logo
Mitigation Without Remediation: Rethinking Cloud Risk Resolution

Mitigation Without Remediation: Rethinking Cloud Risk Resolution

Forbes30-07-2025
Security teams today face a hard reality in modern cloud environments: not every vulnerability can be fixed right away. In fact, many can't be fixed at all—at least not without breaking business-critical systems or waiting on another team's backlog.
That doesn't mean organizations are helpless. It means the way we think about cloud risk has to evolve.
The Exposure We Can't Always Fix
A growing body of research—and firsthand experience—shows that more than half of identified cloud risks go unremediated for extended periods. The reasons vary:
These are relatively common scenarios. And in each case, the longer a vulnerability stays open, the more time an attacker has to find and exploit it.
'Full remediation is always the ultimate goal,' says Snir Ben Shimol, CEO of ZEST Security. 'But mitigation is a key piece to a robust cloud exposure management program—especially when full remediation can't be implemented right away.'
Why Mitigation Matters
Traditionally, security posture has been defined by how quickly teams can identify, prioritize, and patch. But when patching isn't an option, the focus shifts to limiting what an attacker can do.
This is where mitigation comes in. Think of it as a parallel track to remediation—not a replacement, but a way to reduce exposure today while working on a longer-term fix.
Mitigation strategies might include:
These options aren't about perfect security. They're about reducing exploitability. 'Let's take ransomware as an example,' Ben Shimol explains. 'SCPs can be used to limit what an attacker is able to do, such as restricting the ability to delete or encrypt data. That buys valuable time and reduces risk while remediation efforts are underway.'
The Role of Agentic AI in Resolution
Manual mitigation is time-intensive and context-sensitive. Applying the wrong policy—or applying it in the wrong place—can break functionality or disrupt development workflows. That's where automation and AI are starting to play a critical role.
AI-powered resolution engines now exist to analyze the environment, simulate changes, and recommend safe, high-impact actions. These systems, often built around specialized 'agents,' can correlate CSPM findings and vulnerability scans to a range of viable resolutions—including both code fixes and mitigation pathways.
Ben Shimol describes ZEST's approach as a network of AI agents 'each designed to handle specific remediation tasks,' including agents that focus on mitigation using native cloud controls. 'Our agents simulate every fix, mitigation, etc., on a digital twin of your environment, recursively validating the outcome before suggesting changes.'
Why SCPs Are Gaining Attention
AWS Service Control Policies are not new, but they've historically been viewed as administrative guardrails—static controls for limiting service access across accounts.
What's changed is the realization that SCPs can also be dynamic mitigation tools. They can be used to enforce least privilege, restrict destructive actions, and isolate misconfigured services—all without requiring code changes.
When used with precision and context, SCPs can help prevent key stages of an attack, including:
Skeptics sometimes view SCPs as blunt instruments, but that perception is shifting. When properly scoped and validated, they can offer a reliable, reversible, and low-friction way to reduce risk.
The Bigger Shift
Most CSPM tools and vulnerability scanners end at detection and alerting. The burden then falls on security teams to decide what to do next—and to negotiate with DevOps, engineering, or IT to implement a fix.
Mitigation pathways provide a way to break that cycle. They empower security teams to act immediately, using cloud-native controls to reduce the attack surface while waiting on the rest of the system to catch up.
ZEST Security announced it is adding AWS Service Control Policies as a core mitigation pathway in its cloud risk resolution platform. ZEST's approach treats SCPs as real-time controls to prevent key stages of an attack—such as reconnaissance, privilege escalation, or data encryption—even when the underlying vulnerability remains unresolved.
The move highlights a broader industry trend: building smarter tooling that can help security teams take meaningful action—without having to wait for the perfect fix.
'ZEST gives security teams options,' says Ben Shimol. 'We provide resolution pathways aligned to groups of related risks, offering both remediation and mitigation options—so teams can choose the best way forward based on their unique circumstances.'
Looking Ahead
As cloud complexity grows, so does the gap between risk discovery and resolution. Agentic AI systems and proactive mitigation strategies are closing that gap—not by eliminating every vulnerability, but by reducing the chances it can be used against you.
Mitigation isn't a detour from security best practices. It's a way to stay in the fight when perfection isn't possible.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

