On this page · 10 sections
- The problem a new AWS feature just exposed
- What the Security Hub Azure support actually covers
- The honest buy-versus-build math
- What eCorpIT's managed multicloud CSPM service does
- Where Security Hub multicloud fits against the alternatives
- Engagement model and who it is for
- India-specific considerations
- FAQ
- How eCorpIT can help
- References
Summary. On July 14, 2026 AWS extended Security Hub to Microsoft Azure, so it now discovers Azure Virtual Machines, container images, Function Apps, and identities, checks them for misconfiguration, internet exposure, and vulnerabilities, and runs the CIS Microsoft Azure Foundations Benchmark, all priced at the same rates as the equivalent AWS resources with a 30-day free trial. Security Hub Essentials lists at $3.75 per resource unit in us-east-1. The tooling is now cheap and native. The unsolved part is human: a findings queue that nobody triages is worse than no tool, because it manufactures false comfort. eCorpIT, an ISO 27001:2022 certified, CMMI Level 5 technology company founded in 2021 in Gurugram, runs multicloud cloud security posture management for teams that have the two clouds but not the dedicated security engineer. This article covers what the new Security Hub capability does, the honest buy-versus-build math, and how a managed engagement works.
The problem a new AWS feature just exposed
Cloud security posture management, or CSPM, continuously checks cloud resources for risky configuration, exposure, and known vulnerabilities. For years teams ran it per cloud in separate consoles. The Security Hub update folds Azure into the AWS console. Michael Fuller, who leads product for AWS Security Services, wrote in the AWS announcement that customers "have been clear with us that they want Security Hub to also cover the rest of their estate," starting with Azure.
That lowers the tooling barrier close to zero for AWS-centric teams. It does not lower the operational one. A CSPM produces findings continuously, and each finding needs someone to judge whether it matters, find the owner, and get it fixed or formally accepted. Most mid-market teams running AWS and Azure do not have a person whose job is that queue. The findings pile up, the noise trains everyone to ignore the dashboard, and the exposed storage bucket sits open anyway. The tool did its job; the program did not.
We wrote the technical companion to this piece, a full AWS Security Hub multicloud CSPM setup and decision guide, for teams who want to run it themselves. This article is for teams deciding whether to.
What the Security Hub Azure support actually covers
The coverage is scoped and worth knowing before you plan around it.
| Azure resource | What Security Hub evaluates | AWS-equivalent billing unit |
|---|---|---|
| Virtual Machines | Misconfiguration, internet exposure, vulnerabilities | Like an EC2 instance (1 unit) |
| Container images | Known software vulnerabilities | Like an ECR image (1/18 unit) |
| Function Apps | Misconfiguration and exposure | Like a Lambda function (1/12 unit) |
| Identities | Posture and access risk | Like an IAM user or role (1/125 unit) |
| All of the above | CIS Microsoft Azure Foundations Benchmark checks | Priced same as equivalent AWS resources |
Two constraints shape a rollout. Azure findings evaluate in near-real time because AWS built the feature on AWS Config, which now reads across clouds, rather than a once-a-day poll. And per AWS documentation, the CIS Azure benchmark cannot be placed inside a Security Hub configuration policy; you enable it with local configuration directly in the AWS account, which changes how you script a multi-account rollout. Neither is a blocker; both are the kind of detail that turns a one-day job into a one-week job if you meet them for the first time in production.
The honest buy-versus-build math
The decision is not really about the tool, which is inexpensive and native. It is about who owns the outcome.
| Factor | Run it in-house | eCorpIT managed multicloud CSPM |
|---|---|---|
| Enablement | Your team enables Security Hub and Azure in the 30-day trial | We enable and validate inside the trial window |
| Azure onboarding and CIS benchmark | You wire subscriptions and local configuration | Configured per subscription for you |
| Findings triage | Your engineers judge and chase every finding | We triage, suppress noise, and escalate criticals |
| Automation | You build the response rules | Shared AWS and Azure response rules configured |
| Reporting | You build dashboards and evidence | Monthly posture and remediation report |
| Tool cost | AWS bills you directly at $3.75 per resource unit | Passed through; the managed fee is separate |
| Best fit | Teams with a dedicated cloud-security engineer | Teams without one |
If you have an engineer who owns the queue, run it yourself; the tool is now good enough that a separate product is hard to justify for a secondary Azure estate. If you do not, a managed engagement is the difference between coverage and the appearance of coverage.
What eCorpIT's managed multicloud CSPM service does
We run the posture program end to end on the tooling you already pay AWS for. In practice that means five things. We enable Security Hub in your primary AWS security account and connect your Azure subscriptions during the free-trial window, so you see real findings and real spend before committing. We configure the CIS Microsoft Azure Foundations Benchmark through local configuration, since it cannot go in a policy. We wire Azure and AWS findings into shared automation so a critical exposure raises the same ticket regardless of which cloud it came from. We work the queue: triage, suppress the rules that do not apply to your architecture, chase owners, and verify fixes. And we report monthly on posture trend and what was remediated, in language a board can read.
