CIO Brief: Why One Big AWS Account Is a Security Liability
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018, it released tools to make that easy. Companies still running everything in a single account carry much more risk.
Why one account is a liability
In a single AWS account, every system shares the same security boundary. A compromised developer credential might reach production. Logs can be deleted by the same people or attackers they are meant to record. Costs and ownership are hard to separate.
The business impact
- Larger blast radius when something goes wrong.
- Harder compliance, because production and test data mix.
- Weaker audit trail, if logs live where attackers can reach them.
Questions to ask your team
- How many AWS accounts do we have, and is production separated from development?
- Are our security logs stored in a separate account that most people can't access?
- Do we use central guard rails that apply to every account automatically?
What good looks like
A structured set of accounts — management, security, logs, shared infrastructure, and separate workload accounts — with central identity, guard rails and logging applied automatically.
The decision
If you run production in a single shared account, fund a landing zone project. It is far easier to do before your environment grows further, and it is the foundation for every other AWS security improvement.
- re:Invent 2018: AWS Security Hub and Control Tower Previews Change Multi-Account Security Platform Changes
- How to Design a Multi-Account AWS Landing Zone With Security Guardrails How-To & Hardening
- AWS Security Hub Standards Triage Checklist How-To & Hardening