Managed multicloud CSPM for AWS and Azure: run Security Hub without hiring a security team (2026)

AWS Security Hub now scans Azure at AWS-equivalent prices. eCorpIT runs the multicloud CSPM for teams without a security engineer.

Read time
10 min
Word count
1.4K
Sections
10
FAQs
8
Share
Two cloud shapes joined under a shield of light, representing managed multicloud security posture
eCorpIT runs AWS and Azure security posture from one worked findings queue.
On this page · 10 sections
  1. The problem a new AWS feature just exposed
  2. What the Security Hub Azure support actually covers
  3. The honest buy-versus-build math
  4. What eCorpIT's managed multicloud CSPM service does
  5. Where Security Hub multicloud fits against the alternatives
  6. Engagement model and who it is for
  7. India-specific considerations
  8. FAQ
  9. How eCorpIT can help
  10. References

Summary. On July 14, 2026 AWS extended Security Hub to Microsoft Azure, so it now discovers Azure Virtual Machines, container images, Function Apps, and identities, checks them for misconfiguration, internet exposure, and vulnerabilities, and runs the CIS Microsoft Azure Foundations Benchmark, all priced at the same rates as the equivalent AWS resources with a 30-day free trial. Security Hub Essentials lists at $3.75 per resource unit in us-east-1. The tooling is now cheap and native. The unsolved part is human: a findings queue that nobody triages is worse than no tool, because it manufactures false comfort. eCorpIT, an ISO 27001:2022 certified, CMMI Level 5 technology company founded in 2021 in Gurugram, runs multicloud cloud security posture management for teams that have the two clouds but not the dedicated security engineer. This article covers what the new Security Hub capability does, the honest buy-versus-build math, and how a managed engagement works.

The problem a new AWS feature just exposed

Cloud security posture management, or CSPM, continuously checks cloud resources for risky configuration, exposure, and known vulnerabilities. For years teams ran it per cloud in separate consoles. The Security Hub update folds Azure into the AWS console. Michael Fuller, who leads product for AWS Security Services, wrote in the AWS announcement that customers "have been clear with us that they want Security Hub to also cover the rest of their estate," starting with Azure.

That lowers the tooling barrier close to zero for AWS-centric teams. It does not lower the operational one. A CSPM produces findings continuously, and each finding needs someone to judge whether it matters, find the owner, and get it fixed or formally accepted. Most mid-market teams running AWS and Azure do not have a person whose job is that queue. The findings pile up, the noise trains everyone to ignore the dashboard, and the exposed storage bucket sits open anyway. The tool did its job; the program did not.

We wrote the technical companion to this piece, a full AWS Security Hub multicloud CSPM setup and decision guide, for teams who want to run it themselves. This article is for teams deciding whether to.

What the Security Hub Azure support actually covers

The coverage is scoped and worth knowing before you plan around it.

Azure resource What Security Hub evaluates AWS-equivalent billing unit
Virtual Machines Misconfiguration, internet exposure, vulnerabilities Like an EC2 instance (1 unit)
Container images Known software vulnerabilities Like an ECR image (1/18 unit)
Function Apps Misconfiguration and exposure Like a Lambda function (1/12 unit)
Identities Posture and access risk Like an IAM user or role (1/125 unit)
All of the above CIS Microsoft Azure Foundations Benchmark checks Priced same as equivalent AWS resources

Two constraints shape a rollout. Azure findings evaluate in near-real time because AWS built the feature on AWS Config, which now reads across clouds, rather than a once-a-day poll. And per AWS documentation, the CIS Azure benchmark cannot be placed inside a Security Hub configuration policy; you enable it with local configuration directly in the AWS account, which changes how you script a multi-account rollout. Neither is a blocker; both are the kind of detail that turns a one-day job into a one-week job if you meet them for the first time in production.

The honest buy-versus-build math

The decision is not really about the tool, which is inexpensive and native. It is about who owns the outcome.

Factor Run it in-house eCorpIT managed multicloud CSPM
Enablement Your team enables Security Hub and Azure in the 30-day trial We enable and validate inside the trial window
Azure onboarding and CIS benchmark You wire subscriptions and local configuration Configured per subscription for you
Findings triage Your engineers judge and chase every finding We triage, suppress noise, and escalate criticals
Automation You build the response rules Shared AWS and Azure response rules configured
Reporting You build dashboards and evidence Monthly posture and remediation report
Tool cost AWS bills you directly at $3.75 per resource unit Passed through; the managed fee is separate
Best fit Teams with a dedicated cloud-security engineer Teams without one

If you have an engineer who owns the queue, run it yourself; the tool is now good enough that a separate product is hard to justify for a secondary Azure estate. If you do not, a managed engagement is the difference between coverage and the appearance of coverage.