As an AWS and Microsoft partner and an ISO 27001:2022 certified, CMMI Level 5 organisation founded in 2021, eCorpIT runs this with senior-led, multi-disciplinary teams rather than a single named contact. The service is deliberately scoped to security posture. If your priority is cloud cost rather than exposure, that is a different engagement, our cloud and FinOps managed service; if it is securing AI agents specifically, see our AI agent security guardrails service; and if you are still moving workloads between clouds, start with cloud migration and modernization.
Where Security Hub multicloud fits against the alternatives
Security Hub joining the multicloud field does not end the CSPM decision; it reframes it for AWS-centric teams.
| Vector | AWS Security Hub multicloud | Microsoft Defender for Cloud | Dedicated CSPM (for example Wiz) |
|---|---|---|---|
| Home console | AWS Security Hub | Azure portal | Vendor console |
| Azure coverage | VMs, containers, Function Apps, identities; CIS benchmark | Deep, Azure-native | Agentless, broad multicloud |
| AWS coverage | Native | Via Defender for Servers with the Arc agent | Agentless |
| Attack-path analysis | Finding correlation, exposure findings | Azure-centric | Security Graph, a market benchmark |
| Pricing model | Per resource unit; Azure same as AWS | Free CSPM tier plus paid plans | Enterprise contract |
| Best fit | AWS-centric teams adding Azure | Microsoft-aligned teams | Multicloud-first security teams |
We are not tied to one answer. If your center of gravity is Azure, Microsoft Defender for Cloud with its native depth and free CSPM tier may be the better base, and we will say so. If you need agentless breadth and graph-based attack-path analysis across many clouds, a dedicated platform such as Wiz earns its price. Security Hub multicloud is the pragmatic pick when AWS is already your primary console. The managed service adapts to whichever base fits your estate.
Engagement model and who it is for
The engagement is a fixed monthly managed fee scoped to the size of your estate, sitting on top of the AWS bill you continue to pay directly at the per-resource-unit rate. We keep the tool cost transparent and separate from our fee, so you always see what AWS charges versus what the managed service costs. It suits a mid-market company or a funded startup running production workloads across AWS and Azure, with a compliance obligation or a customer-security questionnaire to answer, and without a full-time cloud-security hire. It is not for a team that already has a security operations function; that team should run Security Hub themselves using our decision guide.
India-specific considerations
For Indian teams the tool cost bills in dollars, so the weak rupee matters. At roughly 96 rupees to the dollar in late July 2026, the $3.75 per-resource-unit AWS rate and any usage add-ons convert upward, which makes disciplined scoping of what you monitor a cost lever as much as a security one. On compliance, the Digital Personal Data Protection Act 2023 expects reasonable security safeguards over personal data, and a misconfigured, internet-exposed resource is a common route to a reportable breach. eCorpIT designs and operates cloud posture aligned with DPDP requirements, and our ISO 27001:2022 certification reflects an information-security management system we run in-house. Unified AWS and Azure posture monitoring is one control that supports a DPDP-aligned security story without overclaiming a certification the tool itself provides.
FAQ
How eCorpIT can help
eCorpIT runs multicloud cloud security posture management for AWS and Azure teams that have the clouds but not the security engineer. We enable Security Hub multicloud inside the free-trial window, configure the CIS Azure benchmark, wire shared AWS and Azure automation, work the findings queue, and report monthly, on the tooling you already pay AWS for. As an ISO 27001:2022 certified, CMMI Level 5 AWS and Microsoft partner founded in 2021 in Gurugram, we run it with senior-led teams. To scope a managed posture engagement, contact eCorpIT.
References
- AWS Security Blog, Michael Fuller, "Security Hub adds AI workload protection and multicloud support for Microsoft Azure," July 14, 2026: aws.amazon.com/blogs/security
- AWS, "AWS Security Hub supports monitoring Microsoft Azure" (What's New): aws.amazon.com/about-aws/whats-new
- AWS Security Hub, "Pricing": aws.amazon.com/security-hub/pricing
- AWS Security Hub, "Creating and associating configuration policies" (docs): docs.aws.amazon.com/securityhub
- Help Net Security, "AWS retools Security Hub for AI and multicloud threats," July 15, 2026: helpnetsecurity.com
- The New Stack, "AWS will now watch Microsoft's cloud for you": thenewstack.io/aws-security-hub-azure
- Constellation Research, "AWS fleshes out Security Hub with AI workload protection, Microsoft Azure support": constellationr.com
- Arnav, "Wiz vs Microsoft Defender for Cloud," June 27, 2026: arnav.au
- SiliconANGLE, "AWS turns Security Hub into an AI and multicloud security control plane," July 22, 2026: siliconangle.com
- Exchange Rates UK, "US Dollar to Indian Rupee spot exchange rates history 2026": exchangerates.org.uk
_Last updated: July 29, 2026._