3 ChatGPT Prompts To Help Travel Entrepreneurs Earn $2,000 Monthly
3 ChatGPT Prompts To Help Travel Entrepreneurs Earn $2,000 Monthly

Forbes

time2 minutes ago

  • Forbes

3 ChatGPT Prompts To Help Travel Entrepreneurs Earn $2,000 Monthly

Travel entrepreneurs face a constant challenge: how to scale their businesses while managing content creation, customer service, and marketing across multiple platforms. Whether running a travel blog, offering destination consulting, or leading tours, the administrative work can quickly overwhelm the actual revenue-generating activities. Rather than replacing the human expertise that makes travel services valuable, ChatGPT can handle repetitive tasks, generate content frameworks, and streamline customer communications—freeing entrepreneurs to focus on high-value activities. Now that travel has rebounded after the pandemic, entrepreneurs face increased competition for travelers' attention. Many struggle to maintain consistent content creation and see customer follow-up as a major operational challenge. These pain points directly impact revenue potential in an industry where personal connection and trust are essential for booking decisions. Here are three specific ChatGPT prompts that travel entrepreneurs can implement immediately to boost their monthly revenue toward $2,000. 1. The ChatGPT Content Planning Multiplier ChatGPT Prompt: "I run a travel business focused on [your niche] Travel content creators often face the ongoing challenge of generating new ideas. This ChatGPT prompt produces multiple content angles at once while also pinpointing monetization opportunities. Implementation: A digital nomad consultant might input into ChatGPT: "I run a travel business focused on helping remote workers relocate to Southeast Asia. Create a content strategy..." The ChatGPT response provides a month's worth of content ideas with built-in revenue streams. Revenue Impact: Consistent, problem-solving content attracts organic traffic and can drive meaningful affiliate commissions for travel bloggers who implement this systematic ChatGPT approach. 2. The ChatGPT Booking Conversion Optimizer ChatGPT Prompt: "I offer [specific travel service]Converting interested prospects into paying customers often determines the difference between struggling and thriving travel businesses. Most entrepreneurs send generic follow-ups that fail to address specific concerns. Implementation: A luxury travel advisor might use this ChatGPT prompt: "I offer wellness retreats to busy professionals. Write a follow-up email sequence..." The resulting ChatGPT sequence addresses specific objections while building a sense of urgency. Revenue Impact: Improved follow-up sequences generated by ChatGPT can significantly increase conversion rates for travel services, resulting in substantial monthly revenue gains. 3. The ChatGPT Social Media Automation Engine ChatGPT Prompt: "Create 30 Instagram captions for my [type of travel business] that: 1) Include a mix of educational tips, behind-the-scenes content, and customer stories, 2) Use relevant hashtags for maximum reach, 3) Include clear calls-to-action, and 4) Reflect my brand voice as [describe your tone]. Also suggest optimal posting times for travel audiences." Social media consistency drives booking inquiries, but creating engaging content daily can be overwhelming for many travel entrepreneurs. This ChatGPT prompt generates a month of content while maintaining brand consistency. Implementation: A European walking tour guide might input into ChatGPT: "Create 30 Instagram captions for my small-group cultural tours that..." The ChatGPT output provides ready-to-post content with strategic variety and diversity. Revenue Impact: A consistent social media presence increases brand awareness and direct bookings for travel businesses. ChatGPT Implementation Strategy Week 1: Implement the ChatGPT content planning prompt and create your editorial calendar. Week 2: Set up your email follow-up sequence using the ChatGPT conversion optimizer. Week 3: Generate and schedule social media content using the ChatGPT automation engine. Week 4: Analyze results and refine your ChatGPT approach based on engagement and conversion data. The key is consistency. Travel entrepreneurs who systematically implement all three ChatGPT prompts can expect to see meaningful monthly revenue increases within 90 days. Avoiding ChatGPT Pitfalls Travel entrepreneurs often make these mistakes: copying ChatGPT responses verbatim without personalization, failing to fact-check destination information, or using generic prompts that don't reflect their unique brand voice. Always review and customize ChatGPT outputs with your firsthand travel experience and local insights. The most effective approach combines AI efficiency with authentic expertise—ChatGPT handles the framework while you add the personal touches that only come from real travel experience. Beyond the ChatGPT Prompts These ChatGPT tools are most effective when combined with authentic expertise and genuine customer service. ChatGPT can generate frameworks and ideas, but successful travel entrepreneurs still need to add personal insights, real experiences, and authentic connections that no AI can replicate. Consider these ChatGPT prompts as efficiency multipliers rather than replacements for human creativity. The most successful travel entrepreneurs utilize ChatGPT to handle routine tasks, enabling them to focus their energy on creating exceptional customer experiences. By leveraging ChatGPT for content creation, customer communication, and social media management, entrepreneurs can focus on what truly drives bookings and views: building trust, sharing authentic experiences, and helping people create meaningful memories.

