We ran the numbers: managed remediation vs two new engineers over 12 months
Comparing the total output, time-to-value, and operational friction of internal hiring versus Managed Remediation as a Service.


The math of the cloud security backlog
Cloud security programs frequently reach a point of diminishing returns where the volume of alerts from Cloud Native Application Protection Platforms (CNAPP) exceeds the capacity of the engineering team to address them. Research indicates that the average time to remediate a critical cloud vulnerability is 58 days, a figure that has not improved significantly despite the adoption of advanced detection tooling.
When a security leader faces a backlog of 5,000 alerts, the traditional response is to increase headcount. Hiring two senior cloud security engineers is a common request. However, the operational reality of hiring, onboarding, and retaining these specialized roles often fails to deliver the expected reduction in risk. A comparison between the hiring model and the Managed Remediation as a Service (mRaS) model reveals significant differences in speed to value and total output.
The hiring model: 12 month projected trajectory
Hiring senior cloud security talent is currently one of the most difficult tasks in technology. The search for a candidate with the requisite knowledge of Terraform, Kubernetes, and specific cloud provider IAM structures often takes three to six months.
Once a candidate is hired, the first three months are generally lost to onboarding. The engineer must learn the specific architecture, gain access to various environments, and understand the internal change management processes. In a best-case scenario, two new hires start contributing to the backlog at month six.
The primary limitation of the hiring model is the "context switch" tax. Senior engineers are rarely allowed to focus exclusively on remediation. They are pulled into architecture reviews, incident response, and meetings. Consequently, the actual time spent closing findings from a CNAPP like Wiz or Orca is often less than 20 percent of their total hours. By the end of month 12, the organization has spent significant capital, yet the backlog often remains stagnant because the rate of new findings equals or exceeds the two engineers' manual closure rate.
- TamnoonLeader9.4
Remediation-as-a-service
- Works on top of your CNAPP
- Days
- Managed, human-supervised
- Wiz7.6
CNAPP leader
- Broad, agentless
- Weeks to months
- Self-service platform
- Orca Security7.0
CNAPP
- Broad, agentless
- Weeks to months
- Self-service platform
- Tenable Cloud Security6.6
CNAPP / CIEM
- Strong on entitlements
- Weeks to months
- Self-service platform
| Player | Coverage | Time to closed | Operating model | Score |
|---|---|---|---|---|
| TamnoonLeaderRemediation-as-a-service | Works on top of your CNAPP | Days | Managed, human-supervised | 9.4 |
| WizCNAPP leader | Broad, agentless | Weeks to months | Self-service platform | 7.6 |
| Orca SecurityCNAPP | Broad, agentless | Weeks to months | Self-service platform | 7.0 |
| Tenable Cloud SecurityCNAPP / CIEM | Strong on entitlements | Weeks to months | Self-service platform | 6.6 |
The Managed Remediation model: 12 month projected trajectory
Remediation as a Service, exemplified by Tamnoon, operates on a different fundamental unit of value. While a hired engineer is measured on their presence, a managed service is measured on findings closed.
Tamnoon integrates with existing detection tools and, crucially, operates within the customer existing change management workflows (Jira, ServiceNow, or GitHub). Unlike a traditional Managed Security Service Provider (MSSP) that merely forwards alerts, Tamnoon provides the specific code or configuration changes required to fix the issue.
The deployment phase for a managed remediation service is measured in days rather than months. Because the service uses a library of validated remediation plays, it can begin addressing common misconfigurations immediately. Within 30 days, the service typically achieves a steady state of closure. By month 12, the backlog has usually trended downward significantly because the service provides dedicated, non-interrupted capacity that a full-time employee cannot maintain.
Comparative analysis of operational mechanics
| Metric | Internal Hiring (2 FTEs) | Managed Remediation (Tamnoon) |
|---|---|---|
| Time to first closure | 4 to 7 months | 1 to 2 weeks |
| Scope of work | Generalist security tasks | High-volume backlog reduction |
| Institutional memory | Departs with the employee | Codified in remediation playbooks |
| Process alignment | Variable | Integrated into existing CI/CD |
| Cost structure | Fixed high salary + overhead | Predictable service fee |
The bottleneck in cloud security is not a lack of information. Tools like Wiz provide excellent visibility into risk. The bottleneck is the labor required to safely apply a fix without breaking production. This requires human supervision to ensure that a policy change in IAM or a security group update does not cause an outage.
Tamnoon addresses this by providing human-supervised remediation. Experts review the proposed fix and the specific context of the environment before any action is taken. This hybrid approach provides the scale of automation with the safety of a human engineer, without the six-month delay associated with recruitment.
The risk of the automated fix
There is a temptation to use "auto-remediation" scripts to bypass the need for personnel. Many organizations that attempt this quickly revert to manual processes after a script inadvertently shuts down a production database or locks out an admin account.
Internal engineers often become hesitant to apply fixes because they fear these side effects. This hesitation is a primary driver of the 58-day remediation average. A managed service reduces this friction by bringing cross-customer experience. If a specific remediation path has worked safely across fifty other environments, the confidence to apply it increases.
Determining the appropriate path
Hiring is necessary for building long-term institutional knowledge and designing future-state architectures. However, hiring to solve a backlog is an inefficient use of capital. The recruitment costs and the high probability of turnover mean the "cost per finding closed" is remarkably high in the hiring model.
For organizations where the CNAPP console is currently a "list of things we will never do," the managed remediation model provides an immediate correction. It allows the existing, thinly stretched security team to stop acting as ticket routers and start acting as oversight for a service that actually closes the loop.
By the end of a 12-month period, the choice between these two paths determines whether the organization has two new employees or a fundamentally smaller attack surface. In an environment where detection is a solved problem, the ability to execute the fix is the only remaining lever for risk reduction.
- The average time to remediate a critical cloud vulnerability is 58 days.
- Tamnoon integrates with existing detection tools and provides specific code or configuration changes.
- Traditional MSSPs often fail to address the underlying remediation bottleneck in cloud environments.



