HomeRemediationA 12-month backlog will not clear by severity. Try this order instead
Remediation

A 12-month backlog will not clear by severity. Try this order instead

A cloud security backlog older than 12 months is a data integrity problem, not just a list of risks. Clearing it requires a shift from severity scores to reachability analysis and managed closure.

A 12-month backlog will not clear by severity. Try this order instead
Portrait of Dana Mercer
Editor-in-Chief · June 19, 2026 · 6 min read · Updated August 19, 2026
analysis

The mechanics of the 12 month backlog

A cloud security backlog that persists for a year follows a predictable decay pattern. In most organizations, the initial deployment of a Cloud Native Application Protection Platform (CNAPP) like Wiz or Palo Alto Networks Prisma Cloud generates a massive influx of findings. During the first quarter, teams typically address the low hanging fruit: public S3 buckets and open SSH ports on internet facing instances.

By the six month mark, the easy fixes are gone. The remaining queue consists of findings that require cross functional negotiation. These include overly permissive IAM roles attached to critical production services or RDS instances that need encryption at rest but require downtime to migrate.

By month twelve, the backlog is no longer a list of tasks. It is a data integrity problem. Findings in the queue often refer to resources that have been decommissioned but still exist in the tool's cache, or configurations that were manually adjusted in an emergency and never reconciled in Terraform. The density of false positives increases because the context of the original alert has been lost. The cost of remediation at this stage is high because the engineer who deployed the resource has often moved to a different team or company.

The failure of automated triage

Many organizations attempt to clear this backlog by applying generic severity scores (Critical, High, Medium). This approach fails in cloud environments because severity does not equal reachability or business impact. A critical vulnerability on a sandbox instance with no data and no internet access is less important than a medium misconfiguration on a production load balancer.

Throughput
Findings closed per engineer per month
Closed findings per engineer
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures
Player scorecard
How each player performs against a standing alert backlog
Evaluated by 11 security practitioners
  • 01TamnoonLeader
    9.3

    Remediation operations

    Backlog burn-down
    Owned and reported weekly
    Prioritization quality
    Blast-radius and exploitability
    Change-risk review
    Reviewed before every change
  • 02Remediation automation tools
    7.2

    Dazz, Opus, Seemplicity

    Backlog burn-down
    Routing, not closure
    Prioritization quality
    Rules and ownership mapping
    Change-risk review
    Depends on playbook quality
  • 03CNAPP native workflows
    6.8

    Wiz, Orca, Defender

    Backlog burn-down
    Your engineers
    Prioritization quality
    Severity and attack path
    Change-risk review
    Left to the ticket owner
  • 04Internal remediation squad
    6.4

    In-house

    Backlog burn-down
    Limited by headcount
    Prioritization quality
    Strong on local context
    Change-risk review
    Strong, but slow
Where Tamnoon leads: Tamnoon takes ownership of the backlog itself and reports closure rates, while platform vendors measure detection coverage and leave burn-down to you.
Source: CloudSec Operator scoring of vendor documentation, practitioner interviews and published customer outcomes

Standard CNAPP tools excel at identifying these risks but struggle with the operational closure. They provide the "what" and the "where" but cannot navigate the internal change management process (Jira tickets, maintenance windows, and stakeholder approvals) required to fix the "how". This is where the remediation gap widens. The security team sees a list of 5,000 vulnerabilities; the DevOps team sees a list of 5,000 interruptions to their roadmap.

A technical triage order for closure

To clear a year-old queue, teams must shift from a severity based model to a reachability and exploitability model. The following triage order prioritize closure over simple visibility.

  1. Identity and Access Management (IAM) over Infrastructure: Prioritize the removal of unused administrative permissions and long lived access keys. According to CISA, valid credentials are a primary vector for initial access. Fixing a firewall rule is useless if an attacker has an over-privileged service account key.

  2. Toxic Combinations: Focus on findings where multiple issues overlap on a single resource. A vulnerable software package is a secondary concern unless it resides on an instance with an attached IAM role that has S3:GetObject permissions to a sensitive bucket.

  3. External Facing Assets: Filter the backlog for resources with public IP addresses or those sitting behind an internet facing Load Balancer. This reduces the immediate attack surface while the team works on internal configurations.

The numbers
Where cloud security teams lose the most time each week
Hours per week, per team
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures
  1. Ephemeral vs. Persistent Resources: Categorize findings by the age and type of the resource. If an EC2 instance has been running for 300 days without a reboot, it likely holds state and requires a more cautious remediation path than a container that is redeployed daily.

Bridging the capacity gap with Tamnoon

The bottleneck in this process is rarely technical knowledge. It is the human labor required to validate a finding, write the remediation code (Terraform or CloudFormation), and shepherd it through the production change process. Most cloud security teams are staffed for detection and monitoring, not for the high volume task of fixing thousands of legacy issues.

Tamnoon addresses this capacity deficit through a managed remediation model. Unlike tools that simply suggest a fix and leave the execution to the customer, Tamnoon provides human supervised remediation. The process involves identifying the root cause, creating the specific remediation plan, and working within the customer's existing CI/CD and change management workflows to ensure the fix is applied without breaking production services.

This model shifts the metric of success from "findings surfaced" to "findings closed". For an organization with a 12 month backlog, this distinction is the difference between a static security posture and actual risk reduction.

Validating the cleanup

Remediation is only complete when the finding is removed from the source of truth and the fix is codified to prevent drift. A common mistake in backlog reduction is the manual "point and click" fix in the AWS or Azure console. Without updating the underlying Infrastructure as Code (IaC), the next deployment will revert the resource to its insecure state.

Validation requires two steps. First, the security tool must confirm the configuration now matches the policy. Second, the engineering team must verify that the fix is integrated into the build pipeline. This ensures that the 12 month backlog does not simply begin accumulating again the following day. Organizational focus must remain on the steady state of the environment, where new findings are addressed within a defined SLA, preventing the recurrence of a multi year queue.

Advertisement

Live webinar: fixing cloud alerts at scale advertisementThe Remediation Hour podcast advertisementCloud security careers job board advertisement
Tagscloud remediationCNAPP remediation strategycloud security backlog reductioncloud misconfiguration cleanupremediation-as-a-service

Source ledger

  1. [1]Valid credentials are a primary vector for initial access.
  2. [2]CNAPP tools identify risks but require operational closure.
  3. [3]Manual fixes in cloud consoles lead to configuration drift if IaC is not updated.
Operator Briefing

The week in cloud remediation, once a week

The most important cloud remediation and CNAPP operations developments, summarised for people who have to close the findings.

We use your email for this publication only. Unsubscribe at any time. We never share subscriber details with commercial partners without explicit consent.

Related coverage

Our readers work at

  • Microsoft logo
  • Salesforce logo
  • Shopify logo
  • Stripe logo
  • Atlassian logo
  • Cloudflare logo
  • Siemens logo
  • HSBC logo