Features
AWS security findings in plain English
A Security Hub finding such as ‘S3.8 S3 general purpose buckets should block public access’ tells an engineer what failed. It does not tell a founder whether customer data is exposed. bearhug rewrites every finding into three answers: what is wrong, why it matters to your business, and exactly how to fix it. Engineers can switch to the technical view with one toggle.
Try it: switch the findings list between the friendly and technical views.
How plain-English findings work
bearhug receives findings from AWS Security Hub and Amazon GuardDuty in your connected accounts. Each finding arrives in the format AWS publishes: a control ID, a title written for security specialists and a resource ARN. bearhug keeps all of that detail and adds a plain-English version alongside it.
The plain-English view answers three questions for every finding: what is wrong, why it matters to your business, and exactly how to fix it. Region codes become place names, so eu-west-2 becomes London, and resource identifiers become descriptions such as ‘AWS S3 Bucket’. One toggle switches the dashboard between the friendly view and the technical view, so engineers and non-technical colleagues can look at the same finding in the language that suits them.
Before and after: one real finding
Here is the same AWS Security Hub finding in each view. The technical view is what AWS reports. The plain-English view is what bearhug shows by default.
Both views describe the same risk. The difference is that anyone in your business can read the second one and understand why it matters.
Why teams use plain-English findings
Everyone understands the risk
Founders, product managers and account managers can read a finding and understand whether it matters, without asking an engineer to translate it.
Faster prioritisation
When every finding explains its business impact, it is easier to decide what to fix today and what can wait until next sprint.
Evidence you can share
Share your security posture with your board, investors or customers in language they understand, which helps with security questionnaires and due diligence.
Related guide
Read our guide: AWS Security Hub findings explained in plain English.
Plain-English findings questions
No. The technical view keeps the original Security Hub or GuardDuty finding, including the control title, resource ARN and AWS region. Switch between the two views with one toggle at any time.
Every finding that bearhug receives from AWS Security Hub and Amazon GuardDuty in your connected accounts is available in both the plain-English view and the technical view.
No. The plain-English view is written for people without a security background. It tells you what is wrong, why it matters and how to fix it, and many findings can be fixed in one click.
Explore more bearhug features
Read your AWS security findings in plain English
Connect your AWS account in under five minutes, and your first findings, explained, follow as Security Hub completes its first checks, usually within a couple of hours. 14-day free trial. The paid plan is $100 per AWS account per month.
No credit card. No procurement. Starts from your AWS console.