re:Invent 2018: AWS Security Hub and Control Tower Previews Change Multi-Account Security
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
At re:Invent in November 2018, AWS announced previews of two services that reshaped multi-account security: AWS Security Hub and AWS Control Tower.
AWS Security Hub
Security Hub aggregated findings from GuardDuty, Inspector, Macie and partner products into a single view, and ran automated compliance checks against standards such as the CIS AWS Foundations Benchmark. Later it added the AWS Foundational Security Best Practices standard, PCI DSS and NIST checks, plus cross-account and cross-region aggregation.
AWS Control Tower
Control Tower automated the setup of a multi-account environment — a "landing zone" — based on AWS best practices. It created a management account structure, a log archive account, an audit account, centralized CloudTrail logging, identity through AWS SSO (now IAM Identity Center), and guard rails implemented with SCPs and AWS Config rules.
Why it mattered
AWS had long recommended multiple accounts as security boundaries: separate production from development, isolate workloads, centralize logs where attackers can't erase them. But building that structure by hand was complex. Control Tower made it a guided setup, and Security Hub gave security teams one place to see the results.
In hindsight
Both services became generally available in 2019 and are now core building blocks. The AWS Security Reference Architecture builds on the same model: an organization management account, a security tooling account, a log archive account and separate workload accounts. Organizations that still run everything in one large account face more risk and more work to reach that model — the earlier you adopt it, the easier it is.
- How to Design a Multi-Account AWS Landing Zone With Security Guardrails How-To & Hardening
- AWS Security Hub Standards Triage Checklist How-To & Hardening
- CIO Brief: Why One Big AWS Account Is a Security Liability CIO Briefings