AWS CSPM
AWS CSPM built for teams without a security team
Cloud security posture management (CSPM) continuously checks your cloud configuration against security best practice and compliance frameworks, then tells you what to fix. bearhug is a CSPM designed only for AWS and only for teams that do not have a dedicated security engineer.
What is CSPM?
A CSPM tool connects to your cloud accounts and looks for misconfigurations: public storage buckets, over-permissive IAM roles, unencrypted databases and disabled logging. Misconfigurations, not sophisticated attacks, are behind most cloud breaches. A CSPM finds them before someone else does.
CSPM is different from a one-off audit or a penetration test. It runs all the time, so a change made on a Friday afternoon is checked as soon as AWS reports it, rather than at your next annual review. A good CSPM also helps you prioritise. Most AWS accounts have far more findings than a small team can fix at once, so the tool needs to show which ones matter first.
Why bearhug is different from enterprise CSPM
Enterprise CSPM and CNAPP platforms typically start at $20,000+ a year and are built for security teams who triage alerts all day. bearhug keeps the part of CSPM that small teams need and removes the rest.
AWS-only, AWS-native
Built on AWS Security Hub and Amazon GuardDuty, so it uses the checks AWS recommends, with no agents to install.
Plain English by default
Every finding explains what is wrong, why it matters and how to fix it. The technical view is one toggle away.
Priced for small teams
A flat $100 per AWS account per month. No per-asset counting and no sales call.
What bearhug checks
bearhug surfaces the findings from the AWS Security Hub security standards you have enabled, alongside threat detections from Amazon GuardDuty. Depending on the standards you enable, typical checks include:
- S3 bucket exposure: public access, bucket policies and unencrypted connections. Read more about AWS S3 bucket security.
- IAM users and access keys: unused credentials, missing MFA and permissions broader than they need to be.
- Security groups open to the internet: for example SSH or RDP reachable from anywhere.
- Encryption at rest: databases, volumes and storage without encryption.
- CloudTrail and logging: so you always have a record of activity in your account.
- Root account usage: signs that the root user is being used for day-to-day work.
- GuardDuty threat detections: such as unusual API calls or signs of compromised credentials.
Each of these is a common cloud misconfiguration. See the ones we find most often on our AWS misconfiguration scanner page, or read how bearhug works as an AWS security scanner.
Compliance foundations
bearhug maps findings to the controls in SOC 2, ISO 27001, PCI DSS, GDPR and Cyber Essentials, so you can see which issues affect which framework and show progress before an audit.
It is a foundation, not a certification. You still need an auditor to certify you, but you arrive with the AWS configuration issues they look for already found and fixed, and with a trend line that shows your posture improving.
bearhug compared with other CSPM tools
How bearhug compares with an enterprise CSPM platform and with checking AWS yourself.
| bearhug | Enterprise CSPM | DIY / manual | |
|---|---|---|---|
| Plain-English explanations | Yes | No | No |
| One-click remediation | Yes, with rollback | Some | No |
| Compliance mapping | Yes | Yes | No |
| Set-up time | Under five minutes | Weeks | Ongoing |
| Price | $100 per AWS account per month, plus applicable AWS charges | $20,000+ a year | Engineering time |
| Security expertise required | No | Yes | Yes |
For a detailed, sourced comparison of eight tools, read our guide to the best CSPM tools for start-ups.
How to get started
- Connect your AWS account. Deploy the bearhug CloudFormation stack from the onboarding screen. It creates a read-only IAM role and an Amazon EventBridge rule, and enables AWS Security Hub and Amazon GuardDuty.
- See your posture in plain English. Security Hub and GuardDuty findings appear in your dashboard, grouped by severity and resource.
- Fix what matters first. Apply one-click fixes for supported findings and follow step-by-step guidance for the rest.
Read the full details of what bearhug creates and can access on the how it works page.
Who bearhug is for
bearhug is built for teams that run real workloads on AWS but do not have someone whose full-time job is cloud security.
- Start-ups and SMBs running production workloads on AWS
- Engineering teams without a dedicated security engineer
- Companies preparing for SOC 2, ISO 27001 or enterprise security questionnaires
- Teams with separate AWS accounts for production, staging and development
If that sounds like you, read more about AWS security for start-ups.
What to look for in a CSPM tool
Whichever CSPM you choose, these are the questions worth asking before you buy.
- Does it use checks you can trust? Tools built on AWS-native services such as Security Hub use the controls AWS itself recommends.
- Does it prioritise? A list of hundreds of findings is not useful unless the most important ones are obvious.
- Can everyone understand it? Findings written only for security specialists slow everything down in a small team.
- Does it help you fix issues? Remediation, with a way to undo changes, turns findings into progress.
- Is the price predictable? Per-asset and per-workload pricing grows with your infrastructure and is hard to budget for.
- How long does set-up take? Weeks of onboarding is a real cost for a team that is already stretched.
Related guide
Read our guide: The 3 AWS misconfigurations we see in every account.
AWS CSPM questions
bearhug is a focused CSPM for AWS. It does not include workload agents, container scanning or code scanning.
Each AWS account is connected to bearhug separately. Once connected, every account appears in the same multi-account dashboard.
Under five minutes, using a CloudFormation stack that you deploy from the onboarding screen.
No. bearhug builds on Security Hub and makes its findings understandable and actionable. Security Hub stays enabled in your account. See our AWS Security Hub comparison for the details.
bearhug costs $100 per AWS account per month, with every feature included and no per-asset counting. It is billed in USD through AWS Marketplace.
Connect your AWS account in five minutes
14-day free trial. The paid plan is $100 per AWS account per month, billed through AWS Marketplace.
No credit card. No procurement. Starts from your AWS console.