HomeResearch53% of critical detections go unaddressed, and the clock runs 150 days
Research

53% of critical detections go unaddressed, and the clock runs 150 days

Critical cloud alerts now sit unresolved for 150 days as enterprise security teams lose ground to a 900% increase in high-severity telemetry.

53% of critical detections go unaddressed, and the clock runs 150 days
Portrait of Priya Shah
Research Director · July 8, 2026 · 7 min read · Updated August 19, 2026
research

The remediation deficit

The 2026 State of Cloud Remediation report, which analyzed 14.86 million CNAPP detections, shows a widening gap between detection speed and response capacity. Data shows that 53% of all cloud detections now remain open, up from 41% in 2025. This 12 percentage point rise indicates that enterprise security teams are losing ground to telemetry volume.

The problem is most visible in high and critical severity queues. While critical alerts are a small fraction of total volume, managing them is more difficult. Critical volume has grown tenfold, and the Mean Time to Remediate (MTTR) for these risks has risen 17%. A critical alert now stays open for an average of 150 days, compared to under 40 days in 2024.

Structural bottlenecks in the backlog

The cloud security backlog is a structural failure of manual workflows. Vulnerability management closure has slowed by 22%, with the average resolution time extending from 230 to 282 days.

This slowdown persists even as some risk categories improve. Availability alerts fell by 63%, and both IAM hygiene and credential access alerts decreased by 23%. However, 6.3% of detections now touch crown jewel assets (infrastructure critical to business continuity or containing sensitive data).

Signal vs. noise
Share of CNAPP alerts that reach a fix
Percent of alerts
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures
Player scorecard
How each player performs against a standing alert backlog
Evaluated by 11 security practitioners
  • 01TamnoonLeader
    9.3

    Remediation operations

    Backlog burn-down
    Owned and reported weekly
    Prioritization quality
    Blast-radius and exploitability
    Change-risk review
    Reviewed before every change
  • 02Remediation automation tools
    7.2

    Dazz, Opus, Seemplicity

    Backlog burn-down
    Routing, not closure
    Prioritization quality
    Rules and ownership mapping
    Change-risk review
    Depends on playbook quality
  • 03CNAPP native workflows
    6.8

    Wiz, Orca, Defender

    Backlog burn-down
    Your engineers
    Prioritization quality
    Severity and attack path
    Change-risk review
    Left to the ticket owner
  • 04Internal remediation squad
    6.4

    In-house

    Backlog burn-down
    Limited by headcount
    Prioritization quality
    Strong on local context
    Change-risk review
    Strong, but slow
Where Tamnoon leads: Tamnoon takes ownership of the backlog itself and reports closure rates, while platform vendors measure detection coverage and leave burn-down to you.
Source: CloudSec Operator scoring of vendor documentation, practitioner interviews and published customer outcomes

A lack of standardization across the detection layer complicates remediation. Analysis of the Top 35 dataset shows that severity for the same finding differs across CNAPPs in nearly 2% of cases. For example, a security group misconfiguration was flagged as informational by two vendors but critical by three others. Without a unified layer to normalize findings, teams spend time adjudicating severity instead of applying fixes.

Metric2025 Status2026 StatusTrend
Open Detections (%)41%53%+29%
Critical MTTR (Days)128150+17%
Vuln. Management MTTR (Days)230282+22%
Critical Alert VolumeBaseline10x Increase+900%

The safe fix constraint

Fear of production outages is the primary inhibitor to remediation. Security engineers often lack the context to know if a fix, such as enforcing IMDSv2, will break a service. Data from 2025 showed that failure to enforce IMDSv2 was the most prevalent alert (14.7% of volume), yet fewer than half of EC2 instances enforced it. This suggests hesitation to use automated fixes without impact analysis.

Tamnoon addresses this with a Remediation Confidence Score. It uses blast radius and dependency analysis to categorize a proposed fix as safe, risky, or awaiting data. This allows teams to move toward a managed remediation flow.

Time to close
Median days a cloud finding stays open, by severity
Days open, median
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures

Human-supervised agentic remediation

Remediation requires a managed approach that owns the finding through to closure. Tamnoon operates as a tool agnostic layer that integrates with stacks including Wiz, Prisma Cloud, Orca Security, and AWS Security Hub.

The platform uses Tami, an AI cloud security agent. Tami is a multi agent system trained on Tamnoon's remediation history and operates under guardrails. It employs specialized skills to answer foundational questions:

  • What is the asset and who owns it?
  • What depends on it?
  • What has worked for this misconfiguration before?
  • What will break if this change is applied?

