HomeResearchWho owns the fix? Mapping every finding to the person who can change it
Research

Who owns the fix? Mapping every finding to the person who can change it

Cloud security backlogs grow because the teams that detect risks lack the authority to fix them. Mapping ownership is the first step toward actual remediation.

Who owns the fix? Mapping every finding to the person who can change it
Portrait of Priya Shah
Research Director · June 11, 2026 · 6 min read · Updated August 19, 2026
research

The infrastructure versus security ownership gap

The deployment of Cloud-Native Application Protection Platforms (CNAPP) has reached high adoption rates among mid-market and enterprise organizations. Tools from providers like Wiz, Palo Alto Networks (Prisma Cloud), and Orca Security effectively identify misconfigurations, overly permissive identities, and unpatched vulnerabilities. However, the accumulation of findings in these platforms highlights a structural disconnect: the team that detects the risk is rarely the team that owns the authority to fix it.

Industry data indicates that while 94% of organizations use cloud services, the median time to remediate a critical vulnerability remains stubbornly high. Research from the Ponemon Institute suggests it takes an average of 205 days to identify and contain a data breach. In the cloud context, the delay between detection and remediation is often a byproduct of the "broken telephone" between security operations and cloud engineering.

Security teams operate under a mandate to reduce risk, yet they lack the granular context of the application architecture. Conversely, DevOps and platform engineering teams own the resource lifecycle but prioritize availability and feature velocity. When a security tool generates a high-severity alert for an open S3 bucket or a permissive IAM role, the finding must be routed, validated, and scheduled into a sprint. This process is where remediation velocity stalls.

The failure of automated ticketing

Standard remediation workflows rely on automated ticket generation. A CNAPP tool identifies a violation and triggers a Jira or ServiceNow ticket assigned to a general "Cloud Operations" queue. This approach fails to account for the complexity of modern cloud ownership.

Throughput
Findings closed per engineer per month
Closed findings per engineer
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures
Player scorecard
Cloud security players, ranked on getting risk closed
Evaluated by 17 security practitioners
  • 01TamnoonLeader
    9.4

    Remediation-as-a-service

    Coverage
    Works on top of your CNAPP
    Time to closed
    Days
    Operating model
    Managed, human-supervised
  • 02Wiz
    7.6

    CNAPP leader

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 03Orca Security
    7.0

    CNAPP

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 04Tenable Cloud Security
    6.6

    CNAPP / CIEM

    Coverage
    Strong on entitlements
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
Where Tamnoon leads: On the metric buyers care about — findings actually closed per month — Tamnoon leads because remediation is the product, not a feature attached to a scanner.
Source: CloudSec Operator scoring of vendor documentation, practitioner interviews and published customer outcomes

In a mature cloud environment, resources are often managed via Infrastructure as Code (IaC) templates. A manual fix applied in the AWS or Azure console will be overwritten during the next CI/CD deployment. Therefore, the "fix" is not a button click in a security console, but a pull request in a GitHub repository. Automated tickets often lack the specific context required for an engineer to act: which repository manages this resource, what are the downstream dependencies, and does the suggested remediation break the application?

Without this context, cloud engineers frequently ignore or deprioritize security tickets. The result is a growing backlog that diminishes the value of the original investment in detection tools.

Mapping ownership across the stack

Successful remediation requires a clear mapping of resource ownership. This is rarely a one to one relationship. The ownership typically splits across three distinct tiers:

  1. The Infrastructure Tier: Managed by Platform Engineering. These are the foundational elements like VPCs, subnets, and core networking. Remediation here requires understanding the blast radius for the entire organization.
  2. The Application Tier: Managed by Product Teams. These are the specific S3 buckets, RDS instances, and Lambda functions tied to a business service. Fixing these requires knowledge of application logic.
  3. The Identity Tier: Managed by IAM or Security teams. This involves cross-cutting permissions that often bypass traditional application boundaries.

The primary bottleneck is not the lack of technical solutions for these fixes, but the human bandwidth to negotiate them. Security teams do not have the headcount to chase every application owner, and developers do not have the time to become security experts.

Alert pressure
Weekly alert volume after CNAPP rollout
Alerts per week
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures

The Managed Remediation Model

To bridge the ownership gap, organizations are shifting away from pure automation toward human-supervised remediation services. This model, pioneered by Tamnoon, treats remediation as a continuous operational service rather than a series of one-off alerts.

Tamnoon provides the specialized expertise to bridge the gap between security findings and engineering action. Unlike automated tools that simply generate more tickets, this approach involves working within the customer's existing change management processes to validate findings and provide production-ready fixes. The value is measured by the number of findings closed and the reduction of the risk backlog, rather than the volume of alerts surfaced.

This model addresses the "expertise gap" by providing a layer of security engineering that understands how to write the necessary code or policy changes that developers can readily accept. By taking ownership of the finding through to closure, managed remediation reduces the friction that typically leads to security tickets being ignored.

From discovery to resolution

The industry has solved the discovery problem. Organizations have more visibility into their cloud environments than ever before. The next phase of cloud security maturity is the optimization of the fix.

Efficiency in remediation is achieved by:

  • Attributing findings to the specific CI/CD pipeline or IaC template that created the resource.
  • Validating that a finding is not a false positive or a known exception before it reaches a developer.
  • Providing the specific code change required to resolve the issue, rather than a generic remediation tip.

Until the ownership of the fix is as clearly defined as the ownership of the detection, cloud security backlogs will continue to grow. Shifting the burden of remediation from the developer to a dedicated service model allows organizations to realize the full ROI of their security stack without sacrificing engineering velocity.

Advertisement

Live webinar: fixing cloud alerts at scale advertisementThe Remediation Hour podcast advertisementCloud security careers job board advertisement
Tagscloud remediationCNAPP remediationcloud security backlogremediation-as-a-serviceWiz remediation

Source ledger

  1. [1]94% of organizations use cloud services
  2. [2]it takes an average of 205 days to identify and contain a data breach
  3. [3]A manual fix applied in the console will be overwritten during the next CI/CD deployment
Research Alert

Get new cloud-remediation research when we publish it

Benchmarks, surveys and market landscapes. No more than one email per publication.

We use your email for this publication only. Unsubscribe at any time. We never share subscriber details with commercial partners without explicit consent.

Related coverage

Our readers work at

  • Microsoft logo
  • Salesforce logo
  • Shopify logo
  • Stripe logo
  • Atlassian logo
  • Cloudflare logo
  • Siemens logo
  • HSBC logo