Varonis has announced a new integration with AWS Security Hub, designed to help security teams reduce alert noise and accelerate the protection of sensitive data across AWS and hybrid environments. The integration combines AWS Security Hub findings with Varonis's context on data sensitivity and user behavior to provide a unified risk view and enable automated remediation of misconfigurations.
Varonis integrates its Data Security Platform with AWS Security Hub.
The integration ingests AWS Security Hub findings and adds context on data sensitivity, identity, and user behavior.
It provides a single, unified view of risk across the data estate to cut through alert noise.
Automated remediation capabilities can fix misconfigurations like exposed S3 buckets and stale IAM roles.
The solution delivers end-to-end data security with discovery, classification, posture management, and threat detection.
The goal is to help security teams quickly understand and remediate data exposure risks in the cloud.
Security teams are often overwhelmed by alerts from multiple tools. This integration aims to address that by taking the prioritized findings from AWS Security Hub and enriching them with Varonis's deep context about data sensitivity, user identities, and behavioral patterns. This creates a more actionable, unified view of risk that distinguishes critical threats from benign noise. “By combining powerful insights and critical context on data and how it’s used, customers can quickly understand where data is at risk,” said David Bass, EVP of Engineering and CTO at Varonis.
A key feature of the integration is the ability to automate fixes for common security issues identified in AWS. Varonis can leverage analysis from AWS Security Hub to trigger automated remediation actions. Examples include blocking public access to exposed Amazon S3 buckets, removing stale IAM users and roles, and resolving critical misconfigurations like missing password policies or encryption settings.
The integration extends Varonis's core data security capabilities into the AWS Security Hub workflow. This includes data discovery and classification to identify sensitive information, posture and identity protection to manage access, and data-centric threat detection powered by user behavior analytics (UEBA). This positions the solution as an end-to-end layer for protecting data within AWS environments.
By connecting AWS's infrastructure security insights with Varonis's data-centric intelligence, the integration helps organizations move beyond infrastructure configuration monitoring to actively safeguard the data itself. This is critical as sensitive data increasingly resides in cloud services, and misconfigurations are a leading cause of cloud data breaches.
This integration represents a convergence of cloud security posture management (CSPM) and data security posture management (DSPM), providing a more holistic approach to securing cloud environments by focusing on the protection of the primary asset: data.
About Varonis
Varonis is the leader in data security, fighting a different battle than conventional cybersecurity companies. Our cloud-native Data Security Platform continuously discovers and classifies critical data, removes exposures, and detects advanced threats with AI-powered automation. Thousands of organizations worldwide trust Varonis to defend their data wherever it lives — across SaaS, IaaS, and hybrid cloud environments. Customers use Varonis to automate a wide range of security outcomes, including data security posture management (DSPM), data classification, data access governance (DAG), data detection and response (DDR), data loss prevention (DLP), database activity monitoring (DAM), identity protection, email security, and AI security.