this pain point by acting as a central hub for security findings, consolidating data from both AWS services like Amazon GuardDuty and Amazon Inspector, and now, a growing ecosystem of third-party security providers. This unified view allows security teams to prioritize risks more effectively and respond to threats with greater speed and precision. The launch underscores AWS’s commitment to providing a secure, available, and resilient infrastructure, as emphasized by CEO Matt Garman at re:Invent 2025, according to reporting from TechTarget.

With AWS acting as the seller of record, organizations benefit from pre-negotiated, pay-as-you-go pricing, a consolidated billing system, and the elimination of long-term contractual commitments. This simplified procurement model is a significant advantage, reducing administrative overhead and allowing security teams to focus on proactive threat management. AWS Enterprise Support customers gain access to unified Level 1 support, providing a single point of contact for assistance with both AWS and partner solutions. The integration is built upon the Open Cybersecurity Schema Framework (OCSF), ensuring standardized data formatting and seamless aggregation of security findings.

Expanding the Security Perimeter with Partner Integrations

AWS Security Hub Extended currently features integrations with a diverse range of security partners, including 7AI, Britive, CrowdStrike, Cyera, Island, Noma, Okta, Oligo, Opti, Proofpoint, SailPoint, Splunk (a Cisco company), Upwind, and Zscaler. These partnerships cover a broad spectrum of security domains, encompassing endpoint protection, identity and access management, email security, network security, data security, browser security, and cloud security. The curated selection process aims to provide organizations with best-of-breed solutions that complement AWS’s native security capabilities. This approach allows businesses to tailor their security posture to their specific needs and risk profiles, leveraging the expertise of specialized security vendors.

The integration process is designed to be straightforward. Users can access partner solutions directly within the Security Hub console by selecting the “Extended plan” under the “Management” menu. From there, they can review and deploy any combination of curated offerings. Upon subscription, an automated onboarding experience guides users through the setup process with each partner. Consumption-based metering is automatic, and billing is consolidated into the monthly Security Hub invoice, simplifying financial management.

How Security Hub Extended Works in Practice

The power of AWS Security Hub Extended lies in its ability to correlate security findings from multiple sources. Security findings from all participating solutions are emitted in the OCSF schema and automatically aggregated within Security Hub. This provides security teams with a single pane of glass for monitoring their entire security posture, regardless of the underlying tools or vendors. The normalized data format facilitates efficient analysis and allows for the identification of complex threats that might otherwise go unnoticed. For example, a suspicious activity detected by an endpoint detection and response (EDR) solution like CrowdStrike can be correlated with a vulnerability identified by Amazon Inspector, providing a more complete picture of the risk.

This centralized approach to security data also streamlines incident response. Security teams can quickly investigate alerts, identify the root cause of incidents, and capture appropriate remediation steps. The unified view reduces the time and effort required to triage security events, improving overall security effectiveness. The ability to combine AWS and partner security solutions allows organizations to quickly identify and respond to risks that span across different layers of their technology stack, from the cloud infrastructure to the endpoint devices.

Benefits for Security Operations Teams

The benefits of AWS Security Hub Extended extend beyond simplified procurement and consolidated data. The platform also offers several advantages for security operations teams:

  • Reduced Alert Fatigue: By correlating security findings, Security Hub Extended helps to reduce the number of false positives and prioritize the most critical alerts.
  • Improved Visibility: The unified view of security data provides greater visibility into the organization’s overall security posture.
  • Faster Incident Response: Streamlined incident investigation and remediation capabilities accelerate response times.
  • Enhanced Compliance: The platform helps organizations meet regulatory compliance requirements by providing a centralized audit trail of security events.
  • Scalability and Flexibility: The pay-as-you-go pricing model and the ability to add or remove partner solutions as needed provide scalability and flexibility.

Looking Ahead: The Future of Cloud Security

The launch of AWS Security Hub Extended is part of a broader trend towards more integrated and automated security solutions in the cloud. AWS has been actively investing in artificial intelligence (AI) and machine learning (ML) to enhance its security capabilities, as highlighted at re:Invent 2025. The company’s Security Agent, also previewed at the event, leverages AI to proactively secure applications throughout the entire development lifecycle. These advancements reflect a growing recognition that traditional security approaches are no longer sufficient to address the evolving threat landscape.

As organizations continue to migrate to the cloud, the need for robust and comprehensive security solutions will only increase. AWS Security Hub Extended provides a valuable tool for organizations looking to simplify their security management, improve their threat detection capabilities, and protect their critical assets. The platform’s open architecture and integration with a wide range of security partners position it as a key enabler of a more secure and resilient cloud environment. The availability of the Extended plan in all AWS commercial Regions, coupled with flexible pricing options, makes it accessible to organizations of all sizes.

To learn more about enhancing your security posture with AWS Security Hub, visit the AWS Security Hub User Guide. The AWS Security Hub Extended plan is now generally available, offering flexible pay-as-you-go or flat-rate pricing. You can explore the new features and provide feedback through AWS re:Post for Security Hub or through your standard AWS Support channels.

AWS continues to iterate on its security offerings, and further enhancements to Security Hub Extended are expected in the coming months. Stay tuned for updates and new partner integrations as AWS continues to strengthen its commitment to cloud security. The next major update is anticipated to focus on enhanced automation capabilities and deeper integration with other AWS security services.

Leave a Comment