GUIDE

AWS Security Hub is noisy.

August 26, 2026

Noise is the default

AWS Security Hub CSPM runs hundreds of controls across every standard you enable, in every region it is on. A lot of those controls are correct in the abstract and useless in your account: CloudWatch metric-filter alarms you will never build because you use GuardDuty; IAM findings duplicated in every region; CIS checks on services you do not run.

That is not you misconfiguring Hub. AWS now publishes suggested controls to disable specifically “to reduce finding noise and usage costs.” If the vendor is telling you to turn half of it off, the product is aimed at a different operator than “I have two AWS accounts and a day job.”

Suppress vs disable

  • Suppress hides a finding. The control still runs. You still pay the check.
  • Disable the control stops the check. Existing findings archive after a few days. Related Config rules Hub created go away.
  • Disable a whole standard (PCI in a sandbox, NIST everywhere) if you will never map it to a ticket.

Start with global-resource controls outside your home region, then anything for services you do not use, then CloudWatch.1–.7 if GuardDuty is already on. Re-read the list when AWS adds standards — new controls arrive enabled.

When Security Hub is still the right tool

Hub earns its keep when it is an aggregator: GuardDuty, Inspector, Macie, and partner findings in one place, across many accounts, with a delegated admin. If you have an org and someone whose job is to triage that queue, keep it. The new Hub “v2” / simplified pricing is AWS trying to make that layer a default. Fine, if you will actually look at it.

It is the wrong default for “I want to know if production S3 is public.” You will get that finding somewhere in a thousand others, and you will stop opening the console.

A smaller loop

For one or a handful of accounts, a scheduled read-only scan that emails failed checks is a complete product. Prowler can do that if you wire EventBridge + SES yourself (see email yourself a Prowler report). You can also skip Hub’s Config dependency entirely — Config is usually the expensive half.

PostureRadar is that smaller loop as a service: read-only role, every enabled region, a findings email, $39 per account per month, weekly. Most findings include specific console steps and a CLI command. No dashboard.

Related: Public S3 buckets · Stale IAM access keys · Why AWS Config gets expensive