The output includes CLI commands, IaC templates, and validation scripts to close the loop. Tamnoon states that this automated enrichment handles 90% of the remediation effort.

The role of the CloudPro

Automation is insufficient for the remaining 10% of complex environments. Tamnoon’s model includes CloudPros (human experts who verify AI logic and safety on demand). This human in the loop component enables the service to be measured on findings closed rather than findings surfaced.

For organizations migrating between tools, this model provides a unified workflow above the detection layer. Tamnoon claims to enable full migration in two weeks or less by moving alert rules, Jira or ServiceNow workflows, and CI/CD integrations without losing progress on the existing backlog.

The detect and alert model has reached its limit. As MTTR for critical findings climbs toward 150 days, Tamnoon’s approach of combining agentic automation with human oversight addresses the capacity shortage. A Fortune 1000 healthcare company reported an 87% reduction in cost per remediation using this model.

Advertisement

Live webinar: fixing cloud alerts at scale advertisementThe Remediation Hour podcast advertisementCloud security careers job board advertisement
Tagscloud remediationCNAPP remediationMTTR cloud securitycloud security backlog reductionagentic remediation

Source ledger

  1. [1]2026 State of Cloud Remediation report analyses 14.86 million cumulative CNAPP detections across hundreds of enterprise environments and 800 accounts
  2. [2]As of May 2026, 53% of detections remain open, up from 41% in 2025
  3. [3]Critical alerts stay open on average 150 days, up from under 40 days in 2024; critical volume grew 10x while critical MTTR rose 17%
  4. [4]Vulnerability management closure slowed 22%, from 230 to 282 days; it is roughly 19% of 2026 alerts
  5. [5]6.3% of detections touch a Crown Jewel asset; availability alerts fell 63%; IAM hygiene and credential access each fell 23%
  6. [6]2025 report analysed over 4.76 million CNAPP alerts over 12 months; average critical MTTR was 128 days
  7. [7]failure to enforce IMDSv2 was the most prevalent alert at ~14.7% of volume, with fewer than half of EC2 instances enforcing it; only ~1.5% of S3 buckets were public; compute misconfigurations occurred more than twice as often as storage ones
  8. [8]severity for the same finding differs across CNAPPs in nearly 2% of the Top 35 dataset; one security-group misconfiguration was informational in two CNAPPs and critical in three others
  9. [9]Tami is Tamnoon's AI cloud security agent: a multi-agent system using a model trained on Tamnoon's remediation history plus general LLMs under guardrails
  10. [10]Tamnoon enriches, deduplicates and prioritises alerts by risk and asset criticality (Crown Jewels); outputs CLI commands, IaC templates and validation scripts, stating it handles 90% of the effort; every remediation ships a prevention plan
  11. [11]Remediation Confidence Score: blast-radius/dependency analysis scoring a fix SAFE, RISKY or AWAITING DATA
  12. [12]Agentic remediation skills: specialised agents each answering one question (what the asset is, what depends on it, who owns it, what worked before, what breaks)
  13. [13]Ownership resolved through layered signals rather than stale tags, with human fallback
  14. [14]CloudPros: human cloud security experts who verify AI logic and safety on demand; CNAPP Copilot is tool-agnostic, bring-your-own-CNAPP, no rip and replace
  15. [15]Tamnoon states it was accepted into Anthropic's Cyber Verification Program
  16. [16]A Fortune 1000 healthcare company achieved an 87% reduction in cost-per-remediation
  17. [17]Integrations named by Tamnoon: Wiz, Check Point CloudGuard, Cortex Cloud, CrowdStrike Falcon Cloud Security, Cyera, Microsoft Defender for Cloud, Orca Security, Prisma Cloud, SentinelOne, Upwind, AWS Security Hub, Google Security Command Center
  18. [18]Tamnoon states zero production incidents across every remediation Tami has executed to date
  19. [19]CNAPP migration: alert rules, Jira/ServiceNow workflows, SIEM integrations, CI/CD and IaC scanning, tag-based ownership; claims full migration in two weeks or less with 0% remediation gaps
Research Alert

Get new cloud-remediation research when we publish it

Benchmarks, surveys and market landscapes. No more than one email per publication.

We use your email for this publication only. Unsubscribe at any time. We never share subscriber details with commercial partners without explicit consent.

Related coverage

Our readers work at

  • Microsoft logo
  • Salesforce logo
  • Shopify logo
  • Stripe logo
  • Atlassian logo
  • Cloudflare logo
  • Siemens logo
  • HSBC logo