What eCorpIT's managed multicloud CSPM service does

We run the posture program end to end on the tooling you already pay AWS for. In practice that means five things. We enable Security Hub in your primary AWS security account and connect your Azure subscriptions during the free-trial window, so you see real findings and real spend before committing. We configure the CIS Microsoft Azure Foundations Benchmark through local configuration, since it cannot go in a policy. We wire Azure and AWS findings into shared automation so a critical exposure raises the same ticket regardless of which cloud it came from. We work the queue: triage, suppress the rules that do not apply to your architecture, chase owners, and verify fixes. And we report monthly on posture trend and what was remediated, in language a board can read.

As an AWS and Microsoft partner and an ISO 27001:2022 certified, CMMI Level 5 organisation founded in 2021, eCorpIT runs this with senior-led, multi-disciplinary teams rather than a single named contact. The service is deliberately scoped to security posture. If your priority is cloud cost rather than exposure, that is a different engagement, our cloud and FinOps managed service; if it is securing AI agents specifically, see our AI agent security guardrails service; and if you are still moving workloads between clouds, start with cloud migration and modernization.

Where Security Hub multicloud fits against the alternatives

Security Hub joining the multicloud field does not end the CSPM decision; it reframes it for AWS-centric teams.

Vector AWS Security Hub multicloud Microsoft Defender for Cloud Dedicated CSPM (for example Wiz)
Home console AWS Security Hub Azure portal Vendor console
Azure coverage VMs, containers, Function Apps, identities; CIS benchmark Deep, Azure-native Agentless, broad multicloud
AWS coverage Native Via Defender for Servers with the Arc agent Agentless
Attack-path analysis Finding correlation, exposure findings Azure-centric Security Graph, a market benchmark
Pricing model Per resource unit; Azure same as AWS Free CSPM tier plus paid plans Enterprise contract
Best fit AWS-centric teams adding Azure Microsoft-aligned teams Multicloud-first security teams

We are not tied to one answer. If your center of gravity is Azure, Microsoft Defender for Cloud with its native depth and free CSPM tier may be the better base, and we will say so. If you need agentless breadth and graph-based attack-path analysis across many clouds, a dedicated platform such as Wiz earns its price. Security Hub multicloud is the pragmatic pick when AWS is already your primary console. The managed service adapts to whichever base fits your estate.

Engagement model and who it is for

The engagement is a fixed monthly managed fee scoped to the size of your estate, sitting on top of the AWS bill you continue to pay directly at the per-resource-unit rate. We keep the tool cost transparent and separate from our fee, so you always see what AWS charges versus what the managed service costs. It suits a mid-market company or a funded startup running production workloads across AWS and Azure, with a compliance obligation or a customer-security questionnaire to answer, and without a full-time cloud-security hire. It is not for a team that already has a security operations function; that team should run Security Hub themselves using our decision guide.

India-specific considerations

For Indian teams the tool cost bills in dollars, so the weak rupee matters. At roughly 96 rupees to the dollar in late July 2026, the $3.75 per-resource-unit AWS rate and any usage add-ons convert upward, which makes disciplined scoping of what you monitor a cost lever as much as a security one. On compliance, the Digital Personal Data Protection Act 2023 expects reasonable security safeguards over personal data, and a misconfigured, internet-exposed resource is a common route to a reportable breach. eCorpIT designs and operates cloud posture aligned with DPDP requirements, and our ISO 27001:2022 certification reflects an information-security management system we run in-house. Unified AWS and Azure posture monitoring is one control that supports a DPDP-aligned security story without overclaiming a certification the tool itself provides.

FAQ

How eCorpIT can help

eCorpIT runs multicloud cloud security posture management for AWS and Azure teams that have the clouds but not the security engineer. We enable Security Hub multicloud inside the free-trial window, configure the CIS Azure benchmark, wire shared AWS and Azure automation, work the findings queue, and report monthly, on the tooling you already pay AWS for. As an ISO 27001:2022 certified, CMMI Level 5 AWS and Microsoft partner founded in 2021 in Gurugram, we run it with senior-led teams. To scope a managed posture engagement, contact eCorpIT.

