Remediation and retest

A report that moves nothing was an expensive PDF

Most of what a security audit is worth happens in the six weeks after it is delivered, and most practices are gone by then. We are not: the triage, the pairing and the retest are in the engagement, not sold back to you afterwards.

WEIGHTED RISK · 90 DAYS25240
0100200300DAY 0142842567090

A typical 90-day window on our own scale, illustrative rather than any one client’s. The flat part is the point: what is left after a month needs a change window, not an afternoon.

Day 0 · the report
2Critical
7High
13Medium
9Low
5Informational
Day 90 · the retest
1High
4Medium
6Low
5Informational
Weighted risk removed84%

Medians across anonymised engagements. Nothing on this site identifies a client, an estate or an account.

How the fix works

We work in your tracker, on your board, with your engineers

Not a parallel project with its own status report. Three quarters of the fixes are made by your own team — we are there for the identity and networking ones, which are the fixes that break things when they are made from a report alone.

01Triage together

A two-hour session with the engineers who own the systems. Every finding gets an owner, a target date and — where you disagree with us — a written reason it is being accepted instead.

02Fix in priority order

Critical and High first, regardless of which is easiest. We work in your tracker, on your board, in tickets your team wrote rather than tickets we imported.

03Pair where it helps

For anything touching identity or networking we sit with whoever is making the change, because those are the fixes that break things when made from a report alone.

04Prove the close

Each fix is retested against the original evidence. A finding moves to Closed when we can no longer reproduce it, and not when a ticket is dragged across a board.

05Watch the drift

The controls behind the closed findings go on a watch list. If one comes back — and a few always do — you hear it from us rather than from the next audit.

What you keep

Four things that outlive the engagement

The second question a good client asks is what they have left when we have gone. This is the answer, and it is why the guardrails go in your repository rather than in our report.

84%Weighted risk removed

Median across the first 90 days

100%Criticals closed

Within 14 days, every engagement so far

3 of 4Fixes made by your team

We pair on the fourth

The backlog

Every finding as a ticket in your tracker, with the fix, the effort and the owner already on it.

The guardrails

Policies, SCPs and pipeline checks that stop the fixed thing coming back, written as code in your repository.

The evidence pack

Before and after, dated, ready to attach to a customer questionnaire without anybody rewriting it.

The runbook

How to reproduce every check we ran, so your own team can do the interim passes between audits.

Next step

Already have a report you have not managed to act on?

Send it over. We will triage it against your actual estate, tell you which findings are still real, and put the rest in an order your team can start on this week — whether or not it was our report in the first place.