Pillar 06
A finding is not closed because someone says it is closed. It is closed when it has been tested again and failed to reproduce.
This is the step most engagements skip, and it is the one that converts a report into an asset. Remediation frequently goes wrong quietly — the fix is applied to staging, or to one of four servers, or it is reverted by a later change. Without verification you have a document describing problems you believe are gone.
What we check
Each item re-tested using the original reproduction steps, not a fresh scan that might miss it.
Whether the remediation introduced anything new, which happens more often than most teams expect.
An updated document showing each finding’s original severity and its verified current state.
The page you hand to an insurer, an auditor, or an enterprise client asking whether you have been tested.
The tamper-evident log covering the re-test as well, so the verification is as provable as the original engagement.
An honest account of what was not fixed and why, because an unqualified clean report is rarely a truthful one.
How it works
Your team works the prioritised list. We are available for questions but the fixes are yours to apply.
Every finding re-attempted under the original scope and authorisation.
Items that reproduce go back with additional detail. Items that do not are marked verified closed.
The final report, dated and branded, showing the position before and after.
What we usually find
Re-testing exists because remediation fails quietly far more often than anyone expects. The team believes the finding is closed; the report says it is closed; the system says otherwise. These are the four ways it usually goes wrong.
The change is applied to the host named in the report, while three identical machines behind the same load balancer keep the original configuration.
The remediation is real, tested and correct — and deployed to the wrong environment, where it will sit until somebody checks.
A configuration fix applied by hand, then overwritten weeks later when the environment is rebuilt from a template that was never updated.
The vulnerable component is updated on the affected system while the image, template or build script that produced it remains unchanged, so the flaw returns with the next deployment.
What you get
Each item re-tested with the original reproduction steps, not a fresh scan that may simply miss it.
The original severity and the verified current state of every finding, dated and branded.
The document to hand an insurer, an auditor, or an enterprise client asking whether you have been tested.
What remains open and why. An unqualified clean report is rarely a truthful one.
A twenty-minute call is enough to agree what gets checked and what it costs. Nothing on your systems is touched until you have signed to say we may.
Book a free callarrow_forward