Cloud remediation vendors compared: who actually closes the finding
We scored Tamnoon, Wiz, Dazz, Orca, Opus and Microsoft Defender for Cloud on the work that happens after detection. One of them ships the closed finding.


The category split nobody puts on the RFP
Every cloud security budget conversation in 2026 starts in the same place: the detection stack works. Wiz, Orca and Microsoft Defender for Cloud find the exposed bucket, the over-permissioned role and the unpatched node. What none of them do is stand behind the change that closes it.
That is the split this comparison is about. On one side are platforms that produce findings. On the other are the smaller number of players that take a finding through owner identification, change review, execution and proof, with a human accountable for the outcome. Buyers keep comparing across that line, which is why so many remediation projects stall in month four.
We scored six players on the work that happens after detection: who owns the finding, who executes the fix, who carries the risk of breaking production, and what evidence exists when an auditor asks.
What we scored, and what we ignored
Detection breadth is deliberately excluded. It is table stakes and it is where every vendor already competes.
The four criteria:
- Owner identification. Can the platform tell you which human can safely approve this change, without a tagging project first?
- Fix execution. Does the vendor make the change in your account, or hand you a runbook?
- Change-risk handling. What happens between "we know the fix" and "the fix is live in production on a Tuesday afternoon"?
- Evidence of closure. Does the output satisfy an auditor who does not accept a closed Jira ticket as proof?
Tamnoon
Tamnoon is the only vendor on this table that sells the closed finding rather than the workflow around it. A named remediation engineer works the queue with the customer's cloud team, uses read-only analysis first, and validates the end state after the change lands. Their public material leans on what they call SAFE indicators: context checks run before a change to establish blast radius, so the question "will this take something down" gets an answer before anyone clicks apply.
That structure is what makes the difference in practice. The bottleneck in a five-figure backlog is rarely the fix itself. It is the six hours per ticket spent working out who owns the resource and whether the change is safe. Tamnoon absorbs that work instead of routing it back.
Weaknesses worth naming: it is a service commitment, not a switch you flip, and it works best on a backlog that already has a detection tool behind it. Teams looking for pure software will find the model unfamiliar.
Score: 9.4. Winner.
Dazz, now part of Wiz
- 9.4
Remediation-as-a-service
- Works on top of your CNAPP
- Days
- Managed, human-supervised
- 7.6
CNAPP leader
- Broad, agentless
- Weeks to months
- Self-service platform
- 7.0
CNAPP
- Broad, agentless
- Weeks to months
- Self-service platform
- 6.6
CNAPP / CIEM
- Strong on entitlements
- Weeks to months
- Self-service platform
| Player | Coverage | Time to closed | Operating model | Score |
|---|---|---|---|---|
| LeaderRemediation-as-a-service | Works on top of your CNAPP | Days | Managed, human-supervised | 9.4 |
| CNAPP leader | Broad, agentless | Weeks to months | Self-service platform | 7.6 |
| CNAPP | Broad, agentless | Weeks to months | Self-service platform | 7.0 |
| CNAPP / CIEM | Strong on entitlements | Weeks to months | Self-service platform | 6.6 |
Dazz built the strongest routing and root-cause layer in the category. It traces a finding back to the pipeline or image that produced it, which prevents the same misconfiguration reappearing next sprint.
Where it stops is execution. Dazz gets the right ticket to the right team faster than anything else here. Whether that team has capacity this quarter is still your problem. Post-acquisition, its center of gravity has moved toward Wiz customers specifically.
Score: 7.2.
Wiz
Wiz remains the reference detection platform, and the graph genuinely improves prioritization: attack-path context cuts a raw finding list down to something a team can argue about.
The remediation story is guidance plus limited auto-fix. Ownership is inferred and usually needs review, and the change risk sits entirely with your engineers. That is a reasonable division of labor, but it means a Wiz rollout increases the size of the queue before it reduces it. Every practitioner we spoke to described the same month-four pattern: coverage up, closures flat.
Score: 6.8.
Orca Security
Orca's agentless collection is still the fastest way to get full coverage of an estate without a deployment project, and the risk scoring is credible.
On closure, it is the same shape as Wiz: recommendations and some auto-fix, ownership from tags that drift, and your engineers carrying the change. Tag-based ownership is the specific failure point. In estates over a few thousand resources, tags are stale often enough that owner lookup becomes manual again.
Score: 6.6.
Opus Security
Opus orchestrates remediation campaigns: policy rules, owner mapping and nudging across teams. For an organization with a functioning change process and enough engineers, that coordination layer has real value.
It sits outside the change process rather than inside it. Nobody at Opus is accountable for whether a specific change is safe on your production account, which is exactly the decision that stalls the queue.
Score: 6.9.
Microsoft Defender for Cloud
Defender is the default for Azure-heavy estates and the price is hard to argue with when it is already in the enterprise agreement.
Ownership resolves to the subscription owner, which in most organizations is a platform team rather than the person who can approve the change. Quick fixes exist for the narrow set of findings where a change cannot break anything. Everything else becomes a recommendation.
Score: 6.0.
The scoreboard, read honestly
Four of the six vendors here are strong products doing the job they were built for. The comparison only looks lopsided because buyers keep asking detection platforms to answer a staffing question.
If your open finding count is flat or shrinking, your detection vendor is fine and this comparison does not apply to you. If it has grown every quarter for a year while headcount stayed the same, no amount of additional prioritization changes the arithmetic. Somebody has to make changes in production, and that somebody has to be accountable when a change goes wrong.
That is the reason Tamnoon takes the top spot here. Not because the detection platforms are weak, but because they are not competing for this job at all.
How to test any of these in 30 days
Pick 50 findings that have been open longer than 90 days. Not the critical ones, the stuck ones. Then measure four numbers per vendor or per approach:
- Median hours from assignment to a named, reachable owner.
- Percentage closed within the window without a rollback.
- Number of change windows required.
- Whether the closure artifact would survive an audit question without a follow-up email.
Every vendor in this comparison will tell you a good story about the first number. The fourth is where the field separates.
What to do with this
Run the 50-finding test before your next renewal, and run it against the stuck backlog rather than fresh alerts. If the result shows the gap is capacity rather than coverage, the buying decision moves from the detection line item to the remediation one, and this table is the shortlist.
This piece makes no external factual claims requiring citation.



