A cloud security finding becomes useful only when someone decides what matters, assigns an owner, and follows it through. For IOmergent, the missing layer is a regular operating cadence that filters out noise, adds business context, and keeps remediation moving.
Without that, the cloud security scanner will continue to do its job and generate countless findings, yet the same tickets will stay open week after week. For busy CTOs, VPs, and heads of security already buried in product pressure, customer demands, and a fire hose of alerts, this can look like negligence.
“There’s no doubt about it: people care about security and want to fix things.”
Jon Rose, CISO at IOmergent
But as Jon Rose, seasoned CISO and founder of the information security and risk management advisory firm IOmergent, tells The New Stack, “There’s no doubt about it: people care about security and want to fix things.” They’re just constrained on time, he says, and constantly pulled in a hundred different directions.
A dedicated security team could have full visibility and a good sense of what matters in general. Still, with no one owning the trend line and distilling for engineers, the fight will be lost to, well, pretty much everything else.
Detection is easy. Execution is the hard part.
Recent industry reports show that CSPM adoption has surged by more than 60% in the past year alone. Driven by major data breaches, stricter compliance expectations, and the recognition that traditional cloud environments need continuous visibility, more than 65% of organizations now use some form of CSPM. This market is expected to reach $11.75 billion by 2030. So it’s clear that teams aren’t short on tools or findings. They’re short on time and operational capacity to act on what those tools surface.
The real work is triage: sifting the signal from the noise, deciding what moves now, and ensuring the same findings don’t keep resurfacing week after week.
The gap lies in the sustained execution after the alert comes in. The CSPM flags a finding, but the person reading it still has to decide what it means in context: Is it actually exploitable, how severe is the exposure, and does it affect something the business truly depends on? That judgment takes time, and while sense-checking one issue, dozens more alerts can flood in behind it. So the real work is triage: sifting the signal from the noise, deciding what moves now, and ensuring the same findings don’t keep resurfacing week after week.
Even the best detection degrades when no one owns the trend line. What helps is rhythm, instead of a stern automated email your team will likely ignore. Against a backdrop of continuous monitoring, Rose believes the most effective cadence is a short recurring check-in that clears out the noise, adds the business context, and asks a few simple questions: What’s new, does it matter, what’s still open, what’s blocking it, and who owns the next step?“ Once we do that initial review, filter out some of the sheer volume, and adjust it to what matters to the company, the work does become much more manageable,” says Rose. Some items are quick wins that can be fixed today, while others become part of a longer roadmap, to be tackled steadily alongside everything else.
And that only works when it becomes part of the operating rhythm. Rose points out that security issues are being found and exploited much faster because of AI and increasingly skilled attackers, which makes sporadic reviewing a bad bet. “You have to stay on it every day and make cloud security accountability a normal part of operations,” he explains.
Why cadence matters
A Managed Cloud Security provider like IOmergent won’t be buried under your sprint or negotiating priorities with the person being nudged. It can drive cloud security accountability without the overhead of a full-time hire, and can do so in a way that feels like help, instead of judgment or top-down criticism.
“We’re threading the needle on what really matters.”
Brett Wilson, co-founder and managing partner at IOmergent
Brett Wilson, IOmergent’s co-founder and managing partner, tells The New Stack, “We’re threading the needle on what really matters,” “By compressing the funnel and building a layer in between, we offer a distillation process.”
A huge part of the unlock is the human side. The people IOmergent sends into teams are engineers themselves, often ex-CTOs or DevOps leads, so they understand what it means to keep systems running, scale them, and have to make trade-offs under pressure.
“They understand the work intimately, and often have more experience than some of the team members we work with on our clients,” says Rose. “There’s definitely a coaching and mentoring aspect that happens too.” Those conversations give teams face time with someone who can guide them through the triage and decision-making, instead of handing them another list of issues to close.
Attention is a scarce resource in any fast-moving, cloud-heavy SaaS, fintech, or healthtech firm. Left alone, the backlog grows. The managed cloud security team can create and keep a steady rhythm: continuous monitoring with a weekly or monthly check-in, a clear owner, a judgment call on what matters now and what can wait, and enough context to keep the work moving. The point isn’t perfection; it’s momentum.