References

  1. AWS Security Blog, Michael Fuller, "Security Hub adds AI workload protection and multicloud support for Microsoft Azure," July 14, 2026: aws.amazon.com/blogs/security
  1. AWS, "AWS Security Hub supports monitoring Microsoft Azure" (What's New): aws.amazon.com/about-aws/whats-new
  1. AWS Security Hub, "Pricing": aws.amazon.com/security-hub/pricing
  1. AWS Security Hub, "Creating and associating configuration policies" (docs): docs.aws.amazon.com/securityhub
  1. Help Net Security, "AWS retools Security Hub for AI and multicloud threats," July 15, 2026: helpnetsecurity.com
  1. The New Stack, "AWS will now watch Microsoft's cloud for you": thenewstack.io/aws-security-hub-azure
  1. Constellation Research, "AWS fleshes out Security Hub with AI workload protection, Microsoft Azure support": constellationr.com
  1. Arnav, "Wiz vs Microsoft Defender for Cloud," June 27, 2026: arnav.au
  1. SiliconANGLE, "AWS turns Security Hub into an AI and multicloud security control plane," July 22, 2026: siliconangle.com
  1. Exchange Rates UK, "US Dollar to Indian Rupee spot exchange rates history 2026": exchangerates.org.uk

_Last updated: July 29, 2026._

Frequently asked

Quick answers.

01 What is multicloud CSPM and why does it matter now?
Cloud security posture management continuously checks cloud resources for misconfiguration, exposure, and vulnerabilities. It matters now because on July 14, 2026 AWS Security Hub began scanning Microsoft Azure next to AWS at AWS-equivalent prices, so a single console can cover both clouds. The tooling barrier fell; acting on the findings is the remaining work.
02 What does AWS Security Hub cover on Azure?
Security Hub discovers Azure Virtual Machines, container images, Function Apps, and identities, then evaluates them for misconfiguration, internet exposure, and vulnerabilities, with CIS Microsoft Azure Foundations Benchmark posture checks. Azure findings appear next to AWS findings in the same format, automation, and workflows, priced at the same rates as equivalent AWS resources with a 30-day trial.
03 Should we run Security Hub ourselves or use a managed service?
Run it yourself if you have a security engineer who owns the findings queue; the tool is cheap and native enough to make that reasonable. Use a managed service if no one in-house will triage findings daily, because an unworked queue creates false comfort rather than real coverage. The decision is about ownership, not the tool.
04 How is eCorpIT's service different from buying a CSPM product?
A product gives you findings; our service works them. eCorpIT enables Security Hub multicloud, configures the CIS Azure benchmark, wires AWS and Azure findings into shared automation, triages and remediates, and reports monthly. You keep paying AWS directly for the tool at the per-resource-unit rate; our managed fee covers the people and process on top.
05 Is eCorpIT certified for security work?
eCorpIT is ISO 27001:2022 certified and assessed at CMMI Level 5, and is an AWS and Microsoft partner. We design and operate cloud posture aligned with frameworks such as the DPDP Act 2023, and we describe that as alignment rather than claiming a certification we do not hold. For personal-data workloads we combine posture monitoring with DPDP-aligned data handling.
06 How much does the tooling cost?
AWS Security Hub Essentials lists at $3.75 per resource unit in us-east-1, where an EC2 instance is 1 unit, a Lambda function 1/12, a container image 1/18, and an IAM user or role 1/125, and AWS prices Azure resources at the same rates. Rates vary by region. Our managed fee is separate and scoped to your estate size.
07 Can you cover clouds beyond AWS and Azure?
Security Hub covers Azure today, with AWS stating that more clouds will follow. Where a cloud is not yet covered natively, we combine Security Hub with the appropriate native tool, such as Microsoft Defender for Cloud for deep Azure needs, and manage the combined posture. The goal is one worked queue, not one vendor.
08 Who is this service for?
It fits mid-market companies and funded startups running production workloads across AWS and Azure, with a compliance obligation or customer-security questionnaire to satisfy, and without a full-time cloud-security hire. Teams that already run a security operations function should enable Security Hub themselves using our companion decision guide rather than engage a managed service.

About the author

Manu Shukla

Founder & Director

Founder of eCorpIT. Hands-on engineer leading senior-only delivery for AI apps, custom software, and cloud systems for global clients.

Subscribe

One engineering note a week. No fluff, no spam.

Senior-architect playbooks on AI agents, mobile apps, cloud, security, data, and marketing — delivered every Wednesday.

Past the reading

Read enough. Let's build something.

A senior architect responds in 24 working hours with scope, indicative cost, and a timeline. NDA before any technical conversation.