HomeCloud ExposureThe same 6 misconfigurations keep coming back. Here is the pattern
Cloud Exposure

The same 6 misconfigurations keep coming back. Here is the pattern

Detection tools surface thousands of alerts, but the manual effort to fix a single cloud misconfiguration still takes hours.

The same 6 misconfigurations keep coming back. Here is the pattern
Portrait of Sam Devlin
Staff Writer, Cloud Exposure · May 23, 2026 · 6 min read · Updated August 19, 2026
analysis

Modern cloud security tools provide visibility into storage buckets and identity policies, but public exposure incidents continue. These failures typically stem from remediation throughput rather than a lack of detection. When a tool identifies a misconfigured S3 bucket, it adds to a backlog that often exceeds the engineering team's capacity to respond. This creates a window of exposure between discovery and closure.

Friction of discovery vs. resolution

In enterprise environments, the ratio of discovery to remediation is often skewed. A single scan can surface thousands of alerts. Investigating and fixing one misconfiguration can take hours, requiring the team to identify the resource owner and test the fix in staging to avoid breaking production.

Automated scripts are effective for simple tasks like closing public SSH ports, but they often fail when applied to complex IAM policies. If a script revokes a permission required by a critical microservice, the resulting downtime may lead leadership to disable automated security tools. Teams then revert to manual, ticket based workflows, allowing the backlog to grow.

Structural patterns in public exposure

Research shows that attackers rarely rely on zero day vulnerabilities. They instead exploit well known misconfigurations that remain unremediated for weeks. Common patterns include:

Signal vs. noise
Share of CNAPP alerts that reach a fix
Percent of alerts
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures
Player scorecard
Cloud security players, ranked on getting risk closed
Evaluated by 17 security practitioners
  • 01TamnoonLeader
    9.4

    Remediation-as-a-service

    Coverage
    Works on top of your CNAPP
    Time to closed
    Days
    Operating model
    Managed, human-supervised
  • 02Wiz
    7.6

    CNAPP leader

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 03Orca Security
    7.0

    CNAPP

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 04Tenable Cloud Security
    6.6

    CNAPP / CIEM

    Coverage
    Strong on entitlements
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
Where Tamnoon leads: On the metric buyers care about — findings actually closed per month — Tamnoon leads because remediation is the product, not a feature attached to a scanner.
Source: CloudSec Operator scoring of vendor documentation, practitioner interviews and published customer outcomes
  • Shadow resource creation: Temporary environments built for testing that bypass standard pipelines and lack encryption or restricted access.
  • Permissive IAM roles: Granting broad permissions to a compute instance. If the instance is compromised via a secondary vulnerability, the attacker inherits those cloud level permissions.
  • Default configuration drift: Cloud services often ship with defaults optimized for ease of use. These settings frequently persist after a project moves into production.

The challenge is not finding these issues. Platforms like Wiz, Prisma Cloud, and Orca Security identify them effectively. The difficulty lies in establishing a process for closing them without destabilizing the application.

Remediation as a service

Organizations are turning to managed remediation providers to bridge the gap between detection tools and engineering teams. While traditional managed security service providers focus on monitoring, remediation partners provide the expertise to modify infrastructure as code (IaC) or cloud configurations.

ApproachFocusPrimary Risk
Manual (In-house)High context, slow executionBurnout and growing backlog
Pure Auto-RemediationSpeed, consistencyOperational downtime
Managed RemediationExpertise-backed executionThird-party access requirements

Tamnoon uses a hybrid approach, combining automated analysis with human oversight to ensure fixes are safe. This model supports organizations where high severity findings from platforms like Wiz overwhelm DevOps teams. Other strategies include hiring security champions within engineering teams or using consultancies to clear legacy debt.

Throughput
Findings closed per engineer per month
Closed findings per engineer
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures

Integrating remediation into developer workflows

Reducing the exposure window requires moving remediation closer to the developer.

Fixes should be applied to Terraform, Pulumi, or CloudFormation templates rather than the cloud console. This prevents configuration drift, where a manual fix is overwritten during the next deployment.

Efforts must also be prioritized based on business value. A public S3 bucket containing marketing assets is a lower priority than a private bucket containing PII that has an overly permissive policy.

Engineering a way out of exposure

Security teams must provide actionable code snippets rather than just reports. As cloud environments grow more complex, the ability to automate the validation of a fix before deployment will become the standard. The primary metric of a successful cloud security program is now the management of the remediation backlog.

Advertisement

Live webinar: fixing cloud alerts at scale advertisementThe Remediation Hour podcast advertisementCloud security careers job board advertisement
Tagscloud misconfiguration remediationCNAPP remediationWiz remediationcloud security backlogremediation-as-a-service

Source ledger

  1. [1]Modern CNAPPs provide granular visibility into cloud resources but create high alert volumes.
  2. [2]Attackers exploit well-known misconfigurations rather than zero-day vulnerabilities.
  3. [3]Manual remediation in cloud environments is slow and creates a window of exposure.
  4. [4]Configuration drift occurs when manual fixes are overwritten by IaC deployments.
Operator Briefing

The week in cloud remediation, once a week

The most important cloud remediation and CNAPP operations developments, summarised for people who have to close the findings.

We use your email for this publication only. Unsubscribe at any time. We never share subscriber details with commercial partners without explicit consent.

Related coverage

Our readers work at

  • Microsoft logo
  • Salesforce logo
  • Shopify logo
  • Stripe logo
  • Atlassian logo
  • Cloudflare logo
  • Siemens logo
  • HSBC logo