Founding Father's historic property in Boston tourist district hits market with one intriguing secret
Founding Father's historic property in Boston tourist district hits market with one intriguing secret

Fox News

time10 minutes ago

  • Fox News

Founding Father's historic property in Boston tourist district hits market with one intriguing secret

A Revolutionary War-era home tied to a Founding Father is for sale in historic downtown Boston – but one detail remains under wraps. The property, called the Ebenezer Hancock House, was built in 1767. The building is located at 10 Marshall Street in the city's tourist-heavy Blackstone Block Historic District. The house sits right on Boston's Freedom Trail and boasts proximity to Faneuil Hall, Haymarket and North Station. It's also a short walk from the North End, a bustling tourist hotspot. Luxury real estate company LandVest says the building is the last surviving Boston property tied to John Hancock. The Founding Father owned the house before transferring the title to his brother Ebenezer — for whom the house is now named. The three-story house still maintains Georgian-era interior details, although it was expanded in the 1970s. It is now in use as a law office. "[It] remains the only vernacular structure dating to the mid-1700s to survive in central Boston," the firm's website states. The listing added, "It is reportedly the site where Ebenezer Hancock, deputy paymaster of the Continental Army and John Hancock's younger brother, stored 2 million silver crowns, loaned by the French government, prior to disbursement to the troops." Dave Killen, a commercial real estate broker with LandVest, told Fox News Digital the listing is aimed at commercial buyers, rather than residential ones. "We are actively looking for a buyer who loves the history and the location, and who will embrace their role as a steward of this Boston landmark site with enthusiasm," the broker said. "Given the property's location in the heart of the Blackstone Block, this likely means an owner occupant for office, retail or mixed use." "We are grateful that the story of 10 Marshall Street is being told, and we are excited to see what this new chapter brings." Yet one mystery remains. The asking price is a closely held secret, available only to serious buyers. Killen declined to share the price with Fox News Digital. But the property is one of a kind — and the broker said similar listings are "extremely rare" on the Boston market. "This is the first time in approximately 50 years the property has been available for sale," he said. "The current owners, who have been conscientious stewards of the site, acquired the property in 1976 and helped facilitate the landmark designation." Above all, Killen noted that the property "may have one of the best untold stories for a historical site in downtown Boston." "The Freedom Trail is literally steps from the front door, and I think because the site has been owned and occupied by a law firm of some discretion for the last 50 years, the historical authenticity of this property may be less widely understood than that of some of its more famous peers," the broker said. "We are grateful that the story of 10 Marshall Street is being told," he added. "And we are excited to see what this new chapter brings."

Delta plane wing clips empty aircraft during pushback from gate in Atlanta
Delta plane wing clips empty aircraft during pushback from gate in Atlanta

Yahoo

time29 minutes ago

  • Yahoo

Delta plane wing clips empty aircraft during pushback from gate in Atlanta

ATLANTA (AP) — A Delta Air Lines plane clipped another aircraft while pushing back from the gate Sunday morning in Atlanta, the airline said. The wing of the plane 'reportedly made contact' with an empty aircraft, Delta said in a brief written statement to The Associated Press. The flight was scheduled to travel from Atlanta to Guatemala City, according to FlightAware, a website that tracks flight disruptions. Passengers were transferred to another plane following a delay. On board the commercial aircraft were 192 customers, two pilots and four flight attendants. No injuries were reported, according to Delta, which has its headquarters in Atlanta. Additional information on the incident was not immediately available. The Associated Press Error while retrieving data Sign in to access your portfolio Error while retrieving data Error while retrieving data Error while retrieving data Error while retrieving data

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store