The plan within a week; the retest when you are ready, typically six weeks later.
STEP 3 OF 3
Fix it in the right order, and prove it stayed fixed
Findings ranked by what is reachable and what is being exploited in the wild, with a remediation plan your team can work through and a date in the diary to check it held.
Audit
This is the step organisations skip, and it is the one that decides whether the money was wasted. A report with four hundred findings and no order of work gets read once. A list of eleven things, ordered by risk removed per day of effort, gets done — and the retest six weeks later is what turns it into evidence for a regulator or an insurer.
What happens
- Prioritisation by exploitability and reachability, not by a generic severity score
- Remediation written for the platform you run, not for a textbook
- Compensating controls where a fix is genuinely not possible
- A retest, so the fix is proven rather than believed
A closed list, a retest report, and the evidence trail an auditor or an insurer will accept.
When this is the right first move
- You are holding findings from somebody else's report and need them actually closed
- A certification, a tender or an insurer wants evidence rather than assurances
- A regulator has asked you to demonstrate the measures rather than describe them
- The same weakness has come back twice and nobody knows why
And when it is not. Skip it if there is nothing to prove to anybody yet. An audit is worth its cost when a third party is going to read the output; before that, the money is better spent fixing things.
The other steps
Start at the beginning
The first step costs you half a day and ends in a document you keep whether or not you go further.