← Blog

53% is not your number.

The one the board needs is smaller, and every line of it has a date.

53% is not your number.

Once a quarter you stand in front of the board with a chart that goes up and to the right. It is the only one in the deck that does, and the only one nobody applauds.

It is the open-findings line. Across 800 cloud accounts, 53% of everything scanners ever detected is still open (State of Cloud Remediation 2026). The unresolved pile is bigger than the resolved one, and it has outgrown it every year.

53% is not your number. It never was.

In one sentence: Tamnoon is the self-healing engine for cloud exposures. It gives every finding a verdict, heals what it can prove safe through your own change process, and declines the rest in writing, with the evidence.

Your team did not get slower

Our report says it plainly, and it is the sentence we would put on the first slide. The time to close a critical keeps climbing, and "that isn't because teams got slower." The easy findings were closed first. What is left carries a wider blast radius, more teams to coordinate, and more production risk.

So much of what is still open is not waiting for a patch. It is waiting for a meeting. Somebody has to agree that the change is safe to make, and nobody owns that agreement: the report found that no team owns the end-to-end closure timeline. The finding just gets older.

That is the part of the chart nobody explains to the board. It does not measure effort. It measures how many changes nobody could prove safe.

If the AI works, why is the backlog still growing?

Here is the part that should bother everyone. In the last two years remediation got its own AI. Most of the big scanners now explain a finding in plain English, investigate it, and draft the change in seconds.

By any reasonable expectation, the pile should be shrinking by now. It is still growing. Something here does not add up.

Either the AI does not work, or it is working on the wrong problem. We think it is the second. Writing the change was never the hard part. Knowing it is safe to run in this environment, and finding someone willing to sign it, is the hard part, and that is exactly where the assistants stop. They made the draft instant and left the decision where it was.

So there is a new kind of backlog: changes that are already written, waiting for someone to approve them. Drafted in seconds. Waiting a quarter for a meeting.

That is the smell. Everyone automated the yes. Nobody could sign it, because nothing in the process was able to say no.

The number the board actually needs

Our report is blunt about what belongs on the slide. Not alerts detected. Not alerts closed this quarter. Open findings on crown-jewel assets, by age.

That number is far smaller. Across the dataset, 6.3% of alerts touch a crown-jewel asset. It is small enough to put an owner on every line, and dated, so the oldest ones are the first thing anyone sees.

A director can act on that number. Nobody can act on 53%.

Open is not a decision

That leaves the rest of the backlog, and the rest does not need a slide. It needs a decision.

The engine reads every finding from every scanner you run, read-only, the way a careful engineer would before touching anything: who uses it, what depends on it, who owns it, what changed last week. Then it gives each one of three answers. SAFE: the change is proven safe for this environment and heals through your own change process, rollback attached. RISKY: it cannot be proven safe, so it is declined in writing, with the evidence and a manual path for the owner. AWAITING DATA: one thing is missing, and it asks for it instead of guessing.

Every one of those is a decision. Open stops meaning that nobody decided.

For the CISO with a board meeting on the calendar

The one-page version.

Automation you can put your name to.

Here is your one-pager.

Download the PDF →

That did not go through. Try again, or write to [email protected].

For the CISO with a board meeting on the calendar

The no you can defend

Here is the question every CISO already knows is coming. If an incident ever traces back to a finding, nobody will ask how you missed it. The finding existed. They will ask why it was still open.

"Declined in March, here is the evidence, here is who owns the manual path" is an answer. "It was in the backlog" is not.

That is why the no matters more to you than the yes. Every tool can act. Only a record of what was refused, and why, holds up when someone reads it a year later. A written no is a decision you can sign.

Same backlog. Two slides.

The slide you present today has one line, and it goes up. The slide the board needs has two parts. The crown jewels, by age, with an owner on every line. And everything else, decided: healed with the rescan attached, declined with the evidence, or waiting on one named answer.

Same backlog, two slides.

Same backlog, two slides. Left: the industry's number (State of Cloud Remediation 2026, 800 cloud accounts). Right: an illustration of the report's own board number, crown jewels by age, with everything else decided.

Same scanners, same team, same backlog. A different number, and one you can defend.

Ask any vendor. Including us.

Can it refuse a change? Show us one refusal, evidence attached.

Which of our open findings touch a crown jewel, and how long has each one been open?

Show us the slide: healed, declined and waiting, with a receipt behind every line.

Bring the next board slide.

Watch mode is read-only. Thirty minutes to connect, nothing written. Hours later you know what heals without you, what it declines and why, and what is actually left for the board.

Report the crown jewels. Decide the rest.

Everyone automates the yes. We mastered the no.

Notes from the Healing Gap.

Teardowns, CTF write-ups and field notes from the people who close cloud findings for a living.

You're subscribed.

That did not go through. Try again, or write to [email protected].

At most one email a month. Unsubscribe from any of them.