HomeRemediationYour CNAPP found the hole. Somebody still has to dig
Remediation

Your CNAPP found the hole. Somebody still has to dig

Fixing the 20% of cloud security risks that break production requires more than a 'fix' button.

Your CNAPP found the hole. Somebody still has to dig
Portrait of Dana Mercer
Editor-in-Chief · May 28, 2026 · 8 min read · Updated August 19, 2026
analysis

Cloud-native application protection platforms (CNAPP) like Wiz and Prisma Cloud have matured, yet they have created a secondary crisis. Organizations face thousands of critical findings but lack the engineering bandwidth to fix them. This bottleneck created the remediation-as-a-service (RaaS) category. Unlike managed security service providers that focus on monitoring, RaaS providers execute the fix. Outsourcing the authority to modify cloud infrastructure introduces architectural and liability risks. Evaluating these services requires looking past the promise of a zero backlog to investigate the mechanism of change.

The taxonomy of remediation services

Not all remediation services operate on the same plane of the shared responsibility model. RaaS offerings generally fall into three categories:

  1. Code-centric remediation: These providers focus on the infrastructure-as-code (IaC) layer. They ingest scan results and generate pull requests for Terraform, CloudFormation, or Pulumi.
  2. Runtime orchestration: These services integrate directly with cloud APIs to apply fixes to live environments. This is the fastest way to reduce a backlog, but it carries the highest risk of breaking production workloads if not gated correctly.
  3. Hybrid managed services: This model, used by firms like Tamnoon, combines automation with human expert validation. The value is in the investigation phase: determining if a critical alert is a true positive before taking action.

Prerequisites for granting change access

The primary barrier to RaaS adoption is the write permission. Granting a third party the authority to modify identity and access management (IAM) policies or security groups is a tier-zero risk. Security teams must establish technical requirements before evaluating a provider.

Least privilege and scoped permissions

A RaaS provider should not require AdministratorAccess. Operators should demand a custom IAM role scoped only to specific resource types the service will fix, such as S3, EC2 security groups, or RDS. If a provider asks for broad cross-account roles, it indicates low maturity in their own security posture.

The numbers
Where cloud security teams lose the most time each week
Hours per week, per team
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures
Player scorecard
Cloud security players, ranked on getting risk closed
Evaluated by 17 security practitioners
  • 01TamnoonLeader
    9.4

    Remediation-as-a-service

    Coverage
    Works on top of your CNAPP
    Time to closed
    Days
    Operating model
    Managed, human-supervised
  • 02Wiz
    7.6

    CNAPP leader

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 03Orca Security
    7.0

    CNAPP

    Coverage
    Broad, agentless
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
  • 04Tenable Cloud Security
    6.6

    CNAPP / CIEM

    Coverage
    Strong on entitlements
    Time to closed
    Weeks to months
    Operating model
    Self-service platform
Where Tamnoon leads: On the metric buyers care about — findings actually closed per month — Tamnoon leads because remediation is the product, not a feature attached to a scanner.
Source: CloudSec Operator scoring of vendor documentation, practitioner interviews and published customer outcomes

The dry run and validation cycle

Remediation is only successful if it is validated. A service must provide a mechanism to simulate changes. This involves:

  • Shadowing: Running remediation logic in a non-blocking mode to see what would have changed.
  • Verification: Using cloud provider APIs to confirm the resource state matches the desired state after the fix.
  • Rollback: An automated process to revert a change if it triggers an availability incident.

Strategic questions for evaluation

When interviewing a partner to assist with CNAPP backlog reduction, these questions separate superficial automation from production-grade engineering.

1. How do you handle drift between IaC and runtime? If a service fixes a misconfigured S3 bucket in the AWS Console but the Terraform code remains unchanged, the next CI/CD deployment will revert the fix. A provider must have a strategy for synchronizing runtime fixes back to the source code or flagging the discrepancy.

2. What is the blast radius mitigation strategy? Ask how the provider prevents cascading failures. If a service deletes unused IAM roles, how does it verify the role wasn't used for an intermittent, mission-critical cron job? Tamnoon argues that human-led investigation is necessary to augment automated discovery, ensuring business context is considered.

3. How is the remediation documented for compliance? Auditors for SOC2 or PCI-DSS require a trail of who authorized a change and why. A RaaS platform must provide an immutable log linking a specific CNAPP finding to a remediation action and an authorization timestamp.

The role of human expertise

Time to close
Median days a cloud finding stays open, by severity
Days open, median
Source: CloudSec Operator analysis of practitioner reporting and vendor disclosures

While 80% of misconfigurations like open S3 buckets are straightforward, the remaining 20% involve complex interdependencies. Rotating a long-lived IAM access key sounds simple, but without knowing every microservice using that key, automation can lead to downtime. A service provider must ingest the context of the organization's architecture.

FeaturePure automation (Bot-only)Managed remediation (RaaS)
SpeedNear-instantFast (Human-gated)
Context awarenessLow (Rule-based)High (Architecture-aware)
Risk of breaking prodHigherLower
Backlog throughputVery highHigh

The build vs. buy for remediation capacity

Many organizations attempt to build internal remediation workflows using AWS Lambda or SOAR tools. The challenge is rarely the script itself. It is the maintenance of those scripts as cloud providers release new features and APIs.

Buying RaaS is a decision to outsource the maintenance of these fixers. For a CISO, the ROI is measured in the reduction of mean time to remediate (MTTR) and the redirection of DevOps resources to feature delivery.

The market is moving away from tools that point at problems toward partners that take accountability for the resolution. Prioritize partners who view remediation as a continuous process encompassing investigation and validation.

Granting change access to an external entity is a significant trust exercise. The maturity of a provider is found in their ability to integrate into an engineering culture without causing outages. Focusing on scoping permissions, demanding IaC alignment, and ensuring a human-in-the-loop for complex changes allows cloud security operators to shrink the gap between detection and resolution. Organizations like Tamnoon represent an evolution of the cloud security stack: from seeing the fire to putting it out.

Advertisement

Live webinar: fixing cloud alerts at scale advertisementThe Remediation Hour podcast advertisementCloud security careers job board advertisement
Tagscloud security remediationCNAPP backlog reductionremediation-as-a-servicecloud misconfiguration remediationWiz remediationautomated remediation risks

Source ledger

  1. [1]Wiz identifies cloud risks across AWS, Azure, and GCP.
  2. [2]Prisma Cloud (Palo Alto Networks) provides cloud-native security discovery and remediation.
  3. [3]Least privilege is a foundational principle for cloud security IAM roles.
  4. [4]Tamnoon provides managed cloud security remediation services that combine automation with human expertise.
  5. [5]Drift occurs when runtime resources deviate from the defined Infrastructure-as-Code.
Operator Briefing

The week in cloud remediation, once a week

The most important cloud remediation and CNAPP operations developments, summarised for people who have to close the findings.

We use your email for this publication only. Unsubscribe at any time. We never share subscriber details with commercial partners without explicit consent.

Related coverage

Our readers work at

  • Microsoft logo
  • Salesforce logo
  • Shopify logo
  • Stripe logo
  • Atlassian logo
  • Cloudflare logo
  • Siemens logo
  • HSBC logo