KubeNine
All case studies

Security

Setting up org-wide threat detection across an AWS Organization

Rolling out Amazon GuardDuty across a customer's entire AWS Organization from one delegated security account — centralized findings, real-time alerting, and every current and future account auto-enrolled.

Org-wide, auto-enroll
Coverage
One security account
Operations
Near real-time for high severity
Alerting

// the challenge

A customer ran multiple AWS accounts and an EKS platform with no centralized threat detection. It needed GuardDuty enabled across the whole organization, with findings collected in one place, stored durably, and alerting in real time — configured once, centrally, not clicked through account by account where new accounts would silently be left uncovered.

// our approach

  • Had the management account delegate GuardDuty administration to a dedicated security account, so all configuration lives in one place with no per-member setup.
  • Managed everything in Terraform, split into management and delegated-admin workspaces, with org auto-enable so current and future member accounts are covered automatically.
  • Exported findings on a regular publish interval to a KMS-encrypted, versioned, TLS-enforced, public-access-blocked S3 bucket with key rotation on.
  • Enabled the core protection features org-wide (including S3 data events and EKS audit logs), staged the rest, and wired EventBridge to SNS email for high-severity findings in a readable format.

// the outcome

The organization now has centralized threat detection from a single security account, with member accounts — including ones created later — covered automatically. High-severity findings reach the team in near real time, findings land in durable encrypted storage, and the whole setup is defined in Terraform instead of living as manual console state.

Have a similar challenge?

Book a 15-minute call and we'll show you where we can help — no pitch, no obligation.