Solutions / The situation
A finding you have documented and not fixed is worse than one you never found.
The report came back (from an audit, a pentest, a customer's assessor) and it is sitting in a folder. Nobody disputes the findings; there is simply no owner, no plan and no date. You are now in the worst position available: you have written proof that you knew, and no proof that you acted.
A documented, unremediated finding is evidence of knowledge. In a breach investigation, an insurance claim, or a customer dispute, the first question asked is what you knew and when, and a dated report with no remediation record answers it against you. Before the scan you were unaware. Now you are on record.
What it is costing you
- Knowledge without action converts a technical issue into a liability you can be held to.
- Your cyber insurer can ask for the report; unremediated findings affect coverage and renewal.
- The customer who commissioned the assessment is waiting for a remediation plan, and the deal is waiting with them.
- The findings age. New ones arrive on top. Nobody can tell you which of the open items actually matters.
What we do
We triage the report by real exposure
Vendor severity ratings are generic. We re-rank findings against your actual environment (what is internet-facing, what touches customer data, what is genuinely exploitable), and most reports collapse to a short list that matters.
We validate before you spend
A meaningful share of findings are false positives, compensated by a control you already run, or not applicable. We prove which, so engineering does not burn a sprint on noise.
We produce the remediation plan with owners and dates
The artefact that changes your legal and commercial position is a tracked plan: finding, owner, date, status. It is what the customer, the insurer and the auditor all need to see.
We drive the fixes to closed
We work with your engineers, retest what was fixed, and close items with evidence, not with someone marking a ticket done.
We stop the next report from ambushing you
Continuous monitoring means findings arrive as a steady flow you handle, not as a 90-page document once a year that nobody has capacity to absorb.
What should we do first with a long list of audit or pentest findings?
Triage before you remediate. Re-rank the findings against your actual environment rather than the vendor's generic severity scores: what is internet-facing, what touches customer or personal data, what is genuinely exploitable given the controls you already run. Then produce a written remediation plan with an owner and a target date for each item. The plan itself changes your position with customers, insurers and regulators, because it converts documented knowledge into documented action.
Are unremediated findings a legal liability?
They are evidence of knowledge. In a breach investigation, an insurance claim or a customer dispute, the central question is what the company knew and what it did about it. A dated report with no remediation record shows the first and not the second. A tracked plan with owners, dates and a risk-based rationale for what was deferred demonstrates that decisions were made deliberately, which is a defensible position even when items remain open.
Do we have to fix every finding in a security audit?
No. You have to make a documented, risk-based decision about every finding. Some are fixed, some are mitigated by an existing control, some are accepted with a rationale and a named owner, and some are false positives that should be closed as such. What is not defensible is silence: findings with no decision recorded against them at all.