AWSCIO BriefingsRetrospectives

CIO Brief: Why One Big AWS Account Is a Security Liability

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.

The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018, it released tools to make that easy. Companies still running everything in a single account carry much more risk.

Why one account is a liability

In a single AWS account, every system shares the same security boundary. A compromised developer credential might reach production. Logs can be deleted by the same people or attackers they are meant to record. Costs and ownership are hard to separate.

The business impact

  • Larger blast radius when something goes wrong.
  • Harder compliance, because production and test data mix.
  • Weaker audit trail, if logs live where attackers can reach them.

Questions to ask your team

  • How many AWS accounts do we have, and is production separated from development?
  • Are our security logs stored in a separate account that most people can't access?
  • Do we use central guard rails that apply to every account automatically?

What good looks like

A structured set of accounts — management, security, logs, shared infrastructure, and separate workload accounts — with central identity, guard rails and logging applied automatically.

The decision

If you run production in a single shared account, fund a landing zone project. It is far easier to do before your environment grows further, and it is the foundation for every other AWS security improvement.

aws security hub impactSecurity Hub & Control Tower2018

More on this story