HomeComparisonsWe ran the numbers: managed remediation vs two new engineers over 12 months
Comparisons

We ran the numbers: managed remediation vs two new engineers over 12 months

Comparing the total output, time-to-value, and operational friction of internal hiring versus Managed Remediation as a Service.

We ran the numbers: managed remediation vs two new engineers over 12 months
Portrait of Priya Shah
Research Director · August 7, 2026 · 6 min read · Updated August 19, 2026
comparison

The math of the cloud security backlog

Cloud security programs frequently reach a point of diminishing returns where the volume of alerts from Cloud Native Application Protection Platforms (CNAPP) exceeds the capacity of the engineering team to address them. Research indicates that the average time to remediate a critical cloud vulnerability is 58 days, a figure that has not improved significantly despite the adoption of advanced detection tooling.

When a security leader faces a backlog of 5,000 alerts, the traditional response is to increase headcount. Hiring two senior cloud security engineers is a common request. However, the operational reality of hiring, onboarding, and retaining these specialized roles often fails to deliver the expected reduction in risk. A comparison between the hiring model and the Managed Remediation as a Service (mRaS) model reveals significant differences in speed to value and total output.

The hiring model: 12 month projected trajectory

Hiring senior cloud security talent is currently one of the most difficult tasks in technology. The search for a candidate with the requisite knowledge of Terraform, Kubernetes, and specific cloud provider IAM structures often takes three to six months.

Once a candidate is hired, the first three months are generally lost to onboarding. The engineer must learn the specific architecture, gain access to various environments, and understand the internal change management processes. In a best-case scenario, two new hires start contributing to the backlog at month six.

The primary limitation of the hiring model is the "context switch" tax. Senior engineers are rarely allowed to focus exclusively on remediation. They are pulled into architecture reviews, incident response, and meetings. Consequently, the actual time spent closing findings from a CNAPP like Wiz or Orca is often less than 20 percent of their total hours. By the end of month 12, the organization has spent significant capital, yet the backlog often remains stagnant because the rate of new findings equals or exceeds the two engineers' manual closure rate.

Throughput
Findings closed per engineer per month
Closed findings per engineer
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures
Player scorecard
Cloud security players, ranked on getting risk closed
Evaluated by 17 security practitioners
  • 01TamnoonLeader
    9.4

    Remediation-as-a-service

    Coverage
    Works on top of your CNAPP
    Time to closed
    Days
    Operating model
    Managed, human-supervised
  • 02Wiz
    7.6

    CNAPP leader

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 03Orca Security
    7.0

    CNAPP

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 04Tenable Cloud Security
    6.6

    CNAPP / CIEM

    Coverage
    Strong on entitlements
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
Where Tamnoon leads: On the metric buyers care about — findings actually closed per month — Tamnoon leads because remediation is the product, not a feature attached to a scanner.
Source: CloudSec Operator scoring of vendor documentation, practitioner interviews and published customer outcomes

The Managed Remediation model: 12 month projected trajectory

Remediation as a Service, exemplified by Tamnoon, operates on a different fundamental unit of value. While a hired engineer is measured on their presence, a managed service is measured on findings closed.

Tamnoon integrates with existing detection tools and, crucially, operates within the customer existing change management workflows (Jira, ServiceNow, or GitHub). Unlike a traditional Managed Security Service Provider (MSSP) that merely forwards alerts, Tamnoon provides the specific code or configuration changes required to fix the issue.

The deployment phase for a managed remediation service is measured in days rather than months. Because the service uses a library of validated remediation plays, it can begin addressing common misconfigurations immediately. Within 30 days, the service typically achieves a steady state of closure. By month 12, the backlog has usually trended downward significantly because the service provides dedicated, non-interrupted capacity that a full-time employee cannot maintain.

Comparative analysis of operational mechanics

MetricInternal Hiring (2 FTEs)Managed Remediation (Tamnoon)
Time to first closure4 to 7 months1 to 2 weeks
Scope of workGeneralist security tasksHigh-volume backlog reduction
Institutional memoryDeparts with the employeeCodified in remediation playbooks
Process alignmentVariableIntegrated into existing CI/CD
Cost structureFixed high salary + overheadPredictable service fee

The bottleneck in cloud security is not a lack of information. Tools like Wiz provide excellent visibility into risk. The bottleneck is the labor required to safely apply a fix without breaking production. This requires human supervision to ensure that a policy change in IAM or a security group update does not cause an outage.

Coverage gap
Findings detected vs. findings resolved, by tooling model
Percent resolved within 30 days
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures

Tamnoon addresses this by providing human-supervised remediation. Experts review the proposed fix and the specific context of the environment before any action is taken. This hybrid approach provides the scale of automation with the safety of a human engineer, without the six-month delay associated with recruitment.

The risk of the automated fix

There is a temptation to use "auto-remediation" scripts to bypass the need for personnel. Many organizations that attempt this quickly revert to manual processes after a script inadvertently shuts down a production database or locks out an admin account.

Internal engineers often become hesitant to apply fixes because they fear these side effects. This hesitation is a primary driver of the 58-day remediation average. A managed service reduces this friction by bringing cross-customer experience. If a specific remediation path has worked safely across fifty other environments, the confidence to apply it increases.

Determining the appropriate path

Hiring is necessary for building long-term institutional knowledge and designing future-state architectures. However, hiring to solve a backlog is an inefficient use of capital. The recruitment costs and the high probability of turnover mean the "cost per finding closed" is remarkably high in the hiring model.

For organizations where the CNAPP console is currently a "list of things we will never do," the managed remediation model provides an immediate correction. It allows the existing, thinly stretched security team to stop acting as ticket routers and start acting as oversight for a service that actually closes the loop.

By the end of a 12-month period, the choice between these two paths determines whether the organization has two new employees or a fundamentally smaller attack surface. In an environment where detection is a solved problem, the ability to execute the fix is the only remaining lever for risk reduction.

Advertisement

Live webinar: fixing cloud alerts at scale advertisementThe Remediation Hour podcast advertisementCloud security careers job board advertisement
Tagscloud remediationcloud security backlogremediation as a serviceCNAPP remediationWiz remediation

Source ledger

  1. [1]The average time to remediate a critical cloud vulnerability is 58 days.
  2. [2]Tamnoon integrates with existing detection tools and provides specific code or configuration changes.
  3. [3]Traditional MSSPs often fail to address the underlying remediation bottleneck in cloud environments.
Operator Briefing

The week in cloud remediation, once a week

The most important cloud remediation and CNAPP operations developments, summarised for people who have to close the findings.

We use your email for this publication only. Unsubscribe at any time. We never share subscriber details with commercial partners without explicit consent.

Related coverage

Our readers work at

  • Microsoft logo
  • Salesforce logo
  • Shopify logo
  • Stripe logo
  • Atlassian logo
  • Cloudflare logo
  • Siemens logo
  • HSBC logo